Kong validates the JWT but doesn't populate req.user on the backend. The middleware now decodes the JWT payload to extract user info (id, email, tenantId, roles) so RolesGuard can check role-based access. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| common | ||
| database | ||
| events | ||
| proto | ||
| testing | ||