Map commitment actions to compliance-page scopes
OAuth2 tokens with v1:compliance-page could not create commitment groups or items because the IAM actions were never listed in OAuth2ScopeMappings. Document the mapping step so MCP/API work does not skip it again. Signed-off-by: Émile Ré <emile@probo.com>
This commit is contained in:
@@ -71,6 +71,8 @@ if err != nil {
|
||||
}
|
||||
```
|
||||
|
||||
MCP clients commonly authenticate with OAuth2 access tokens. Every action passed to `Authorize` must also appear in the owning package's `OAuth2ScopeMappings` (see [OAuth2 API scopes](authorization.md#oauth2-api-scopes)). Role policies alone are not enough — unmapped actions fail closed with insufficient scope. Personal API key e2e clients skip this gate, so do not treat a green MCP e2e as proof that OAuth2 works.
|
||||
|
||||
## Common resolver patterns
|
||||
|
||||
**List with pagination:**
|
||||
|
||||
Reference in New Issue
Block a user