mirror of https://github.com/veypi/OneAuth.git
fix(api/settings): add admin permission check for settings update
Add permission check in settings update API to ensure only admin users can modify system settings. This fixes a security vulnerability where any authenticated user could modify critical configurations. - Check 'setting:update' permission before allowing updates - Return 403 Forbidden for non-admin usersmaster
parent
4a57017067
commit
9dc866315f
Loading…
Reference in New Issue