Follow-up to #1. Receive Sign in with Apple server-to-server notifications (consent revoked, Apple account deleted, email forwarding disabled or enabled) at an HTTPS route of the cloud Worker.
Verify each notification's JWT against Apple's keys (https://appleid.apple.com/auth/keys), with the com.origin89.apps.ios audience and the Apple issuer. Map Apple's sub to our user through the WorkOS user's Apple identity, since the cloud stores only the WorkOS issuer and subject. On consent-revoked or account-delete, delete or disable the user the same way DELETE /v1/account does; on email events, update nothing the cloud does not store.
Then set the route as the notification URL on the com.origin89.apps.ios App ID's Sign in with Apple configuration. It stays empty until the route exists.
Acceptance: tests for a valid notification of each type, a bad signature, a wrong audience, and an unknown user.
Follow-up to #1. Receive Sign in with Apple server-to-server notifications (consent revoked, Apple account deleted, email forwarding disabled or enabled) at an HTTPS route of the cloud Worker.
Verify each notification's JWT against Apple's keys (
https://appleid.apple.com/auth/keys), with thecom.origin89.apps.iosaudience and the Apple issuer. Map Apple'ssubto our user through the WorkOS user's Apple identity, since the cloud stores only the WorkOS issuer and subject. Onconsent-revokedoraccount-delete, delete or disable the user the same wayDELETE /v1/accountdoes; on email events, update nothing the cloud does not store.Then set the route as the notification URL on the
com.origin89.apps.iosApp ID's Sign in with Apple configuration. It stays empty until the route exists.Acceptance: tests for a valid notification of each type, a bad signature, a wrong audience, and an unknown user.