chiappa
|
c9f9a45664
fix: accept nullable email on /auth/users/upsert-oidc (SEC_REVIEW F33)
|
4 napja |
chiappa
|
57ab1ba034
fix: audit `GET /auth/users/{id}` lookups to detect enumeration (SEC_REVIEW F17)
|
5 napja |
chiappa
|
400674340e
fix: harden local-admin lookup against is_local-flip tamper (SEC_REVIEW F12)
|
5 napja |
chiappa
|
8d948ae676
fix: make admin audit emit transactional with mutation (SEC_REVIEW F4, F5)
|
5 napja |
chiappa
|
8a94dff6ae
fix: enforce single local-admin row in upsertLocal (SEC_REVIEW F3)
|
5 napja |
chiappa
|
8cf73d2833
feat(M03): api auth foundations — tokens, RBAC, BFF impersonation
|
1 hete |