fix(security): enforce wiki git writes and LFS token access at request time #143
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
Permission gaps in wiki Git push and LFS token handling allow bypassing access controls.
Upstream Reference
Severity: High
Write access bypass on wiki git operations and LFS token handling.
Action
Cherry-pick from upstream
release/v1.26.Authored-by: Claude Opus 4.6 (1M context) noreply@anthropic.com