Skip to content

v0.1.19

Choose a tag to compare

@hideyukiMORI hideyukiMORI released this 22 May 15:52
· 61 commits to main since this release
203bd74

Changed

  • Example note/tag UseCases enforce row ownership via assertResourceOwner (BOLA, FT146)
  • /examples/notes and /examples/tags require Bearer auth when examples are enabled
  • Repositories persist owner_id; list queries scoped to JWT sub

Added

  • createResourceAccessDeniedHandler wired into example module
  • Cross-user access returns 403 (not 200 leak)

Closes #98