Skip to content

fix/invite permisisons#3240

Merged
ajhollid merged 5 commits intodevelopfrom
fix/invite-permisisons
Feb 4, 2026
Merged

fix/invite permisisons#3240
ajhollid merged 5 commits intodevelopfrom
fix/invite-permisisons

Conversation

@ajhollid
Copy link
Collaborator

@ajhollid ajhollid commented Feb 4, 2026

Fixes a vulnerability whereby a user is able to create an invite with a role that has permissions >= their own role. A user should only be able to create invites with permissions < their own.

@ajhollid ajhollid merged commit 18018ce into develop Feb 4, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant