Allow system user to manage org branding and fix logo auth

FixSecurityService
Ya
25 Aprili 2026, 16:20 UTC
Mwandishi
Kamo
Ahadi ya
bc36235

- Add system user bypass as first guard in canManageOrgBranding so platform system user has full branding control over all non-parent orgs - Fix uploadLogo endpoint which had a raw org-owner-only check that bypassed both canManageOrgBranding and god-mode, causing 403 for system user

Mabadiliko yote

Je, unaona nini kuhusu usafiri?

Kila moja ya hizi updates ardhi katika nafasi yako ya kazi moja kwa moja. Kuanza bure na kuangalia kukua wiki baada ya wiki.

Kuwa Huru MileleMtazamo wa bei