1c82a75a88
- Added requireSuperUser() middleware in apps/api/src/middleware/rbac.ts
that checks staff.isSuperUser, returns 403 if false
- Wired into index.ts:
- POST/PATCH/DELETE /api/staff/* → requireSuperUser() after requireRole("manager")
- /api/admin/settings/* → requireSuperUser() after requireRole("manager")
- resolveStaffMiddleware: inject isSuperUser: true for AUTH_DISABLED dev mode
Co-Authored-By: Paperclip <noreply@paperclip.ing>