Server-side Primary Role authorization for connectors
We are building custom Community widgets with role-based visibility. Our widgets check the viewer’s Primary Role before loading their content modules, but we also need server-side authorization to prevent unauthorized users from calling the connectors directly.
Does Developer Studio support a server-enforced Primary Role allowlist per connector, rejecting unauthorized requests before the upstream API call? The documented template user context exposes identity but not Primary Role. Is there a supported authorization mechanism or conditional authorization step for composite connectors?
Separately, does segment-based Widget Visibility prevent custom-widget scripts from loading and init()from running, or does it only hide the widget?