Matt
4b9743a594
audit: 33-agent comprehensive audit + critical fixes
Full team audit run, all reports verbatim in docs/AUDIT-2026-05-12.md
(5900+ lines, 30+ critical findings). Already-fixed this commit:
- permission-overrides PUT: self-target block + RolePermissions allow-list + cross-tenant guard
- /api/auth/resolve-identifier: rate-limit + synthetic miss-email kill enumeration
- admin email-change: rotates account.accountId + revokes sessions
- middleware: token-gated email confirm/cancel routes whitelisted
- NAV_CATALOG: 10 dead-link sweeps to existing /admin/<x> targets
Feature work landing same commit: optional username sign-in
(migration 0054), per-user permission overrides (0055) with three-state
matrix tabbed inside UserForm, user disable button, role + outcome +
stage label normalisation across the platform, admin email-change
with auto-notification template.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-05-12 16:52:35 +02:00
..
2026-05-12 15:28:22 +02:00
2026-05-06 22:15:01 +02:00
2026-05-12 14:50:58 +02:00
2026-05-12 16:52:35 +02:00
2026-05-04 22:57:01 +02:00
2026-05-12 14:50:58 +02:00
2026-05-07 20:59:28 +02:00
2026-03-26 11:52:51 +01:00
2026-05-12 14:50:58 +02:00
2026-05-12 15:28:22 +02:00
2026-05-04 22:57:01 +02:00
2026-05-12 15:28:22 +02:00
2026-05-04 22:57:01 +02:00
2026-05-06 22:21:23 +02:00
2026-05-12 14:50:58 +02:00
2026-05-07 21:45:42 +02:00
2026-05-05 20:18:05 +02:00
2026-05-04 22:57:01 +02:00
2026-05-07 20:59:28 +02:00
2026-05-06 22:38:59 +02:00
2026-05-01 23:33:53 +02:00
2026-05-07 20:59:28 +02:00
2026-05-05 03:38:47 +02:00
2026-05-12 14:50:58 +02:00
2026-05-06 19:26:28 +02:00