Add the staff permissions audit report.

A role-by-role audit of who can do what across the backend API, the
admin frontend, Better Auth, the photo API and the deployment config.
It records the effective permission matrix for admin, organizer, staff
and marketing, where the frontend drifts from what the API actually
allows, and a prioritised remediation plan.

Committed as a reference for that remediation work; the findings in
section 11 describe the current state, not fixes.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
Michilis
2026-09-14 21:16:21 +00:00
co-authored by Claude Fable 5.1
parent 9cc330030b
commit a70333f5e4
File diff suppressed because it is too large Load Diff