Skip to main content

Auth: hbf-media-manager

How this service handles authentication. Full flows: docs/architecture/auth-flows.md

Tokens This Service Accepts

Token typeWhere validatedGuard / middleware
User JWThbf-core /users/meHBFGuard

Tokens This Service Sends

CallingToken usedHow attached
hbf-coreCORE_TOKENAuthorization: Bearer <CORE_TOKEN> header

Tokens This Service Issues

None.

Roles / Scopes Enforced

Endpoint patternRequired role
Admin endpointsHBF_ORG_ADMIN (via AdminOrgRoleGuard)
Member endpointsAny org role (via MemberOrgRoleGuard)

Auth Notes

  • HBFGuard delegates token validation to hbf-core by calling /users/me.
  • Admin endpoints require HBF_ORG_ADMIN. Member endpoints accept any active org membership, including HBF_ORG_EDITOR.
  • Config: CORE_URL, CORE_TOKEN.