You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
fix: update aal requirements to update user (#1766)
## What kind of change does this PR introduce?
If a user has verified factors (mfa enabled) we should require an AAL2
session in order to proceed with any operation
We restrict phone, email, and password from updates as we consider those
as sensitive fields
Context:
https://supabase.slack.com/archives/C02AK9166FR/p1725466764804889
---------
Co-authored-by: Stojan Dimitrovski <[email protected]>
0 commit comments