Files
metacrypt/internal/engine/engine.go
Kyle Isom 7f9e7f433f Treat authenticated callers with no roles as service accounts
MCIAS service tokens have nil roles and may not return account_type
in the validate response. Recognize authenticated callers with a
username but no roles as service accounts for IsUser() purposes.
Explicit guest role still blocks access.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
2026-03-25 20:19:14 -07:00

11 KiB