-
- Downloads
Prevent award_emoji to notes not visible to user
When the parent noteable is not visible to the user (e.g. confidential) we prevent the user from adding emoji reactions to notes
Showing
- app/policies/note_policy.rb 1 addition, 0 deletionsapp/policies/note_policy.rb
- changelogs/unreleased/security-2776-fix-add-reaction-permissions.yml 5 additions, 0 deletions...unreleased/security-2776-fix-add-reaction-permissions.yml
- spec/policies/note_policy_spec.rb 2 additions, 0 deletionsspec/policies/note_policy_spec.rb
Please register or sign in to comment