[fix] Scope /m permission checks to the requested project (#7242)
* fix(mobile): scope permission checks to the requested project Without an explicit project_id query param, the auth middleware resolves the request scope to the workspace's default project. The access check then compares that default project against the requested scope_id and denies every permission on a non-default project, which disabled the custom-secret Attach button (and other edit_secret gates) there. * test(api): pin the permission-check scope contract; docs per review Codex review follow-ups: document on check_permissions that scope_id asserts the authenticated scope (it never selects it), add a regression test for the 403 on a scope mismatch, and shorten the client comment. --------- Co-authored-by: Mahmoud Mabrouk <mmabrouk@users.noreply.github.com>
M
Mahmoud Mabrouk committed
5b3ea6f03ba9e7f1cf4053048c1ce7b56a440652
Parent: 0ae3423
Committed by GitHub <noreply@github.com>
on 9/29/2026, 5:04:51 PM