vertx-web icon indicating copy to clipboard operation
vertx-web copied to clipboard

Check scopes/authz before invoking user handler/eventbus address

Open pmlopes opened this issue 4 years ago • 0 comments

OpenAPI module creates a router with security setup, however the way oauth2 works is that the requested scopes may be not be granted by the IdP so the returned token doesn't necessarely contain the required scopes.

We need to use the AuthorizationHandler before the user handler is called to ensure that the requested scopes are allowed.

pmlopes avatar Mar 16 '21 11:03 pmlopes