🔴 [P0] Add workspace authorization on incoming connections #276
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
Incoming connections created in default workspace without authorization check.
Location
apps/api/src/federation/federation.controller.ts:238-259Security Impact
Required Implementation
Priority
CRITICAL (P0) - Authorization bypass