feat: complete NX9-Auth management and integrity hardening

This commit is contained in:
thakares committed 2026-07-24 16:18:48 +05:30
1 parent dc5417334b
commit a969f9c571
59 files changed
+6508 -290

No files matched your search

+18
View File
@@ -61,6 +61,24 @@ Existing applications upgraded from earlier schemas receive a stable Client ID.
> **Protocol boundary:** Application credentials, redirect URIs, and scopes form the application registration layer. Redirect URIs are registration metadata intended to become security-enforced redirect destinations when OAuth2/OIDC protocol handlers are implemented. This registration subsystem does not by itself claim complete OAuth2/OIDC grant-flow support.
### Application user membership
Registered applications can be assigned existing NX9-Auth users (same-tenant only). Membership is independent of application client credentials and of global RBAC:
| Concern | Role |
| --- | --- |
| Application credentials | Authenticate the registered application itself (`client_id` + `client_secret`) |
| Application membership | Assign existing human users to an application (`owner` / `admin` / `member` metadata) |
| Global RBAC | Authoritative admin authorization (`applications:manage`, roles, permissions) |
Membership APIs (all require `applications:manage`):
- `GET/POST /api/v1/applications/:id/members`
- `PATCH/DELETE /api/v1/applications/:id/members/:user_id`
- `GET /api/v1/users/:id/applications`
Membership roles do **not** grant `applications:manage` or any other global permission. Removing membership revokes application assignment only; it does not delete the user account.
---
## Runtime Lifecycle