github-code/Noves-Inc/canton-data-app
Noves-Inc/canton-data-app: docs/security.md
# Security model ## Identities Use two distinct OIDC clients: - a public browser client for user sign-in; - a confidential M2M client used only by backend M2M indexing. Create a Canton user whose ID exactly matches the M2M token's `sub`. Grant only `CanReadAsAnyParty`. Leave `participantAdmin`, `ide
READ ON GITHUB-CODE ↗