User can define access rights to LOs via ACL by using internal API
- Default: No access rights to a particular LO
- Priliminary token simulated until authentication via OpenID Connect is implemented
- Group rights are out-of-scope in first step
- Access rights can be deleted via API
- ACLs can be requested via API (GET)
- Clarify: Who gains which access rights to a newly created LO by default and how? --> No implementation at this stage!
Edited by Volker Wassmuth