Skip to content
Snippets Groups Projects
Select Git revision
  • master default protected
  • 12-9-stable
  • 12-7-stable
  • 12-6-stable
  • 12-8-stable
  • github/fork/Kloppi313/patch-1
  • 12-5-stable
  • 12-4-stable
  • github/fork/ramalokesh8477/master
  • 12-1-stable
  • 12-2-stable
  • 12-0-stable
  • 12-3-stable
  • 42-42-stable
  • github/fork/hussamgit398/patch-2
  • 12-3-auto-deploy-20190911
  • 12-3-auto-deploy-20190916
  • 12-3-auto-deploy-20190908
  • 12-3-auto-deploy-20190901
  • 12-3-auto-deploy-20190901-32664
  • v12.10.0.pre
  • v12.9.0
  • v12.9.0-rc42
  • v12.8.7
  • v12.8.6
  • v12.8.5
  • v12.8.4
  • v12.8.3
  • v12.6.8
  • v12.7.7
  • v12.8.2
  • v12.8.1
  • v12.9.0.pre
  • v12.8.0
  • v12.8.0-rc42
  • v12.5.10
  • v12.7.6
  • v12.6.7
  • v12.7.5
  • v12.5.9
40 results

ce-60465-prevent-comments-on-private-mrs.yml

  • Alex Kalderimis's avatar
    e640de75
    Prevent unauthorised comments on merge requests · e640de75
    Alex Kalderimis authored
    * Prevent creating notes on inaccessible MRs
    
    This applies the notes rules at the MR scope. Rather than adding extra
    rules to the Project level policy, preventing :create_note here is
    better since it only prevents creating notes on MRs.
    
    * Prevent creating notes in inaccessible Issues
    
    without this policy, non-team-members are allowed to comment on issues
    even when the project has the private-issues policy set. This means that
    without this change, users are allowed to comment on issues that they
    cannot read.
    
    * Add CHANGELOG entry
    e640de75
    History
    Prevent unauthorised comments on merge requests
    Alex Kalderimis authored
    * Prevent creating notes on inaccessible MRs
    
    This applies the notes rules at the MR scope. Rather than adding extra
    rules to the Project level policy, preventing :create_note here is
    better since it only prevents creating notes on MRs.
    
    * Prevent creating notes in inaccessible Issues
    
    without this policy, non-team-members are allowed to comment on issues
    even when the project has the private-issues policy set. This means that
    without this change, users are allowed to comment on issues that they
    cannot read.
    
    * Add CHANGELOG entry