FastAPI authentication is pretty well documented. Role-based access control (RBAC) is not always that intuitive though. πŸ€” I have seen `if "Admin" not in user.roles: raise 403` hardcoded across differ

FastAPI authentication is pretty well documented. Role-based access control (RBAC) is not always that intuitive though. πŸ€” I have seen `if "Admin" not in user.roles: raise 403` hardcoded across different routes. Ok so use a decorator, but what about changing roles over time?

1 reportother

Claim audit

No BS check run yet β€” press βš– to extract this story's claims and verify them against independent sources.

All coverage

FastAPI authentication is pretty well documented. Role-based access control (RBAC) is not always that intuitive though. πŸ€” I have seen `if "Admin" not in user.roles: raise 403` hardcoded across differ

mastodon:fosstodonother20d ago kagi β†—

FastAPI authentication is pretty well documented. Role-based access control (RBAC) is not always that intuitive though. πŸ€” I have seen `if "Admin" not in user.roles: raise 403` hardcoded across different routes. Ok so use a decorator, but what about changing roles over time?