Skip to content

docs: role permission sync removes revoked claims from built-in roles (#1426) - #266

Open
marcelo-maciel wants to merge 2 commits into
fullstackhero:mainfrom
marcelo-maciel:docs/role-permission-sync-authoritative
Open

marcelo-maciel wants to merge 2 commits into
fullstackhero:mainfrom
marcelo-maciel:docs/role-permission-sync-authoritative

Conversation

@marcelo-maciel

@marcelo-maciel marcelo-maciel commented Oct 2, 2026 •

Copy link
Copy Markdown
Contributor

Docs for fullstackhero/dotnet-starter-kit#1426 (the fix for fullstackhero/dotnet-starter-kit#1417).

The role-permission syncer section of Authorization now says the sync is authoritative for the built-in Basic and Admin roles: it removes permission claims the catalog no longer grants, logs each removal at Warning, keeps the root tenant's IsRoot permissions and leaves non-permission claims alone. The changelog entry carries the upgrade note that narrowing IsBasic or removing a permission now revokes it on existing tenants at the next start.

Also fixes a pre-existing error in building-blocks/caching.mdx: it said the RolePermissionSyncer warms the permission cache, while the syncer only invalidates it (through the permissions tag) when it adds or removes a system-role claim.

Files: src/content/docs/security/authorization.mdx, src/content/docs/changelog/index.mdx, src/content/docs/building-blocks/caching.mdx

npx astro check: 0 errors, 0 warnings.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant