-
- Downloads
Merge branch 'security-fix-pat-web-access-11-3' into 'security-11-3'
[11.3] Resolve "Personal access token with only `read_user` scope can be used to authenticate any web request" See merge request gitlab/gitlabhq!2657
No related branches found
No related tags found
Showing
- app/controllers/application_controller.rb 1 addition, 22 deletionsapp/controllers/application_controller.rb
- app/controllers/concerns/sessionless_authentication.rb 28 additions, 0 deletionsapp/controllers/concerns/sessionless_authentication.rb
- app/controllers/dashboard/projects_controller.rb 1 addition, 0 deletionsapp/controllers/dashboard/projects_controller.rb
- app/controllers/dashboard_controller.rb 3 additions, 0 deletionsapp/controllers/dashboard_controller.rb
- app/controllers/graphql_controller.rb 1 addition, 0 deletionsapp/controllers/graphql_controller.rb
- app/controllers/groups_controller.rb 3 additions, 0 deletionsapp/controllers/groups_controller.rb
- app/controllers/projects/commits_controller.rb 1 addition, 0 deletionsapp/controllers/projects/commits_controller.rb
- app/controllers/projects/issues_controller.rb 9 additions, 4 deletionsapp/controllers/projects/issues_controller.rb
- app/controllers/projects/tags_controller.rb 2 additions, 0 deletionsapp/controllers/projects/tags_controller.rb
- app/controllers/projects_controller.rb 2 additions, 0 deletionsapp/controllers/projects_controller.rb
- app/controllers/users_controller.rb 1 addition, 0 deletionsapp/controllers/users_controller.rb
- changelogs/unreleased/security-fix-pat-web-access.yml 5 additions, 0 deletionschangelogs/unreleased/security-fix-pat-web-access.yml
- config/initializers/rack_attack_global.rb 5 additions, 5 deletionsconfig/initializers/rack_attack_global.rb
- lib/gitlab/auth/request_authenticator.rb 10 additions, 4 deletionslib/gitlab/auth/request_authenticator.rb
- lib/gitlab/auth/user_auth_finders.rb 37 additions, 2 deletionslib/gitlab/auth/user_auth_finders.rb
- spec/controllers/application_controller_spec.rb 0 additions, 151 deletionsspec/controllers/application_controller_spec.rb
- spec/controllers/dashboard/projects_controller_spec.rb 5 additions, 0 deletionsspec/controllers/dashboard/projects_controller_spec.rb
- spec/controllers/dashboard_controller_spec.rb 18 additions, 13 deletionsspec/controllers/dashboard_controller_spec.rb
- spec/controllers/graphql_controller_spec.rb 45 additions, 2 deletionsspec/controllers/graphql_controller_spec.rb
- spec/controllers/groups_controller_spec.rb 20 additions, 0 deletionsspec/controllers/groups_controller_spec.rb
Please register or sign in to comment