Dynamic Link Generation Based on OAuth2 User Permissions
Most REST APIs treat pagination and navigation as a solved problem, and then quietly ignore a much messier one: what happens when two different users hit the same endpoint and get back two very different sets of things they're allowed to do? A manager sees an "approve" link on an order.
