Skip to content

docs: root operator permissions load under their own tenant; claim strategy authenticates on its own - #255

Merged
iammukeshm merged 2 commits into
fullstackhero:mainfrom
marcelo-maciel:docs/root-operator-permissions-home-tenant
Sep 28, 2026
Merged

iammukeshm merged 2 commits into
fullstackhero:mainfrom
marcelo-maciel:docs/root-operator-permissions-home-tenant

Conversation

@marcelo-maciel

Copy link
Copy Markdown
Contributor

Docs for fullstackhero/dotnet-starter-kit#1404 (fixes fullstackhero/dotnet-starter-kit#1403).

  • cross-cutting-concerns/caching.mdx: a root operator's permission set is loaded under the operator's own tenant, so a cross-tenant request keeps working when the cache entry is cold.
  • architecture/multitenancy-deep-dive.mdx and modules/multitenancy.mdx: the strategy-chain comments and the callout no longer call the claim strategy a pre-auth no-op. In Finbuckle 10.1.0 it runs the default scheme's handler itself, so an authenticated caller always resolves to its own tenant claim and the tenant header only decides for anonymous requests.
  • guides/operator-impersonation.mdx: the pointer sentence says why the root override has to run after authentication.
  • Changelog entry for 2026-09-28.

npx astro check: 0 errors, 0 warnings.

# Conflicts:
#	src/content/docs/changelog/index.mdx
@iammukeshm
iammukeshm merged commit 2951746 into fullstackhero:main Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Root operator gets a random 401 on cross-tenant requests when its permission cache entry is cold

2 participants