- Shipped
- September 23, 2026 at 12:42 PM UTC
- Author
- Kamo
- Commit
- 6a2418e
**************** caught the previous commit: **************** and **************** now resolve a session (getCachedOrganizationId, in each handler's own body), so the scanner no longer sees them as unguarded. Remove their lines from the baseline, per the test's own message. **************** stays listed: it resolves its org and checks CONFIGURE_SYSTEM through private helpers (getOrganizationFromRequest, refuseUnlessMayConfigure) the scanner's known limitation doesn't follow into, the same as **************** and **************** already on this list for the identical reason.
