-
- Downloads
Merge branch 'security-1072-graphql-subscription-scope-validation-16-9' into '16-9-stable-ee'
Ensure PAT scope is validated everywhere for GraphQL/ActionCable See merge request https://gitlab.com/gitlab-org/security/gitlab/-/merge_requests/3977 Merged-by:GitLab Release Tools Bot <delivery-team+release-tools@gitlab.com> Approved-by:
Luke Duncalfe <lduncalfe@gitlab.com> Co-authored-by:
Dylan Griffith <dyl.griffith@gmail.com>
Showing
- app/channels/application_cable/channel.rb 9 additions, 0 deletionsapp/channels/application_cable/channel.rb
- app/channels/graphql_channel.rb 3 additions, 2 deletionsapp/channels/graphql_channel.rb
- app/graphql/resolvers/base_resolver.rb 1 addition, 1 deletionapp/graphql/resolvers/base_resolver.rb
- app/graphql/types/base_enum.rb 1 addition, 1 deletionapp/graphql/types/base_enum.rb
- app/graphql/types/base_field.rb 1 addition, 1 deletionapp/graphql/types/base_field.rb
- app/graphql/types/base_object.rb 1 addition, 1 deletionapp/graphql/types/base_object.rb
- lib/gitlab/graphql/authorize/authorize_resource.rb 1 addition, 1 deletionlib/gitlab/graphql/authorize/authorize_resource.rb
- lib/gitlab/graphql/authorize/object_authorization.rb 1 addition, 1 deletionlib/gitlab/graphql/authorize/object_authorization.rb
- spec/channels/graphql_channel_spec.rb 81 additions, 0 deletionsspec/channels/graphql_channel_spec.rb
- spec/channels/noteable/notes_channel_spec.rb 56 additions, 4 deletionsspec/channels/noteable/notes_channel_spec.rb
- spec/graphql/resolvers/base_resolver_spec.rb 15 additions, 2 deletionsspec/graphql/resolvers/base_resolver_spec.rb
- spec/graphql/types/base_enum_spec.rb 15 additions, 0 deletionsspec/graphql/types/base_enum_spec.rb
- spec/graphql/types/base_field_spec.rb 17 additions, 0 deletionsspec/graphql/types/base_field_spec.rb
- spec/graphql/types/base_object_spec.rb 17 additions, 3 deletionsspec/graphql/types/base_object_spec.rb
- spec/lib/gitlab/graphql/authorize/authorize_resource_spec.rb 18 additions, 4 deletionsspec/lib/gitlab/graphql/authorize/authorize_resource_spec.rb
- spec/lib/gitlab/graphql/authorize/object_authorization_spec.rb 19 additions, 7 deletions...lib/gitlab/graphql/authorize/object_authorization_spec.rb
- spec/support/helpers/stub_action_cable_connection.rb 2 additions, 1 deletionspec/support/helpers/stub_action_cable_connection.rb
spec/channels/graphql_channel_spec.rb
0 → 100644
Please register or sign in to comment