Skip to content
Security

Auth verification helper restricted to authorized callers

Direct execution of the internal authentication verification helper is now restricted to authorized callers only, reducing the surface area for privilege misuse.

The authentication verification trigger helper can no longer be invoked directly by unprivileged callers. Only the specific authorized roles that require it retain execute permission.

  • Unauthorized direct calls to the verification helper are now rejected at the database level.
  • No change to the sign-up or email verification flow that users experience.