We experienced something strange today. As user search v2 is deprecated, we needed to upgrade our authorization extension from v2.4 to v2.6. Our extension is configured to add permissions to the user object.
When we upgraded the extension, one of our rules (auth0-authorization-extension) changed. The permissions were no longer added to the user object, but groups were persisted in the user´s application metadata.
Did we stumble upon a bug, or is there a reasonable explanation for this?