Prevent PM in org A from assigning linguist/reviewer from org B. Added _assert_user_in_job_org() helper that resolves job org_id (with project fallback) and checks db.memberships for the assignee. Also added assert_user_in_org() and get_job_or_403() to core/authz.py for use in upcoming MT-13 and MT-15 commits. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| authz.py | ||
| config.py | ||
| database.py | ||
| dependencies.py | ||
| logging.py | ||
| redis.py | ||
| secrets_config.py | ||
| security.py | ||
| seed.py | ||