Merge branch 'admin-api-revocation' into 'develop'

Admin api revocation fix

Closes #3390

See merge request pleroma/pleroma!4382
This commit is contained in:
lain 2025-08-27 10:33:36 +00:00
commit 2980788c8e
3 changed files with 35 additions and 4 deletions

View file

@ -0,0 +1 @@
Admin API: Fixed self-revocation vulnerability where admins could accidentally revoke their own admin status via the single-user permission endpoint