I needed some fancy authorization logic, so i've added my own custom AuthorizationHandler (https://docs.microsoft.com/en-us/aspnet/core/security/authorization/policies?view=aspnetcore-3.1). Basically the gist of it is that you add an attribute to your API that specifies the required set of permissions, and the custom logic just makes sure the user has those permissions.
[CustomAttribute("PermissionX", "PermissionY")]
MyApi()
This will make sure the user has PermissionX and PermissionY, otherwise the request to this API will fail. My issue is that when a user calls this API, they just get a 403 back without any information. If the user has PermissionX, but not PermissionY, I'd like the 403 to have a message like "Missing permissionY" instead of just a generic 403.
I've found some old discussions about this from a few years ago, but the conclusion was that a solution was being worked on and it wasn't yet possible. This was a while ago though, and i haven't seen any recent updates. Is there some way to do this yet? I'm fine adding some higher level middleware, I just don't know how that would work right now.