Restrict APP REST API for users with account and capabilities

Restrict APP REST API for users with account and capabilities

tech