Hardened auth, closing a critical IDOR class
A dependency deep in the stack carried a known vulnerability and we had no fast way to even tell where it was used. I built the inventory and the update path, then closed the loop, so the next disclosure was a patch rather than a fire drill.
Closed an object-reference flaw and added authz tests; the pen-test re-run came back clean.