csrf and permissions hardening

Merge request reports

Loading