Impersonation tokens still need target-user authorization
When support or admin tooling mints an impersonation / "act as" token, validating that the operator is allowed to impersonate is only half the check. Every subsequent read and write must still authori
authbyexample.hashnode.dev1 min read