▣ wi

New work item

Sub-item of #879 Pluto P1: IDOR on /api/image/[id] — add access-scope check (patient photos fetchable by any authed user) · pluto