Grant top-level org owners cross-org delete/update access

FixSecurityService
Ya
12 Mei 2026, 01:49 UTC
Mwandishi
Kamo
Ahadi ya
e06fa5e

deleteDomain and updateDomain previously rejected platform admins operating on child-org domains because they checked isUserOwnerOfOrg against the target org directly, with no bypass for top-level org owners — unlike the read flows (getAllDomains, getDomainById). Net effect: a top-level admin could view a child org's domain but silently 403 on any attempt to change or remove it. Reuse hasElevatedCrossOrgAccess (top-level owner / system member) so both write flows match the read flows. Also log the rejection so the silent 403 is no longer invisible to debugging.

Mabadiliko yote

Je, unaona nini kuhusu usafiri?

Kila moja ya hizi updates ardhi katika nafasi yako ya kazi moja kwa moja. Kuanza bure na kuangalia kukua wiki baada ya wiki.

Kuwa Huru MileleMtazamo wa bei