mirror of
https://github.com/pocket-id/pocket-id.git
synced 2026-10-10 11:49:05 +02:00
refactor: authorize API routes with per-endpoint scopes (#1823)
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
This commit is contained in:
co-authored by
copilot-swe-agent[bot]
parent
1bd6f006c8
commit
0ec6bfa191
@@ -90,6 +90,11 @@ func MissingPermission() *Error {
|
||||
return New(CodeForbidden, http.StatusForbidden, "You don't have permission to perform this action")
|
||||
}
|
||||
|
||||
// MissingScope keeps the generic forbidden code and names the scope the caller lacks so API clients can tell what to request
|
||||
func MissingScope(scope string) *Error {
|
||||
return MissingPermission().WithDetail("required_scope", scope)
|
||||
}
|
||||
|
||||
func CrossOriginRequestForbidden(cause error) *Error {
|
||||
return Wrap(cause, CodeForbidden, http.StatusForbidden, "Cross-origin requests are not allowed")
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user