JSON mode should be disabled for Member users, or the ability to disable JSON mode on an action by action basis should be added.
This would address permission violations which are possible through using JSON mode (users can successfully execute an action on entities they don't have permissions for).
Created by Anna Persico
·