mirror of
https://github.com/penpot/penpot.git
synced 2026-08-08 05:48:50 +00:00
* 🐛 Restrict webhook edit/delete to team members only Remove the creator-id fallback from get-webhooks-permissions. Previously, the webhook creator could always edit/delete their webhook even after being removed from the team. Now can-edit comes from team role only — removed users get :not-found. Webhooks are NOT deleted on member removal; the team owns them and team admins/owners manage them. AI-assisted-by: mimo-v2.5-pro * 🐛 Restrict webhook creation to team editors Use team role check (check-edition-permissions!) for create-webhook instead of the custom check that allowed any team member to create webhooks via creator-id self-match override. AI-assisted-by: mimo-v2.5-pro