-
- Downloads
Don't use fragment cache on commit page
This makes sure the user viewing the commit does not get to see anything they're not allowed to see
Showing
- app/views/projects/commits/_commit.html.haml 41 additions, 53 deletionsapp/views/projects/commits/_commit.html.haml
- changelogs/unreleased/security-bvl-exposure-in-commits-list.yml 5 additions, 0 deletions...logs/unreleased/security-bvl-exposure-in-commits-list.yml
- spec/features/projects/commits/user_browses_commits_spec.rb 21 additions, 2 deletionsspec/features/projects/commits/user_browses_commits_spec.rb
Please register or sign in to comment