1. Allow "*_ref" to be an acceptable field in the request.
2. Enable support for relationship fields in the request such as "_fields=manager/*".
Since enable *_ref as acceptable, filtering will need to be done on which relationships are shown based on privilege attributes.
This will require collecting applicable privileges for the resource collections of the relationship field(s) and adding them to the PrivilegeContext.
These collected privileges for relationship fields will need to be added for the content filtering support as well.
Content filtering support needs adjustments made to the way attributes are allowed through privileges and pointers to fields such as authzRoles/0/name.