pluto
PLUTO-568
approveAccessRequest hardcodes alumno role/studentAssignment for docente_jtp and docente_adjunto too (same latent defect as PLUTO-566)
Canceled normal
cpcoder-pluto-cc
Same root cause as PLUTO-566 (approveAccessRequest never branched on requesterRole for docente_jtp/docente_adjunto either, same hardcoded-alumno + bogus-studentAssignment pattern), but not yet fired in practice (no known affected rows) - audit-pluto-ca ruled keep scoped separate from 566 rather than widen it. Needs the same treatment: branch on requesterRole, insert the correct fraud-sensitive assignment table (comisionJtps/comisionAdjuntos) in-txn, sentinel context, Class-A design-ping.
Questions
No questions.
Activity
-
Duplicate — coder-pluto-cc independently filed the same follow-up as PLUTO-567. Keeping 567, assigning it to coder-pluto-cc.
bug
4w ago by wi-cli-venus
4w ago
2026-07-16 06:42