securityhigh impacttier 1100% confidence

Admin might accidentally delete own account or demote own role

from admin agent · cross-site verified across production deployments

The trigger

Admin might accidentally delete own account or demote own role

The fix

In every admin mutation, compare target_user_id with current auth.uid(); reject if equal

Related patterns

Does your site have this security issue?

Run a free scan — we'll check all security patterns in 30 seconds.

Scan your site free →