buster/packages
dal 2e04af1785
fix: address additional critical PR review comments
- Fixed permission hierarchy: full_access (5) now correctly ranks higher than viewer (3)
- Removed 'querier' role from admin permission check as it was too permissive
- Added organizationId parameter to dashboard access checks to prevent unauthorized access
- Fixed public dashboard expiry date check to verify dates are in the future
- Added cycle detection for collection permissions to prevent infinite recursion
- Fixed bulk remove permissions to correctly filter by identityIds array
- Updated date comparison to use ISO string format for PostgreSQL timestamp columns

These fixes address critical security and logic issues identified in the PR review.

🤖 Generated with [Claude Code](https://claude.ai/code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-07-29 12:28:58 -06:00
..
access-controls fix: address additional critical PR review comments 2025-07-29 12:28:58 -06:00
ai feat(access-controls): migrate Rust access control libraries to TypeScript 2025-07-28 10:17:35 -06:00
data-source dry run 2025-07-25 18:29:35 -06:00
database fix: address additional critical PR review comments 2025-07-29 12:28:58 -06:00
env-utils slack markdown fixes 2025-07-21 17:35:58 -06:00
rerank dry run 2025-07-25 18:29:35 -06:00
sandbox dry run 2025-07-25 18:29:35 -06:00
server-shared fix: address additional critical PR review comments 2025-07-29 12:28:58 -06:00
slack dry run 2025-07-25 18:29:35 -06:00
stored-values dry run 2025-07-25 18:29:35 -06:00
supabase Update inlcude 2025-07-12 23:46:09 -06:00
test-utils dry run 2025-07-25 18:29:35 -06:00
typescript-config update package.json pass if no unit tests 2025-07-17 23:03:54 -06:00
vitest-config fix weird vite 7 error 2025-07-23 15:57:44 -06:00
web-tools dry run for these two bad boys 2025-07-25 19:00:07 -06:00
tsconfig.json Update broken types 2025-07-03 09:25:29 -06:00