API access never required the admin flag in =< 2.5.1, just that 
non-admins can only see their own stuff, and can't see broker-wide info 
at all.

The admin flag has been replaced by a "tags" field for users. Users can 
be given arbitrary tags within rabbitmq-server. rabbitmq-management then 
checks for the following tags:

"administrator" (do everything, same as admin before)
"monitoring" (look at everything, but only touch your own stuff)
"management" (limited access to mgmt, same as non-admin before)

Note also that by giving a user no tags you can lock them out of mgmt 
completely. This would be useful if (for example) you use secret queue 
names as capabilities.

Well, it's landed on default now, but you'll need default of everything. 
Not sure what all the revision numbers are.

