docker run -e JWT_SECRET=<random secret, 32+ bytes> -p 3110:3110 ghcr.io/imkit/imkit-auth-server:masterJWT_SECRETis required; the service exits at startup without it. Use a long random value and keep it in a secret store.POST /signissues an HS256 token for any posted claims (adds a one-yearexp). Anyone who can reach/signcan mint a token for any user, so never expose this service outside a private network.POST /verifyaccepts only HS256 tokens signed withJWT_SECRETand returns their claims, or 401.- Tokens and claims are never logged; the request log records method, path, status and timing only.
- Tokens are compatible with the 1.x release (Node 8, jsonwebtoken 8): a token issued by either version verifies in the other when both use the same
JWT_SECRET.
npm ci
npm testMethod: POST Request Format: JSON
{"token": "Client Access Token"}Response: User data in JSON
{"id": "user-id", "nickname": "Nickname", "avatarUrl", "Avatar URL"}## Verify
curl -X "POST" "https://auth.fangho.com/verify" \
-H 'Content-Type: application/json; charset=utf-8' \
-d $'{
"token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpZCI6InNzcyIsIm5pY2tuYW1lIjoiTm9sYSIsImF2YXRhclVybCI6Imh0dHBzOi8vZ2xvYmFsYXNzZXRzLnN0YXJidWNrcy5jb20vYXNzZXRzL2MxZjRjZDAyZGUyNDQ4M2ViODZjNjk2NDAxYWQ0MjEzLmpwZyIsImV4cCI6MTU1NDM5MDg4NywiaWF0IjoxNTU0MzA0NDg3fQ.cnhdb0s37SZ5jS3jdL1DB78xdoZBQhfV_V1hpGUJbjs"
}'
{
"id": "sss", //Required
"nickname": "Nola", //Optional, the nickname of the client will be overwritten
"avatarUrl": "https://globalassets.starbucks.com/assets/c1f4cd02de24483eb86c696401ad4213.jpg"//Optional, the avatarUrl of the client will be overwritten
}
