Skip to content

Handle Sign in with Apple server-to-server notifications #2

Description

@lemarier

Follow-up to #1. Receive Sign in with Apple server-to-server notifications (consent revoked, Apple account deleted, email forwarding disabled or enabled) at an HTTPS route of the cloud Worker.

Verify each notification's JWT against Apple's keys (https://appleid.apple.com/auth/keys), with the com.origin89.apps.ios audience and the Apple issuer. Map Apple's sub to our user through the WorkOS user's Apple identity, since the cloud stores only the WorkOS issuer and subject. On consent-revoked or account-delete, delete or disable the user the same way DELETE /v1/account does; on email events, update nothing the cloud does not store.

Then set the route as the notification URL on the com.origin89.apps.ios App ID's Sign in with Apple configuration. It stays empty until the route exists.

Acceptance: tests for a valid notification of each type, a bad signature, a wrong audience, and an unknown user.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions