UpdateUserAction and CreateUserAction were calling syncPermissions() which wrote to model_has_permissions table directly. This meant permissions persisted even after being removed from the role. Now users only get permissions through their roles.
UpdateUserAction and CreateUserAction were calling syncPermissions() which wrote to model_has_permissions table directly. This meant permissions persisted even after being removed from the role. Now users only get permissions through their roles.