Skip to content

security: onboarding & admin privilege hardening (3 fixes)#45

Merged
BunsDev merged 7 commits into
mainfrom
consolidate/onboarding-admin
Jun 15, 2026
Merged

security: onboarding & admin privilege hardening (3 fixes)#45
BunsDev merged 7 commits into
mainfrom
consolidate/onboarding-admin

Conversation

@BunsDev

@BunsDev BunsDev commented Jun 15, 2026

Copy link
Copy Markdown
Member

Batches 3 Codex security fixes: onboarding admin privilege, admin privilege escalation (x2).

BunsDev and others added 7 commits June 3, 2026 05:36
# Conflicts:
#	apps/web/src/lib/server/functions/__tests__/onboarding.test.ts
#	apps/web/src/lib/server/functions/onboarding.ts
# Conflicts:
#	apps/web/src/lib/server/functions/__tests__/onboarding.test.ts
#	apps/web/src/lib/server/functions/onboarding.ts
# Conflicts:
#	apps/web/src/routes/api/cloud/__tests__/bootstrap.test.ts
Copilot AI review requested due to automatic review settings June 15, 2026 13:19
@BunsDev BunsDev merged commit d76340f into main Jun 15, 2026
2 of 3 checks passed
@BunsDev BunsDev deleted the consolidate/onboarding-admin branch June 15, 2026 13:20

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Note

Copilot was unable to run its full agentic suite in this review.

Updates the cloud bootstrap API test expectations to reflect tightened authentication/authorization behavior as part of admin privilege hardening.

Changes:

  • Adjusts the bootstrap test to require that getAuth is invoked during the request handling path.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants