21 lines
678 B
Markdown
21 lines
678 B
Markdown
|
|
# AuthZ Policy Propagation (fs_003)
|
||
|
|
|
||
|
|
## Objective
|
||
|
|
Introduce deny-by-default RBAC policy and propagate through backend auth middleware, endpoint guards, frontend route guards, and admin policy editor.
|
||
|
|
|
||
|
|
## Language & Library Constraints
|
||
|
|
- Primary language: python
|
||
|
|
- Available libraries: fastapi, pydantic, sqlalchemy
|
||
|
|
- Prefer explicit use of selected library APIs in task execution contracts.
|
||
|
|
|
||
|
|
## Required Artifacts
|
||
|
|
- server/auth/*.py
|
||
|
|
- server/routes/*.py
|
||
|
|
- web/src/guards/*
|
||
|
|
- web/src/admin/policy/*
|
||
|
|
- security_test_plan.md
|
||
|
|
|
||
|
|
## Acceptance
|
||
|
|
- Generate deterministic taskitems with strict execution contracts.
|
||
|
|
- Include selected library and preferred APIs per task where applicable.
|