FastAPI authentication is pretty well documented. Role-based access control (RBAC) is not always that intuitive though. π€ I have seen `if "Admin" not in user.roles: raise 403` hardcoded across differ
FastAPI authentication is pretty well documented. Role-based access control (RBAC) is not always that intuitive though. π€ I have seen `if "Admin" not in user.roles: raise 403` hardcoded across different routes. Ok so use a decorator, but what about changing roles over time?