How should the Front End handle OAuth Scopes

Viewed 41

Currently I have a Angular Application and looking for some understanding / knowledge on the best way of implementing a read / write on certain parts of my application.

I'm trying to understand how exactly OAuth scopes work.

I make a call to my server and get a token, then decoded with @auth0/angular-jwt.

In the return i can see scope: "Document: read Currier: write"

My question is How in the Front End would you use scope? I was hoping I could break it in an object with boolean values so I can hide show certain elements of a table.

Like if its Document: read The user can only read it. If its read and write they can read and edit.

Seems like it's difficult if it the permissions come in a string.

0 Answers
Related