Scope personal API tokens to an organization #19

Merged
alice merged 1 commit from feat/tokens-org-id into main 2026-08-28 10:46:28 +00:00
Owner

Tokens were previously scoped only to an account, with org permissions applied implicitly at request time. This adds org_id to the token model and requires it (with a membership check) on creation, so a token is explicitly tied to one org.

  • api_tokens.org_id column (indexed, not null)
  • POST /api/tokens requires org_id and verifies the caller belongs to that org
  • GET /api/tokens returns org_id per token
  • Existing token tests updated for the new signature

Companion frontend change: render-dmarc-ui#(see linked PR)

Tokens were previously scoped only to an account, with org permissions applied implicitly at request time. This adds `org_id` to the token model and requires it (with a membership check) on creation, so a token is explicitly tied to one org. - `api_tokens.org_id` column (indexed, not null) - `POST /api/tokens` requires `org_id` and verifies the caller belongs to that org - `GET /api/tokens` returns `org_id` per token - Existing token tests updated for the new signature Companion frontend change: render-dmarc-ui#(see linked PR)
Scope personal API tokens to an organization
All checks were successful
Go lint / lint (pull_request) Successful in 1m21s
service-dmarc-api CI / build-and-push (pull_request) Successful in 3m35s
a44b27a618
Tokens were only scoped to an account, with org permissions applied
implicitly. Add org_id to the token model and require it (with a
membership check) on creation so tokens are explicitly tied to one org.
alice merged commit 05eac4b26d into main 2026-08-28 10:46:28 +00:00
alice deleted branch feat/tokens-org-id 2026-08-28 10:46:28 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
dmarc-ing/service-dmarc-api!19
No description provided.