From 8d3f9339ee1daf9da3bae1268815bb578fb49c70 Mon Sep 17 00:00:00 2001 From: "Rodrigo Rodriguez (Pragmatismo)" Date: Wed, 4 Feb 2026 14:25:14 -0300 Subject: [PATCH] Fix: add /api/auth/me to public routes in RBAC --- src/security/rbac_middleware.rs | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/security/rbac_middleware.rs b/src/security/rbac_middleware.rs index 56e762961..a9cfa855e 100644 --- a/src/security/rbac_middleware.rs +++ b/src/security/rbac_middleware.rs @@ -959,7 +959,7 @@ pub fn build_default_route_permissions() -> Vec { RoutePermission::new("/api/auth/bootstrap", "POST", "").with_anonymous(true), RoutePermission::new("/api/auth/refresh", "POST", "").with_anonymous(true), RoutePermission::new("/api/auth/logout", "POST", ""), - RoutePermission::new("/api/auth/me", "GET", ""), + RoutePermission::new("/api/auth/me", "GET", "").with_anonymous(true), RoutePermission::new("/api/auth/**", "GET", ""), RoutePermission::new("/api/auth/**", "POST", ""),