Task library BAPIAUTH
Project scope 10 tickets / 3 phases
Total focused work estimate 27h 30m + setup
Suggested stack TypeScript · OpenAPI · PostgreSQL Fictional engineering practice briefs. Starter repositories, fixtures, automated grading, and verified ownership are not included.
Choose a bounded subset for an assessment or practice session. Prerequisites and remaining project work must be agreed separately.
Field percentages are editorial estimates of the ticket's engineering focus. They total 100%; they are not measured time, proficiency scores, or ownership evidence.
Pattern topics identify design choices to practice. Read the ticket's acceptance criteria and justify the simplest suitable approach. Tags are not capability or ownership evidence; an untagged ticket has no curated pattern topic assigned.
Recommended next step Start with BAPIAUTH-101 Open the first ticket for its prerequisites, acceptance criteria, verification plan, and an editable task draft.
What the engineer takes away Practice delegated authorization, resource scoping, and secure public API ergonomics.
What the team gains Provide usable partner access that remains least-privilege and revocable.
Before you start Create a local authorization service and synthetic partner clients for two organizations; generate disposable test credentials only. Delivery agreement Deliver local credential and access contracts; connect no real partner account.
AI tools are welcome during implementation. Record assumptions, review the result, and verify its behavior.
Delivery phases PHASE 1 Separate actor, organization, client, and permission scope.
PHASE 2 Validate resource authority and token lifecycle.
PHASE 3 Handle rotation, auditing, and migration.
Define delegated authority Separate actor, organization, client, and permission scope.
BAPIAUTH-101 Entry ticket; project setup still required BAPIAUTH-102 Depends on BAPIAUTH-101 Enforce access Validate resource authority and token lifecycle.
BAPIAUTH-103 Depends on BAPIAUTH-102 Estimated field mix
API design 40% Security 40% Privacy engineering 20% BAPIAUTH-104 Depends on BAPIAUTH-102, BAPIAUTH-103 BAPIAUTH-105 Depends on BAPIAUTH-102, BAPIAUTH-104 BAPIAUTH-106 Depends on BAPIAUTH-105 Estimated field mix
Security 70% Distributed systems 30% Support client operations Handle rotation, auditing, and migration.
BAPIAUTH-107 Depends on BAPIAUTH-104, BAPIAUTH-106 Estimated field mix
API design 50% Site reliability 30% Security 20% BAPIAUTH-108 Depends on BAPIAUTH-105, BAPIAUTH-106 Estimated field mix
Security 60% Privacy engineering 20% API design 20% BAPIAUTH-109 Depends on BAPIAUTH-107, BAPIAUTH-108 Estimated field mix
Security 50% System design 30% API design 20% BAPIAUTH-110 Depends on BAPIAUTH-109 Estimated field mix
Developer tooling 40% Security 40% API design 20% Use this project CSV keeps grouping and dependency keys as descriptive fields. Import mapping depends on your tracker configuration.