-
Notifications
You must be signed in to change notification settings - Fork 68
Open
Labels
Description
I'm having difficulty figuring out how all the middleware and options work together.
There are three middleware: wrap-access-rules, wrap-authentication, wrap-authorization. How do these work together and which are necessary? It seems like if I use wrap-access-rules, I may omit wrap-authorization.
What options are available for backends? I see :unauthorized-handler, does a :unauthenticated-handler exist?
What options are available for wrap-access-rules? I see :rules and :on-error. Does/should :on-error handle unauthenticated requests? Unauthorized requests? When should :on-error be used instead of the :unauthorized-handler option specified in the backend?
These concerns should be better documented.
daveliepmann and tkindy