903 B
903 B
rbac Specification
Purpose
TBD - created by archiving change foundation-auth. Update Purpose after archive.
Requirements
Requirement: Role model
The system SHALL support roles platform_admin, shop_owner, shop_staff, customer. Shop roles MUST carry a shop_id scope.
Scenario: seeded platform admin
- WHEN migrations run on a fresh database
- THEN a
platform_adminaccount exists and can log in
Requirement: Role enforcement
Protected routes SHALL declare required roles; the API MUST reject requests with insufficient role using 403.
Scenario: customer hits admin route
- WHEN a
customertoken calls an/api/admin/*route - THEN the API returns 403 with code
FORBIDDEN
Scenario: shop scope isolation
- WHEN a
shop_ownerof shop A accesses/api/shop/*resources of shop B - THEN the API returns 403 or 404, never the data