Description
API lacks fine-grained access control. Implement RBAC with roles, permissions, and resource-level authorization.
Acceptance Criteria
Technical Scope
- api/src/middleware/
- api/src/controllers/
- Edge: permission explosion, role hierarchy resolution, temporary elevation
Description
API lacks fine-grained access control. Implement RBAC with roles, permissions, and resource-level authorization.
Acceptance Criteria
Technical Scope