-
- Downloads
Resolve: Milestones leaked via search API
Fix milestone titles being leaked using search API when users cannot read milestones
Showing
- app/models/project.rb 12 additions, 0 deletionsapp/models/project.rb
- changelogs/unreleased/security-fix_milestones_search_api_leak.yml 5 additions, 0 deletions...gs/unreleased/security-fix_milestones_search_api_leak.yml
- lib/gitlab/project_search_results.rb 6 additions, 0 deletionslib/gitlab/project_search_results.rb
- lib/gitlab/search_results.rb 24 additions, 2 deletionslib/gitlab/search_results.rb
- spec/lib/gitlab/search_results_spec.rb 24 additions, 0 deletionsspec/lib/gitlab/search_results_spec.rb
- spec/models/project_spec.rb 17 additions, 0 deletionsspec/models/project_spec.rb
- spec/requests/api/search_spec.rb 42 additions, 4 deletionsspec/requests/api/search_spec.rb
Please register or sign in to comment