refactor: authorize API routes with per-endpoint scopes (#1823)

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
This commit is contained in:
Elias Schneider
2026-10-09 21:33:14 +02:00
committed by GitHub
co-authored by copilot-swe-agent[bot]
parent 1bd6f006c8
commit 0ec6bfa191
48 changed files with 1422 additions and 681 deletions
@@ -90,6 +90,11 @@ func MissingPermission() *Error {
return New(CodeForbidden, http.StatusForbidden, "You don't have permission to perform this action")
}
// MissingScope keeps the generic forbidden code and names the scope the caller lacks so API clients can tell what to request
func MissingScope(scope string) *Error {
return MissingPermission().WithDetail("required_scope", scope)
}
func CrossOriginRequestForbidden(cause error) *Error {
return Wrap(cause, CodeForbidden, http.StatusForbidden, "Cross-origin requests are not allowed")
}