Scope personal API tokens to an organization #19
Loading…
Reference in a new issue
No description provided.
Delete branch "feat/tokens-org-id"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Tokens were previously scoped only to an account, with org permissions applied implicitly at request time. This adds
org_idto the token model and requires it (with a membership check) on creation, so a token is explicitly tied to one org.api_tokens.org_idcolumn (indexed, not null)POST /api/tokensrequiresorg_idand verifies the caller belongs to that orgGET /api/tokensreturnsorg_idper tokenCompanion frontend change: render-dmarc-ui#(see linked PR)