Skip to main content

Module admin_scope

Module admin_scope 

Source
Expand description

Admin scope guard for JWT-authenticated admin requests.

When admin routes receive a JWT (rather than a raw admin_token), the guard verifies that the JWT’s scope claim contains fraiseql:admin. Bearer-token authenticated requests (using admin_token) bypass this check entirely for backwards compatibility.

The guard is additive: it does not replace bearer-token auth. Routes that use the guard should apply it after the bearer-auth middleware.

Constants§

ADMIN_SCOPE
The required scope claim value for admin API access via JWT.

Functions§

has_admin_scope
Check whether a space-delimited scope string contains the fraiseql:admin scope.
require_admin_scope
Validate that a JWT scope claim authorizes admin access.