Skip to content

fix(den-api): require fresh auth for membership changes#2263

Open
benjaminshafii wants to merge 1 commit into
devfrom
fix/security-fresh-auth-membership
Open

fix(den-api): require fresh auth for membership changes#2263
benjaminshafii wants to merge 1 commit into
devfrom
fix/security-fresh-auth-membership

Conversation

@benjaminshafii

@benjaminshafii benjaminshafii commented Jun 14, 2026

Copy link
Copy Markdown
Member

Summary

  • Require fresh privileged sessions for organization invitations and member removals.
  • Reuse existing fresh_auth_required handling and status mapping.
  • Add a security review tracker with remaining follow-ups and validation log.

Tests

  • Passed: pnpm exec bun test test from ee/apps/den-api (145 tests, 0 failures).
  • Passed: pnpm test:e2e.

Review in cubic

@vercel

vercel Bot commented Jun 14, 2026

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
openwork-app Ready Ready Preview, Comment Jun 14, 2026 8:26pm
openwork-den Ready Ready Preview, Comment Jun 14, 2026 8:26pm
openwork-den-worker-proxy Ready Ready Preview, Comment Jun 14, 2026 8:26pm
openwork-landing Ready Ready Preview, Comment, Open in v0 Jun 14, 2026 8:26pm

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 5 files

Re-trigger cubic

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant