Skip to content

RBAC/auth on the unified shell (viewer + operator roles) #47

Description

@CodeBuildder

Context

Basic JWT authentication with viewer (read-only) and operator (can approve actions) roles. Parent: #46.

Acceptance Criteria

  • Shell requires authentication (JWT or session cookie)
  • Viewer role: read-only, cannot approve actions
  • Operator role: full access including action approval
  • Unauthorized approval attempt returns 403 and is logged to audit trail

Dependencies

Blocked by: none | Blocks: none

Notes

No model tier.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions