7a7fd760812d2f547158cb21586f4aba3bfbfaef
H8: enabling the residentialAccess flag grants the full residential CRUD set, so a non-super-admin caller must now hold those leaves themselves to grant it — closes the escalation back door around the role-superset check. M12: an admin can no longer change their OWN isActive / roleId / residentialAccess (self-lockout / self-escalation), mirroring the permission-override route's self-target block. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Description
No description provided
Languages
TypeScript
98.7%
HTML
1%
CSS
0.1%
Shell
0.1%