No description
Advocates could not filter their own task list by client because the /api/tasks endpoint treated any userId query param as a request to view another user's tasks, rejecting non-Admin/Manager callers with 403 even when userId matched their own session id. |
||
|---|---|---|
| .claude | ||
| dev | ||
| ondeck | ||
| tasks | ||
| .gitignore | ||