Returns the first requested right a derivation may not carry: one the original token does not cover and derivableBeyond() does not allow.
derivableBeyond()
the original token's access rights
the access rights asked for, every token's together
passed to derivableBeyond()
the right, or null when every one is derivable
Returns the first requested right a derivation may not carry: one the original token does not cover and
derivableBeyond()does not allow.