I've an ASP.NET Web API with 100+ endpoints. Authentication is done using Identity Server JWT token. and the Web API is trusting a scope say "User". "User" scope will basically give full access to the user on all the end points. so no Athorization is necessary.
Now, there is a requirement to introduce a new scope say "LimitedAccessUser" which should have rights on just one endpoint. User with "LimitedAccessUser" scope shouldn't be able to call the other endpoints. I really don't want to go to all the other endpoints and force them to have "User" scope which will prevent "LimitedAccessUser" from calling those endpoints.
Is there any better way around this?