restfulobjects/restfulobjects-spec

v1.1.0 - B7 - Domain Services Resource - filtered based on user's permissions

runrightfast opened this issue · 0 comments

Should the list of available services that are returned be filtered based on the user's permissions? I believe they should be because no links should be returned that are not accessible based on the user's permissions.

If the answer is yes, then the caching headers should be short-term. I would recommend using USER_INFO because the list of available services are specific to the user.