Are there any best practices for exposing resource permissions/ACL to a front end via a RESTful API? Are there any best practices for exposing resource permissions/ACL to a front end via a RESTful API? symfony symfony