I have now added per-app access control to the authentication system. Apps can be registered by super admins, with client IDs and client secrets generated that must be implemented in the individual apps. Super admins can then open up access to users on an app-by-app basis.


