--- name: audit-rbac description: Audit & fix RBAC and audit log compliance in API endpoints and frontend components --- Audit the specified files or directories for RBAC and audit log compliance. **Fix every issue found immediately.** ## Rules ### API Endpoints (NestJS — `apps/api/src/`) 1. **Every mutation endpoint** (POST, PATCH, PUT, DELETE) MUST have `@RequirePermission('resource', 'action')`. If missing, **add it**. 2. **Read endpoints** (GET) should have `@RequirePermission('resource', 'read')`. If missing, **add it**. 3. **Self-endpoints** (e.g., `/me/preferences`) may skip `@RequirePermission` — authentication via `HybridAuthGuard` is sufficient. 4. **Controller format**: Must use `@Controller({ path: 'name', version: '1' })`, NOT `@Controller('v1/name')`. If wrong, **fix it**. 5. **Guards**: Use `@UseGuards(HybridAuthGuard, PermissionGuard)` at controller or endpoint level. Never skip PermissionGuard. 6. **Webhooks**: External webhook endpoints use `@Public()` — no auth required. ### Frontend Components (`apps/app/src/`) 1. **Every mutation element** (button, form submit, toggle, switch, file upload) MUST be gated with `usePermissions` from `@/hooks/use-permissions`. If not: - **Create/Add buttons**: Wrap with `{hasPermission('resource', 'create') &&