Skip to content

Sat rbac capabilities v2#126

Open
kelleyloder wants to merge 3 commits into
developfrom
sat-rbac-capabilities-v2
Open

Sat rbac capabilities v2#126
kelleyloder wants to merge 3 commits into
developfrom
sat-rbac-capabilities-v2

Conversation

@kelleyloder
Copy link
Copy Markdown

  • Add OpenSpec documentation for RBAC/auth contract changes

  • Enforce fail-fast behavior for invalid Xerxes tokens:

    • return 401 immediately on invalid/expired tokens (stop swallowing errors)

This is the first step of the RBAC v2 rollout.
Additional changes (SAT v2 capability checks, domain/access mapping, etc.) will be implemented in follow-up PRs.

This aligns backend behavior with the updated auth contract and now works correctly with the UI session-expired handling fix.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant