Adversarial review of LeanerCloud/cloud-commitments-cli#1427 (frontend validateGroupCombination) noted the contradiction check (a view-only group must not combine with a write-capable group) is FRONTEND-ONLY. Backend guardGroupChange (internal/auth/service_user.go:~369) enforces >=1 group / last-admin / self-escalation (LeanerCloud/cloud-commitments-cli#907) but NOT the view-only+write contradiction, so the /api/users update endpoint accepts contradictory combos from a non-UI API consumer. Low security impact (additive permission model; a malicious update:users holder could assign the write group alone anyway - it's an accident guard, not a security boundary), but worth backend parity for defense-in-depth and non-UI consumers. Add the same view-only/write-capable classification to guardGroupChange and reject with a clear error. Effort ~S. Source: LeanerCloud/cloud-commitments-cli#1427 review.
Adversarial review of LeanerCloud/cloud-commitments-cli#1427 (frontend validateGroupCombination) noted the contradiction check (a view-only group must not combine with a write-capable group) is FRONTEND-ONLY. Backend guardGroupChange (internal/auth/service_user.go:~369) enforces >=1 group / last-admin / self-escalation (LeanerCloud/cloud-commitments-cli#907) but NOT the view-only+write contradiction, so the /api/users update endpoint accepts contradictory combos from a non-UI API consumer. Low security impact (additive permission model; a malicious update:users holder could assign the write group alone anyway - it's an accident guard, not a security boundary), but worth backend parity for defense-in-depth and non-UI consumers. Add the same view-only/write-capable classification to guardGroupChange and reject with a clear error. Effort ~S. Source: LeanerCloud/cloud-commitments-cli#1427 review.