#141 [highway-api] API tokens need scoped permissions support

closed critical Created 2025-11-27 21:17 · Updated 2025-11-28 01:26

Description

Edit
Currently API tokens only identify the user - permissions come from user's roles. Need to add scopes/permissions to tokens so a tenant_admin can create a read-only token. Token payload should include 'scopes' field and permission checks should intersect user roles with token scopes.

Comments

Loading comments...

Context

Loading context...

Audit History

View All
Loading audit history...