Scenario: How would you implementfine-grained, resource-based authorizationin anASP.NET Core Web API? For example, ensuring a user can only editdocuments they own.