2 Commits
Author SHA1 Message Date
F4ilji 3860c5d24c fix(permissions): remove direct user permission sync — roles only
UpdateUserAction and CreateUserAction were calling syncPermissions()
which wrote to model_has_permissions table directly. This meant
permissions persisted even after being removed from the role.

Now users only get permissions through their roles.
2026-07-16 14:09:30 +05:00
F4ilji 936b1fb5b0 changes 2026-04-07 17:54:26 +05:00