Add the staff permissions audit report.
A role-by-role audit of who can do what across the backend API, the admin frontend, Better Auth, the photo API and the deployment config. It records the effective permission matrix for admin, organizer, staff and marketing, where the frontend drifts from what the API actually allows, and a prioritised remediation plan. Committed as a reference for that remediation work; the findings in section 11 describe the current state, not fixes. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Fable 5.1
parent
9cc330030b
commit
a70333f5e4