Matt
4b9743a594
audit: 33-agent comprehensive audit + critical fixes
Full team audit run, all reports verbatim in docs/AUDIT-2026-05-12.md
(5900+ lines, 30+ critical findings). Already-fixed this commit:
- permission-overrides PUT: self-target block + RolePermissions allow-list + cross-tenant guard
- /api/auth/resolve-identifier: rate-limit + synthetic miss-email kill enumeration
- admin email-change: rotates account.accountId + revokes sessions
- middleware: token-gated email confirm/cancel routes whitelisted
- NAV_CATALOG: 10 dead-link sweeps to existing /admin/<x> targets
Feature work landing same commit: optional username sign-in
(migration 0054), per-user permission overrides (0055) with three-state
matrix tabbed inside UserForm, user disable button, role + outcome +
stage label normalisation across the platform, admin email-change
with auto-notification template.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-12 16:52:35 +02:00
..
2026-05-04 22:57:01 +02:00
2026-05-12 15:28:22 +02:00
2026-05-05 12:49:53 +02:00
2026-05-07 21:45:42 +02:00
2026-05-09 04:14:29 +02:00
2026-05-04 22:57:01 +02:00
2026-05-11 13:47:52 +02:00
2026-05-11 13:01:47 +02:00
2026-05-05 13:46:54 +02:00
2026-05-04 22:57:01 +02:00
2026-05-05 03:38:47 +02:00
2026-05-04 22:57:01 +02:00
2026-05-12 15:28:22 +02:00
2026-05-04 22:57:01 +02:00
2026-05-07 21:02:12 +02:00
2026-05-04 22:57:01 +02:00
2026-05-11 13:01:47 +02:00
2026-05-09 19:17:58 +02:00
2026-05-05 13:46:54 +02:00
2026-05-07 21:45:42 +02:00
2026-05-08 02:20:27 +02:00
2026-05-12 16:52:35 +02:00
2026-05-06 23:48:59 +02:00
2026-05-12 15:28:22 +02:00