Checks a token's access array has the shape it must: non-empty, each element a string reference or a well-formed right.
the access array
{ ok: true, access } (a deduplicated copy), or a refusal
{ ok: true, access }
Checks a token's access array has the shape it must: non-empty, each element a string reference or a well-formed right.