# FAVO RBAC PATCH V2

Root: /var/www/html/favo

Fix:
- SessionService now returns `s.account_id AS id`.
- Auth::can() can therefore resolve the logged-in account correctly.
- PermissionService validates account ID before permission lookup.
- Superadmin role now correctly triggers its platform/system permissions and Superadmin override.

No database migration required.

IMPORTANT: after deployment, existing browser session may contain a token created before the patch, but the token remains valid. Logout/login once if desired to create a fresh session.
