Permission refresh at token issuance
Auto-generated from the source archive. Do not edit by hand — rerun
catalyst-changelog-syncinstead.
What changed
Section titled “What changed”- All three OAuth grants (password, authorization_code, refresh_token) now refresh the account’s denormalized
dPermissionssnapshot from its current roles and permissions at issuance, persisting it only when it actually changed. - The cross-BC account loader (
IAccountLoader.loadById) gains an opt-inrefreshPermissionsoption; without it, behavior is exactly as before. - The refresh is fail-soft: if the recompute or its persistence fails, tokens are still issued with the stored snapshot — a login is never blocked by the maintenance step.
Why it matters
Section titled “Why it matters”Granting or revoking a permission on a role previously never reached the accounts holding that role: the snapshot was only recomputed when the account itself was edited, so authorization ran against stale data indefinitely. Now the contract is simple — a role permission change takes effect at the user’s next login or token renewal, plus at most the five-minute guard cache. Token response shapes, JWT claims, and all grant validations are unchanged.