Hi Konstantin,
Thank you for your response. I understand the explanation regarding the use of the “integration user” for operations in the service via the Client Credentials Grant flow.
As you mention in the Jmix documentation, the Resource Owner Password Credentials Grant is not considered sufficiently secure in certain scenarios and is already deprecated in the OAuth 2.1 standard. Given this, I would like to know if there is an alternative way to log the actual user performing the modification instead of the client application itself in the Audit add-on, while ensuring compliance with OAuth 2.1 recommendations.
Could you please advise on a secure and standard approach to achieve this?
Best regards,
Francesc