SIGN IN SIGN UP

[fix] Scope /m permission checks to the requested project (#7242)

* fix(mobile): scope permission checks to the requested project

Without an explicit project_id query param, the auth middleware resolves
the request scope to the workspace's default project. The access check
then compares that default project against the requested scope_id and
denies every permission on a non-default project, which disabled the
custom-secret Attach button (and other edit_secret gates) there.

* test(api): pin the permission-check scope contract; docs per review

Codex review follow-ups: document on check_permissions that scope_id
asserts the authenticated scope (it never selects it), add a regression
test for the 403 on a scope mismatch, and shorten the client comment.

---------

Co-authored-by: Mahmoud Mabrouk <mmabrouk@users.noreply.github.com>
M
Mahmoud Mabrouk committed
5b3ea6f03ba9e7f1cf4053048c1ce7b56a440652
Parent: 0ae3423
Committed by GitHub <noreply@github.com> on 9/29/2026, 5:04:51 PM