🔒 Security
- API: Prevented
subscription_feemutation on invoice updates to fix a business-logic bypass vulnerability that allowed wiping member balances without recording payments. - Access Control: Prevented inactive users from authenticating and accessing the application panel.
- Access Control: Prevented privilege escalation vulnerabilities during user role assignments.
🧹 Maintenance & Chores
- Testing: Adjusted test configuration settings to skip vite.
Full Changelog: v3.0.0-alpha.3...v3.0.0-alpha.4