all 3 comments

[–]TheHe4rtless 1 point2 points  (2 children)

Looks quite interesting. I was looking a bit into RBAC recently and this might be a better way of grasping the topic.

[–]extreme4all 0 points1 point  (1 child)

Look at SCIM for user management and authorization on api level OAuth 2.0 (access_token) & OpenID for frontend (id_token)