-
- Downloads
Redact unsubscribe links in issuable texts
It's possible that user pastes accidentally also unsubscribe link which is included in footer of notification emails. This unsubscribe link contains personal token which attacker then use to act as the original user (e.g. for sending comments under his/her identity).
Showing
- app/models/concerns/issuable.rb 3 additions, 0 deletionsapp/models/concerns/issuable.rb
- app/models/concerns/redactable.rb 33 additions, 0 deletionsapp/models/concerns/redactable.rb
- app/models/note.rb 3 additions, 0 deletionsapp/models/note.rb
- app/models/snippet.rb 3 additions, 0 deletionsapp/models/snippet.rb
- changelogs/unreleased/redact-links-dev.yml 5 additions, 0 deletionschangelogs/unreleased/redact-links-dev.yml
- db/post_migrate/20181014121030_enqueue_redact_links.rb 65 additions, 0 deletionsdb/post_migrate/20181014121030_enqueue_redact_links.rb
- db/schema.rb 1 addition, 1 deletiondb/schema.rb
- lib/gitlab/background_migration/redact_links.rb 62 additions, 0 deletionslib/gitlab/background_migration/redact_links.rb
- spec/lib/gitlab/background_migration/redact_links_spec.rb 96 additions, 0 deletionsspec/lib/gitlab/background_migration/redact_links_spec.rb
- spec/migrations/enqueue_redact_links_spec.rb 42 additions, 0 deletionsspec/migrations/enqueue_redact_links_spec.rb
- spec/models/concerns/redactable_spec.rb 69 additions, 0 deletionsspec/models/concerns/redactable_spec.rb
app/models/concerns/redactable.rb
0 → 100644
changelogs/unreleased/redact-links-dev.yml
0 → 100644
spec/migrations/enqueue_redact_links_spec.rb
0 → 100644
spec/models/concerns/redactable_spec.rb
0 → 100644
Please register or sign in to comment