Add backend validation to block Everyone role modifications

FeatureSecurityService
Shipped
October 16, 2025 at 2:18 AM UTC
Author
snadjafinia
Commit
e94913d

- Added protection check in updateRole endpoint - Added protection check in deleteRole endpoint - Returns 403 Forbidden when attempting to modify protected roles - Checks isAllowDelete field before allowing operations - Clear error messages in response - Logs all attempted violations for security monitoring - Prevents any backdoor modification of Everyone role

All changes

Like what you see shipping?

Every one of these updates lands in your workspace automatically. Start free and watch it grow week after week.

Start Free ForeverView Pricing