Expand description
Admin scope guard for JWT-authenticated admin requests.
When admin routes receive a JWT (rather than a raw admin_token), the guard
verifies that the JWT’s scope claim contains fraiseql:admin. Bearer-token
authenticated requests (using admin_token) bypass this check entirely for
backwards compatibility.
The guard is additive: it does not replace bearer-token auth. Routes that use the guard should apply it after the bearer-auth middleware.
Constants§
- ADMIN_
SCOPE - The required scope claim value for admin API access via JWT.
Functions§
- has_
admin_ scope - Check whether a space-delimited scope string contains the
fraiseql:adminscope. - require_
admin_ scope - Validate that a JWT scope claim authorizes admin access.