Closed
Description
Right now if someone knows the v5 Project ID of an active project, and that project has a billing account, they can launch a challenge. We need to:
- Check to see if the jwt user has an active v5 Project ID
- That user has a role on that project (v5 Project.members)
- If the user has no role on the project, throw a 403