Skip to content

security: restrict consequential mutations to admin and owner - #178

Merged
GoddeyUwamari merged 1 commit into
mainfrom
security/auth-consequential-mutations
Oct 6, 2026
Merged

GoddeyUwamari merged 1 commit into
mainfrom
security/auth-consequential-mutations

Conversation

@GoddeyUwamari

Copy link
Copy Markdown
Owner

Closes the Viewer/Member authorization gap on consequential AWS-triggering, outbound, and billing mutations. Preserves existing authentication, organization scoping, plan gates, and rate limits. No changes to #175 workspace routes or other out-of-scope authorization surfaces.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@vercel

vercel Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
devcontrol Ready Ready Preview Oct 6, 2026 4:14am UTC

@GoddeyUwamari
GoddeyUwamari merged commit e8ab3a8 into main Oct 6, 2026
6 checks passed

This branch was successfully deployed

1 active deployment
Preview — 63dc5e5b Deployed Oct 6, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant