iya-sts
    Preparing search index...
    narrowScope: (scope: unknown, subject: Subject, context?: any) => Narrowed = ...

    Type Declaration

      • (scope: unknown, subject: Subject, context?: any): Narrowed
      • Returns the scope to grant, with every gated permission the subject's roles do not authorize taken off.

        What is taken off is recorded in one audit row (STS-ADMIN-0821); the caller refuses invalid_scope when emptied is true. A scope naming nothing gated comes back unchanged.

        Parameters

        • scope: unknown

          the requested scope

        • subject: Subject

          { kind, name, authenticated }

        • Optionalcontext: any

          optional { clientId, grant } for the audit row

        Returns Narrowed

        { scope, removed, emptied, why }