Skip to content

Conversation

@Mohamad-Mortada
Copy link
Member

This is safe as last4 and expiration is already shown in the web and the only people who can access this are people in this policy which is same as in frontend.

def show?
user&.auditor? || OrganizerPosition.role_at_least?(user, record.event, :reader) || grantee?
end

@Mohamad-Mortada Mohamad-Mortada requested a review from a team December 29, 2025 00:09
@Mohamad-Mortada Mohamad-Mortada changed the title [v4] Allow other users to see stripe card last 4 [v4] Allow other org members to see stripe card last 4 Dec 29, 2025
@Mohamad-Mortada Mohamad-Mortada added this pull request to the merge queue Dec 29, 2025
Merged via the queue into main with commit 9e20d9a Dec 29, 2025
16 checks passed
@Mohamad-Mortada Mohamad-Mortada deleted the v4-stripe-card-last4-visibility branch December 29, 2025 20:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants