This story is for the security patch that was the most critical part of a larger body of work represented in #232. That story will be revised, re-estimated, and prioritized as a remaining piece of work. This story is just to encapsulate the work that has been done and merged.
Acceptance Criteria
[x] Change the API so that records cannot be deleted by any user.
[x] Change the API so that records cannot be altered by any user (except perhaps the necessary alterations of the "meeting" record's participants).
Notes for @mlippert :
Please attach Riff Server PR #21 to this card.
Deploy to Demo to patch our most public facing site.
Include this patch in all future deployments of platform and EDU.
This story is for the security patch that was the most critical part of a larger body of work represented in #232. That story will be revised, re-estimated, and prioritized as a remaining piece of work. This story is just to encapsulate the work that has been done and merged.
Acceptance Criteria
Notes for @mlippert :