feat(openzaak): least-privilege client scopes (WP-57)

setup_configuration has no YAML field for granular autorisaties, so
bigregister-test now starts at heeft_alle_autorisaties: false (dev + prod
template) and bootstrap-catalogus.sh grants exactly the ztc/zrc scopes the
harness needs via the Django ORM, sidestepping the zero-scope
chicken-and-egg with the JWT-authenticated Autorisaties REST API.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
eho
2026-07-30 14:05:54 +02:00
co-authored by Claude Sonnet 5
parent 89ad3490b0
commit 1e87997ea0
6 changed files with 112 additions and 13 deletions
@@ -4,8 +4,12 @@
# into it to produce the gitignored data.prod.yaml that docker-compose.openzaak.prod.yml
# mounts over the container's data.yaml.
#
# Least-privilege client scopes (heeft_alle_autorisaties: true below) are WP-57's job, not
# this WP's — left matching the dev harness on purpose.
# Least-privilege client scopes (WP-57): heeft_alle_autorisaties is false, matching the dev
# harness (setup_configuration has no YAML field for granular `autorisaties` — see
# data.yaml's comment). This template only covers infra config; a real deploy must grant this
# client's Autorisaties the same way bootstrap-catalogus.sh does for the dev harness — via
# `manage.py shell` (or the Autorisaties REST API from an already-privileged caller) against
# the production catalogus/zaaktype URLs, once, as part of standing up that environment.
sites_config_enable: true
sites_config:
items:
@@ -25,4 +29,4 @@ vng_api_common_applicaties:
client_ids:
- ${OPENZAAK_CLIENT_ID}
label: BIG-register BFF (production)
heeft_alle_autorisaties: true
heeft_alle_autorisaties: false