aravind changes
This commit is contained in:
@@ -28,10 +28,12 @@ var ErrNoIdentity = errors.New("no authenticated identity in context")
|
||||
|
||||
// Identity is who the request is, as resolved from the session row.
|
||||
//
|
||||
// Role is carried because Phase 3D will need it, and because carrying it now
|
||||
// means the middleware reads it once per request instead of every future
|
||||
// authorization check re-querying the user. It is NOT consulted anywhere in
|
||||
// Phase 3C: authentication only.
|
||||
// Role is read once per request by the middleware, out of the user row, so an
|
||||
// authorization check never has to re-query. It is the authorization authority:
|
||||
// httpserver.Server.authorize gates operations on it, the repository's ownership
|
||||
// predicate narrows a talent caller's rows by it, and service/definitions.go
|
||||
// checks it on every definition write. AccountType is NOT an authority — a user
|
||||
// can change their own through PATCH /me.
|
||||
type Identity struct {
|
||||
UserID string
|
||||
OrgID string
|
||||
|
||||
Reference in New Issue
Block a user