This release includes breaking changes for platform teams planning a safe upgrade.
✓ No known CVEs patched in this version
Topics
+4 more
Affected surfaces
Summary
AI summaryFixed event assignment for non‑admin users by removing the admin‑only guard on GET /auth/users.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Bugfix | Medium |
GET /auth/users no longer requires admin privileges for non-admin users, allowing event assignment. GET /auth/users no longer requires admin privileges for non-admin users, allowing event assignment. Source: llm_adapter@2026-05-28 Confidence: low |
— |
| Bugfix | Medium |
Removed requireAdmin guard from GET /auth/users endpoint. Removed requireAdmin guard from GET /auth/users endpoint. Source: granite4.1:30b@2026-05-28-audit Confidence: low |
— |
Full changelog
Fixed
- Calendar – event assignment for non-admin users: The
GET /auth/usersendpoint previously required admin privileges, causing the assignee dropdown to silently render empty for child and other non-admin family profiles. Removed the unnecessaryrequireAdminguard so all authenticated family members can load the user list and assign calendar events.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]