createMember is insecure
In createMember,pending
should be hard coded to "none" (pending member) when the user is not db owner.
Edited by mma227
In createMember,pending
should be hard coded to "none" (pending member) when the user is not db owner.