Authentication
Permissions and Roles
How to classify who may call each route and what permission evidence is required.
First created Last updated
End-to-end developer runbook
- Step 1 - Confirm the API area: Identify the product area, route module, endpoint path, and consumer before writing or calling code.
- Step 2 - Read the endpoint contract: Check method, auth, parameters, response, errors, side effects, and related docs.
- Step 3 - Prepare authentication and input: Use the right session, bearer token, webhook secret, or internal header. Validate body and query data before sending it.
- Step 4 - Make the request: Call the endpoint from the correct origin and environment. Keep credentials and secrets out of logs.
- Step 5 - Verify response, side effects, and records: Confirm status code, response shape, database records, external side effects, and audit evidence.
- Step 6 - Add tests, docs, and handoff notes: Update route inventory, consumer notes, and certification checks before depending on the change.
Role classification
- Action 1 - Classify the route: Public, dashboard-authenticated, rego-authenticated, partner-admin, event-scoped, platform-admin, webhook, internal, or test-only.
- Action 2 - Find enforcement source: Link the middleware, helper, or inline check that proves the role.
- Action 3 - Check record scope: Verify partner ID, event ID, attendee ID, staff profile ID, or payment account scope.
- Action 4 - Document escalation: If only FPH staff or platform admins can call it, say why.
Permission matrix
| Caller | Typical route group | Required proof |
|---|---|---|
| Public user | contact, public waitlist, public integration callback | validation, abuse controls, signed state where applicable |
| Attendee | rego, fursonas, social, rego notices | rego session and attendee/event scope |
| Partner operator | events, reports, admin, finance, HR | dashboard session plus partner/event permission |
| Platform admin | network bans, org control, test tooling | dashboard session plus elevated role |
| System | hooks, cron, test control | signed webhook, shared secret, or guarded internal header |