DEV Community

Discussion on: A small guide to authentication and security for SPA

Collapse
 
papaponmx profile image
Jaime Rios

Neat, thanks for sharing. Do you have any suggestions for creating tenants and different user privileges in a web app?

Collapse
 
stereobooster profile image
stereobooster • Edited

Depends on what you mean. Last time I looked into authorisation thing, I guess, it was Rails app and we used cancancan for it (if I remember it right)

Collapse
 
bgadrian profile image
Adrian B.G.

Open ID scopes should handle that. The authorization server can decide which user has access to what action:resource.