67015ef82b
- Add tests/test_permission_system_live.py: 33 live tests against real PostgreSQL testing RBAC, ABAC, RLS, cross-tenant isolation, guest access, entity sharing, field-level permissions, role invalidation, group permissions, membership suspension - fix(contacts): delete route uses contacts:delete instead of contacts:write The delete_contact and delete_contact_person routes were checking contacts:write permission instead of contacts:delete, allowing users without delete permission to delete contacts. - fix(contacts): DeleteContactCommand passes is_system_admin to service DeleteContactCommand.run() was not passing is_system_admin from the session to contact_service.delete_contact(), causing system admins to be blocked by the row-level admin access check. - fix(contacts): allow deletion of tenant-owned contacts contact_service.delete_contact() required admin-level entity access for ALL contacts, including tenant-owned ones (owner_id=None). Tenant-owned contacts can now be deleted by any user with contacts:delete permission (already verified by the route via require_permission).