v0.12.24 STAFF SECURITY · v0.12.25 QA DISPLAY
Admin is a role. Permission + recent strong authentication is the key.
This release separates staff role membership from exact privileged permissions and from the strong-auth state of the current session. Sensitive finance actions can require all three before the database will accept an authorization.
Automated security checks
Confirms schema v23 and deliberately attempts role, permission, session and audit bypasses.
NOT RUNSchema check has not run yet.
NOT RUNSelf-test has not run yet.
Session-bound strong-auth sequence
The QA Finance Admin receives only admin_console, finance_read, and payout_risk_review. It does not receive moderation/support powers.
READYStart with a QA Finance Admin session.
Staff privileged-access production evidence
These remain open until they are truly implemented in production. The staging QA simulator does not satisfy them.
Recent staff QA runs
No QA runs recorded yet.
Evidence tools
Database security events remain protected separately; clearing browser evidence does not rewrite the server audit trail.
