OAuth2 authorization for project and custom project-specific user role

Viewed 471

I'm new to OAuth2 and trying to figure out what is the best practice for the following scenario:

  • I'm implementing 'ToDo' web service (CRUD for 'tasks')
  • I'm using OAuth2 and Google as auth provider to get user details (email, name)
  • Now I need to implement project-specific roles for users ('admin', 'user')

Speaking in terms of OAuth2 - Google doesn't 'own' my service, so it cannot help me with storing/providing 'ToDo'-specific roles, is it correct?

What is the common/best approach to implement it, do I need to create my own authorization service where I'll need to store relations like userinfo -> project-specific role?

3 Answers
Related