4 Commits
Author SHA1 Message Date
Matthew Meszaros cbf0667d8f feat: hold every API key to its creator's current workspace role on each gated route and AI tool, and stop a key, including on the realtime socket, once its creator leaves the workspace (api_key_holder_left) 2026-10-04 05:15:30 -07:00
Matthew Meszaros 886756ae0f feat: share one api_key_mailbox_limited code and keyMailboxLimited check across the campaign, AI tool and MCP handlers 2026-10-04 03:43:26 -07:00
Matthew Meszaros bf47984cd5 feat: cap every OAuth grant and API key at the delegating member's role (consent narrows scopes and reports the withheld ones, tokens re-check the member's current role at every gate and MCP tool, keys stay within their creator's permissions, mailboxes and IP allowlist), keep OAuth tokens off API key and OAuth app management, require a fresh sign-in to approve an app, revoke a grant whose refresh token is presented twice, count only unexpired grants as installs, seal app webhook secrets under the instance key, name the workspace and flag unverified apps on the consent screen, and let credential managers list and revoke every member's app authorizations 2026-10-04 02:59:10 -07:00
Matthew Meszaros 8ce331a7ac feat: fix the campaign test-email endpoint answering 404 for every caller by scoping its campaign lookup to the organization instead of the user, let it send from any mailbox of the organization and render a real contact through a new contact_id, attach the campaign's files, and extend the template preview with contact_id, campaign_id and account_id so it applies the signature, opt-out footer and plain-text rule the send path does 2026-09-04 02:58:36 -07:00