Fix proper token scoping and permission enforcement
Now: - Global tokens (aisbf.json) ONLY access global endpoints - User tokens (database) ONLY access their own /api/u/<username> endpoints - No cross-access possible - Admin users still have full access
Showing
Please
register
or
sign in
to comment