SpiceDB checks involving relations with caveats can result in no permission when permission is expected in github.com/authzed/spicedb
{ "url": "https://pkg.go.dev/vuln/GO-2025-3744", "review_status": "UNREVIEWED" }