feat: RBAC P2 (autorisation par permission + garde de session + /api/me) #12
No reviewers
Labels
No labels
auto-merge
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference: AcadeNice/corentin_wakdo#12
Loading…
Add table
Reference in a new issue
No description provided.
Delete branch "feat/p2-rbac"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
RBAC P2 : couche d'autorisation et cablage de la garde de session.
chaque appel (10.4 RG-3) ; un role desactive ne confere rien.
place dans App\Controllers pour ne pas inverser la dependance du Core.
Premier consommateur reel du SessionGuard.
Qualite : 110 tests (unit + integration DB auto-skippee, dont un garde anti-regression du predicat
role.is_active contre le schema reel), PHPStan L6 vert, /api/me valide en E2E. Revue adversariale
passee (3 findings corriges, 1 refute by-design).
Base volontaire : dev.