- Same-secret backend token is still accepted by the frontend guard - Permission denial must not invoke the schema or database callback - Admin error bodies must not echo secrets or raw tokens
- Same-secret backend token is still accepted by the frontend guard - Permission denial must not invoke the schema or database callback - Admin error bodies must not echo secrets or raw tokens