<?xml version="1.0" encoding="UTF-8"?><oembed><type>video</type><version>1.0</version><html>&lt;iframe src=&quot;https://www.loom.com/embed/d1755b3bbc8a4197a293f431db373a84&quot; frameborder=&quot;0&quot; width=&quot;1662&quot; height=&quot;1246&quot; webkitallowfullscreen mozallowfullscreen allowfullscreen&gt;&lt;/iframe&gt;</html><height>1246</height><width>1662</width><provider_name>Loom</provider_name><provider_url>https://www.loom.com</provider_url><thumbnail_height>1246</thumbnail_height><thumbnail_width>1662</thumbnail_width><thumbnail_url>https://cdn.loom.com/sessions/thumbnails/d1755b3bbc8a4197a293f431db373a84-d836ef8ff310fbd7.gif</thumbnail_url><duration>334.374</duration><title>Fixing Cross-Space Edit Permissions</title><description>This Loom explains a permissions fix to prevent cross-space edits and the tests and migrations added to enforce it. The author traced unexpected cross-space editing to reader access being too permissive and tightened group access so reader permissions do not allow cross-space edits. They added scenarios in group access tests and ran migrations that introduce access-level functions such as editor requirements for sync and added capabilities like CanViewConcept alongside CanViewContent. Finally, they adjusted step definitions to stop ignoring the username and to use the space icon.</description></oembed>