diff --git a/.changeset/fresh-rockets-spend.md b/.changeset/fresh-rockets-spend.md new file mode 100644 index 000000000..df7524a57 --- /dev/null +++ b/.changeset/fresh-rockets-spend.md @@ -0,0 +1,5 @@ +--- +'hive': patch +--- + +Fix legacy member scope mappings granting access to deleting projects. diff --git a/packages/services/api/src/modules/organization/providers/organization-member-roles.ts b/packages/services/api/src/modules/organization/providers/organization-member-roles.ts index 5fc0eec2d..c2665a71e 100644 --- a/packages/services/api/src/modules/organization/providers/organization-member-roles.ts +++ b/packages/services/api/src/modules/organization/providers/organization-member-roles.ts @@ -368,7 +368,6 @@ function transformOrganizationMemberLegacyScopesIntoPermissionGroup( break; } case ProjectAccessScope.SETTINGS: { - permissions.add('project:delete'); permissions.add('project:modifySettings'); permissions.add('schemaLinting:modifyProjectRules'); break;