Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 10 additions & 0 deletions crates/control-plane-api/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,16 @@ capability mask or prefix scope, because the new credential would not preserve
those restrictions. Tenant creation in `server/public/graphql/tenant.rs` also
rejects either restriction before provisioning a tenant.

`Envelope` accepts `X-Estuary-Scope-Prefix: acmeCo/` on authenticated requests.
It narrows the effective claims through the existing `prefix_scope` policy, so
clients can switch tenants using an unscoped bearer without obtaining a new token.
A token already carrying a prefix scope only accepts a matching header (using the
token's trailing-slash normalization); conflicting scopes return HTTP 400 rather
than replacing the token ceiling. Empty, malformed, or repeated headers also
return HTTP 400; a header without authentication returns HTTP 401.
Credential-creation guards apply to header-scoped requests too. No header means
unchanged token behavior. This is request scoping, not persisted credential scope.

## Development

> **NOTE:** All commands below should be run from inside the Lima VM.
Expand Down
Loading
Loading