Vladimir Bugorskiy

SYSTEM LOG /

Multimodal Input Pipeline Adds Safeguards for Platform Administrators

Multimodal Input Pipeline now uses a separate persisted USER/ADMIN platform role. Active platform administrators can access administrative areas, while disabling a user immediately ends their browser session.

This update strengthens the access-control model in Multimodal Input Pipeline. - A separate platform role is introduced: USER or ADMIN, persisted in the database. - Access to administrative routes under /admin/** is available only to active platform administrators; ordinary users do not receive elevated rights automatically. - Browser sessions are rechecked against persisted state. If an account is disabled or its role changes, the stale session is ended immediately. - The last remaining enabled administrator is protected at both the application and database level: it cannot be accidentally disabled, deleted, or demoted, even during concurrent changes. - Platform roles do not automatically grant access to projects, packages, or sources; normal project permissions still apply. - The configured startup identity is idempotently enabled and assigned the ADMIN role at startup; an existing account's stored password value is not recalculated. - Migration V34 extends the users table without removing existing data: current users are safely backfilled with the USER role. For end users, this means more predictable and safer administration of the platform: the system clearly distinguishes regular users from administrators, and critical actions are protected against accidental loss of access.
← All system notes