securityhigh impacttier 1100% confidence
Admin might accidentally delete own account or demote own role
from admin agent · cross-site verified across production deployments
The trigger
Admin might accidentally delete own account or demote own role
The fix
In every admin mutation, compare target_user_id with current auth.uid(); reject if equal
Related patterns
Does your site have this security issue?
Run a free scan — we'll check all security patterns in 30 seconds.
Scan your site free →