about summary refs log tree commit diff
path: root/gn_auth/errors
diff options
context:
space:
mode:
authorClaude Sonnet 4.62026-08-27 14:44:56 +0000
committerFrederick Muriuki Muriithi2026-08-27 10:17:50 -0500
commit0e21fb99310dfdd776e9b974572ee231d8f8c75b (patch)
tree03f65e823c45faa735cd9f5968e83eb9c081722a /gn_auth/errors
parent522865ba4e792b8ae0ed4b4dc5c65be821a03359 (diff)
downloadgn-auth-0e21fb99310dfdd776e9b974572ee231d8f8c75b.tar.gz
feat(users/admin): implement POST /auth/user/<uid>/roles/assign
Checks resource:user:assign-role via can_assign_role (gn_libs.privileges.resources)
on the caller's roles for the request's resource_id — caller must hold
resource-owner (or masquerade as one) on that resource.

Updates test setup to grant resource-owner on SYSTEM_RESOURCE instead of
system-administrator, matching the actual privilege model.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Reviewed-By: Frederick M. Muriithi <fredmanglis@gmail.com>
Diffstat (limited to 'gn_auth/errors')
0 files changed, 0 insertions, 0 deletions