Files
probo/e2e/console
Sacha Al Himdani 2ffeb7f3e8 Require set-owner authorization to create OWNER membership
An organization ADMIN could mint an OWNER membership via createUser, which
only gated iam:membership-profile:create and bypassed the owner-only
iam:membership-role:set-owner check that updateMembership already enforces.

Gate the requested role in both createUser entry points (connect resolver
and the MCP CreateUserTool) with an additional set-owner authorization when
the role is OWNER, mirroring updateMembership. Add a regression test that
locks the ADMIN/OWNER privilege boundary the fix relies on.

Signed-off-by: Sacha Al Himdani <sacha@probo.com>
2026-07-03 17:37:26 +02:00
..
2026-07-03 10:13:00 +02:00
2026-07-03 10:13:00 +02:00
2026-06-09 17:19:46 +02:00
2026-07-03 10:13:00 +02:00
2026-07-03 10:13:00 +02:00
2026-07-03 10:13:00 +02:00
2026-07-03 10:13:00 +02:00
2026-07-03 10:13:00 +02:00
2026-07-03 10:13:00 +02:00
2026-07-03 10:13:00 +02:00
2026-07-03 10:13:00 +02:00
2026-07-03 10:13:00 +02:00
2026-07-03 10:13:00 +02:00
2026-07-03 11:53:57 +02:00
2026-07-03 11:53:57 +02:00
2026-07-03 10:13:00 +02:00
2026-07-03 10:13:00 +02:00
2026-07-03 10:13:00 +02:00
2026-07-03 10:13:00 +02:00