chore: promote dev → uat (GRO-1036 security fixes) #386
Reference in New Issue
Block a user
Delete Branch "dev"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
Promotes dev to uat with the security fixes from GRO-1036:
/api/invoices/stats/summarynow requiresrequireRole("manager")— previously unauthenticatedstripePaymentIntentIdguard restored (422 if missing); manual refund fallback removedSource PR
Review
CI is green (Lint & Typecheck, Test, E2E, Build all pass). Code was reviewed and CTO-approved in PR #385 — approving this promotion gate as required for the dev→uat merge.