1. 28 10月, 2019 2 次提交
  2. 25 10月, 2019 18 次提交
  3. 24 10月, 2019 1 次提交
    • B
      Only assign merge params when allowed · 61d16cb0
      Bob Van Landuyt 提交于
      When a user updates a merge request coming from a fork, they should
      not be able to set `force_remove_source_branch` if they cannot push
      code to the source project.
      
      Otherwise developers of the target project could remove the source
      branch of the source project by setting this flag through the API.
      61d16cb0
  4. 23 10月, 2019 4 次提交
  5. 17 10月, 2019 2 次提交
    • L
      Pass all wiki markup formats through pipelines · 6cbdc90c
      Luke Duncalfe 提交于
      Previously, when the wiki page format was anything other than `markdown`
      or `asciidoc` the formatted content would be returned though a Gitaly
      call. Gitaly in turn would delegate formatting to the gitlab-gollum-lib
      gem, which in turn would delegate that to various gems (like RDoc for
      `rdoc`) and then apply some very liberal sanitization.
      
      It was too liberal!
      
      This change brings our wiki content formatting in line with how we
      format other markdown at GitLab, so we have a SSOT for sanitization.
      
      https://gitlab.com/gitlab-org/gitlab/issues/30540
      6cbdc90c
    • R
      Mask Sentry auth token · 97711758
      Ryan Cobb 提交于
      This makes it so we mask Sentry's auth token. This mask only occurs in
      the UI.
      97711758
  6. 14 10月, 2019 2 次提交
  7. 11 10月, 2019 2 次提交
  8. 10 10月, 2019 1 次提交
    • K
      Avoid #authenticate_user! in #route_not_found · 81eba220
      Kerri Miller 提交于
      This method, #route_not_found, is executed as the final fallback for
      unrecognized routes (as the name might imply.) We want to avoid
      `#authenticate_user!` when calling `#route_not_found`;
      `#authenticate_user!` can, depending on the request format, return a 401
      instead of redirecting to a login page. This opens a subtle security
      exploit where anonymous users will receive a 401 response when
      attempting to access a private repo, while a recognized user will
      receive a 404, exposing the existence of the private, hidden repo.
      81eba220
  9. 09 10月, 2019 2 次提交
  10. 07 10月, 2019 3 次提交
  11. 02 10月, 2019 3 次提交
    • A
      Pick only those groups that the viewing user has access to, · b554257b
      Aakriti Gupta 提交于
      in a project members' list. Add tests for possible scenarios
      
      Re-factor and remove N + 1 queries
      
      Remove author from changelog
      
      Don't use memoisation when not needed
      
      Include users part of parents of project's group
      
      Re-factor tests
      
      Create and add users according to roles
      
      Re-use group created earlier
      
      Add incomplete test for ancestoral groups
      
      Rename method to clarify category of groups
      
      Skip pending test, remove comments not needed
      
      Remove extra line
      
      Include ancestors from invited groups as well
      
      Add specs for participants service
      
      Add more specs
      
      Add more specs
      
      use  instead of
      
      Use public group owner instead of project maintainer to test owner acess
      
      Remove tests that have now been moved into participants_service_spec
      
      Use :context instead of :all
      
      Create nested group instead of creating an ancestor separately
      
      Add comment explaining doubt on the failing spec
      
      Imrpove test setup
      
      Optimize sql queries
      
      Refactor specs file
      
      Add rubocop disablement
      
      Add special case for project owners
      
      Add small refactor
      
      Add explanation to the docs
      
      Fix wording
      
      Refactor group check
      
      Add small changes in specs
      
      Add cr remarks
      
      Add cr remarks
      
      Add specs
      
      Add small refactor
      
      Add code review remarks
      
      Refactor for better database usage
      
      Fix failing spec
      
      Remove rubocop offences
      
      Add cr remarks
      b554257b
    • G
    • G
      Update VERSION to 12.2.7 · 8a527e4b
      GitLab Release Tools Bot 提交于
      8a527e4b