Security: Add authorization checks to controllers #14
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
Controllers lack authorization checks. Any authenticated user can perform CRUD operations on all resources.
Location
backend/app/Http/Controllers/Api/V1/TeamMemberController.phpbackend/app/Http/Controllers/Api/V1/ProjectController.phpAcceptance Criteria
Related