check group based access since yutian was able to use my endpoint and he is not part of my keycloak group