Enforce the FN-7559 release-authorization hold in the approve-plan and reject-plan routes, since a direct API call previously bypassed the dashboard's UI-only protection.
- Add a guard in register-task-workflow-routes.ts: reject approve-plan and reject-plan requests with 400 when task.awaitingApprovalReason === "release-authorization", instructing the caller to add the **Release Authorized By User:** yes marker instead.
- Add regression tests in routes-github.test.ts covering both approve-plan and reject-plan against release-authorization-held tasks.
- Add changeset fn-7564-approve-plan-release-authorization-guard.md (patch, security) documenting the fix.
Files changed:
.changeset/fn-7564-approve-plan-release-authorization-guard.md | 7 ++
packages/dashboard/src/__tests__/routes-github.test.ts | 82 ++++++++++++++++++++++
packages/dashboard/src/routes/register-task-workflow-routes.ts | 23 ++++++
3 files changed, 112 insertions(+)
Fusion-Task-Id: FN-7564
Fusion-Task-Lineage: ccadd492-ee2b-4f0e-af2f-5f37c6351922
Co-authored-by: Fusion (runfusion.ai) <noreply@runfusion.ai>