Security breach identified

Field-level write restrictions on User entity — currently any authenticated user can call updateMe({ is_head_admin: true }) from the browser console. Need server-write-only field support in entity schema.

Please authenticate to join the conversation.

Upvoters
Status

In Review

Board
💡

Feature Request

Date

About 2 hours ago

Author

Moshe Polter

Subscribe to post

Get notified by email when there are changes.