Security role save for locked roles and clearer API errors

Fixkamo-internal
Shipped
April 20, 2026 at 9:51 PM UTC
Author
kamo
Commit
a48495b

- When isAllowEditSecurity is false, omit rights and securityModelIds from the PUT body so SecurityService accepts metadata-only updates (session timeout, description) instead of rejecting permission payloads. - Treat fully locked roles only when isAllowEditSecurity === false, not when the field is undefined, so legacy rows without the flag can still be edited. - Parse JSON error bodies from failed role updates instead of relying on an often-empty statusText.

All changes

Like what you see shipping?

Every one of these updates lands in your workspace automatically. Start free and watch it grow week after week.

Start Free ForeverView Pricing