Skip to content
Snippets Groups Projects
Select Git revision
  • master default protected
  • 12-9-stable
  • 12-7-stable
  • 12-6-stable
  • 12-8-stable
  • github/fork/Kloppi313/patch-1
  • 12-5-stable
  • 12-4-stable
  • github/fork/ramalokesh8477/master
  • 12-1-stable
  • 12-2-stable
  • 12-0-stable
  • 12-3-stable
  • 42-42-stable
  • github/fork/hussamgit398/patch-2
  • 12-3-auto-deploy-20190911
  • 12-3-auto-deploy-20190916
  • 12-3-auto-deploy-20190908
  • 12-3-auto-deploy-20190901
  • 12-3-auto-deploy-20190901-32664
  • v12.10.0.pre
  • v12.9.0
  • v12.9.0-rc42
  • v12.8.7
  • v12.8.6
  • v12.8.5
  • v12.8.4
  • v12.8.3
  • v12.6.8
  • v12.7.7
  • v12.8.2
  • v12.8.1
  • v12.9.0.pre
  • v12.8.0
  • v12.8.0-rc42
  • v12.5.10
  • v12.7.6
  • v12.6.7
  • v12.7.5
  • v12.5.9
40 results

users.rb

  • Timothy Andrew's avatar
    3c88a786
    Implement review comments for !12445 from @godfat and @rymai. · 3c88a786
    Timothy Andrew authored
    - Use `GlobalPolicy` to authorize the users that a non-authenticated user can
      fetch from `/api/v4/users`. We allow access if the `Gitlab::VisibilityLevel::PUBLIC`
      visibility level is not restricted.
    
    - Further, as before, `/api/v4/users` is only accessible to unauthenticated users if
      the `username` parameter is passed.
    
    - Turn off `authenticate!` for the `/api/v4/users` endpoint by matching on the actual
      route + method, rather than the description.
    
    - Change the type of `current_user` check in `UsersFinder` to be more
      compatible with EE.
    3c88a786
    History
    Implement review comments for !12445 from @godfat and @rymai.
    Timothy Andrew authored
    - Use `GlobalPolicy` to authorize the users that a non-authenticated user can
      fetch from `/api/v4/users`. We allow access if the `Gitlab::VisibilityLevel::PUBLIC`
      visibility level is not restricted.
    
    - Further, as before, `/api/v4/users` is only accessible to unauthenticated users if
      the `username` parameter is passed.
    
    - Turn off `authenticate!` for the `/api/v4/users` endpoint by matching on the actual
      route + method, rather than the description.
    
    - Change the type of `current_user` check in `UsersFinder` to be more
      compatible with EE.