diff --git a/.env.dev b/.env.dev index 223905a..540e107 100644 --- a/.env.dev +++ b/.env.dev @@ -152,6 +152,11 @@ SKIP_DID_WEB_VERIFICATION=true # When false, verifies JWT signature against issuer's JWKS AUTH_SKIP_VERIFY=true +# HS256 Issuers: PDSes allowed to use HS256 (shared secret) authentication +# Must share PDS_JWT_SECRET with Coves instance. External PDSes use ES256 via DID resolution. +# For local dev, allow the local PDS or turn AUTH_SKIP_VERIFY = true +HS256_ISSUERS=http://localhost:3001 + # Logging LOG_LEVEL=debug LOG_ENABLED=true diff --git a/.env.prod.example b/.env.prod.example index 38a884a..557db29 100644 --- a/.env.prod.example +++ b/.env.prod.example @@ -26,6 +26,34 @@ PDS_ROTATION_KEY=CHANGE_ME_64_HEX_CHARS # PDS_EMAIL_SMTP_URL=smtp://user:pass@smtp.example.com:587 # PDS_EMAIL_FROM_ADDRESS=noreply@coves.me +# ============================================================================= +# JWT Authentication +# ============================================================================= +# Coves supports two JWT verification methods: +# +# 1. HS256 (shared secret) - For your own PDS +# - Fast, no network calls needed +# - Requires shared PDS_JWT_SECRET +# - Only for PDSes you control +# +# 2. ES256 (DID resolution) - For federated users +# - Works with any PDS (bsky.social, etc.) +# - Resolves user's DID document to get public key +# - No shared secret needed +# +# HS256_ISSUERS: Comma-separated list of PDS URLs allowed to use HS256 +# These PDSes MUST share the same PDS_JWT_SECRET with Coves +# Example: HS256_ISSUERS=https://pds.coves.social,https://pds.example.com +HS256_ISSUERS=https://pds.coves.me + +# PLC Directory URL for DID resolution (optional) +# Defaults to https://plc.directory if not set +# PLC_DIRECTORY_URL=https://plc.directory + +# Skip JWT signature verification (DEVELOPMENT ONLY!) +# Set to false in production for proper security +AUTH_SKIP_VERIFY=false + # ============================================================================= # AppView OAuth (for mobile app authentication) # ============================================================================= diff --git a/docker-compose.prod.yml b/docker-compose.prod.yml index 6321011..9bc6077 100644 --- a/docker-compose.prod.yml +++ b/docker-compose.prod.yml @@ -96,6 +96,12 @@ services: # Cursor encryption for pagination CURSOR_SECRET: ${CURSOR_SECRET} + # PDS JWT secret for verifying HS256 tokens from the PDS + # Must match the PDS_JWT_SECRET configured on the PDS + PDS_JWT_SECRET: ${PDS_JWT_SECRET} + # Whitelist PDS issuer(s) allowed to use HS256 (no kid) + HS256_ISSUERS: ${HS256_ISSUERS} + # Restrict community creation to instance DID only COMMUNITY_CREATORS: did:web:coves.social networks: