mirror of
https://github.com/projectsend/projectsend.git
synced 2026-10-04 21:43:57 +00:00
d3230a4b64
Setting a password and removing a second factor are how an administrator lets a locked-out person back in, so a token holding edit_clients or edit_users can sign in as the accounts it may edit. That stays what those abilities mean; it is now said where it is chosen. The token form warns when either is ticked, and the API guide says it beside the abilities, with the three refusals on your own account under "Staff accounts". The OpenAPI document carries the new 403s, and CHANGELOG.md an Unreleased entry. GHSA-j5cp-r8pr-m5cr