Config is always served on the root-group route — the subgroup variant
(…/subgroups/{sgid}/nodes/{nid}/config) does not exist in the backend
(verified against the backend source: the gateway defines only PUT/DELETE on
subgroup nodes). Subgroup-scoped users still pass the access check here
because the user↔group mapping is keyed on the root group id.
Fetch node config from the cloud.
Config is always served on the root-group route — the subgroup variant (
…/subgroups/{sgid}/nodes/{nid}/config) does not exist in the backend (verified against the backend source: the gateway defines only PUT/DELETE on subgroup nodes). Subgroup-scoped users still pass the access check here because the user↔group mapping is keyed on the root group id.