The just-merged production-only commits were never run through QA
(they were pushed directly to the production branch), so several
version markers and hardcoded test strings had drifted out of sync
with each other:
- package.json was bumped to 17.8.0 but package-lock.json,
release-manifest.json and app-runtime.js's own VERSION constant were
never updated to match - reverted to 17.7.3 since no other release
artifact actually changed.
- service-worker.js's cache name legitimately moved to
v81-20260912-account-center-loader (real new modules need the cache
bust), but release-manifest.json's pwaCache field and two
release-check.mjs assertions still expected the old v78 name.
- edge-security-v1774.mjs and static-security.mjs asserted the old
employee role list (with "admin") and old PWA cache name that
production's own commits had already changed.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This Edge Function grants platform-admin power (list every user across
every workspace, ban/unban accounts, trigger password resets for any
user_id) but answered with Access-Control-Allow-Origin: '*', unlike the
sibling caterium-create-employee function which already uses an origin
allowlist. Authorization itself was never bypassable this way (the
function still requires the caller's own Bearer token and re-checks
sun_is_platform_admin() server-side), but a wildcard CORS response
removes a real layer of defense-in-depth if a platform-admin token were
ever exposed to another origin.
Applies the same allowedOrigin()/corsHeaders() pattern already proven in
caterium-create-employee, and extends edge-security-v1774.mjs (which
already asserted the wildcard was gone from create-employee, but never
checked this function) to cover both.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>