-
- Downloads
There was an error fetching the commit references. Please try again later.
Fix failing auhtorizations in GraphQL
0. Add authorize to LabelType and NamespaceType. 1. Make sure that authorizations on non-nullable fields are also executed.
Showing
- app/graphql/types/label_type.rb 2 additions, 0 deletionsapp/graphql/types/label_type.rb
- app/graphql/types/metadata_type.rb 2 additions, 0 deletionsapp/graphql/types/metadata_type.rb
- app/graphql/types/query_type.rb 1 addition, 4 deletionsapp/graphql/types/query_type.rb
- app/policies/repository_policy.rb 5 additions, 0 deletionsapp/policies/repository_policy.rb
- changelogs/unreleased/security-bvl-enforce-graphql-type-authorization.yml 5 additions, 0 deletions...eased/security-bvl-enforce-graphql-type-authorization.yml
- lib/gitlab/graphql/authorize/authorize_field_service.rb 2 additions, 0 deletionslib/gitlab/graphql/authorize/authorize_field_service.rb
- spec/graphql/types/label_type_spec.rb 6 additions, 0 deletionsspec/graphql/types/label_type_spec.rb
- spec/graphql/types/metadata_type_spec.rb 1 addition, 0 deletionsspec/graphql/types/metadata_type_spec.rb
- spec/graphql/types/query_type_spec.rb 0 additions, 4 deletionsspec/graphql/types/query_type_spec.rb
- spec/lib/gitlab/graphql/authorize/authorize_field_service_spec.rb 42 additions, 28 deletions.../gitlab/graphql/authorize/authorize_field_service_spec.rb
app/policies/repository_policy.rb
0 → 100644
spec/graphql/types/label_type_spec.rb
0 → 100644
Please register or sign in to comment