An authentication and authorization system based on RBAC for restful APIs
github.com
github.com
Were there any gotchas in implementing this type of identity access management system?
The scopes look like github scopes, e.g. `read:resource`. So it’s more of a capabilities based system vs an RBAC one, but we have translated roles (via LDAP group membership) to capabilities to simplify things in some cases.
Something like this is great to centralize management