-
- Downloads
There was an error fetching the commit references. Please try again later.
Don't display badges when builds are restricted
Badges were leaked to unauthorized users even when Public Builds project setting is disabled. Added guard clause to the controller to check if user can read build.
Showing
- app/controllers/projects/badges_controller.rb 2 additions, 1 deletionapp/controllers/projects/badges_controller.rb
- changelogs/unreleased/security-fix-badges-leaked-to-unauthorized-users.yml 5 additions, 0 deletions...ased/security-fix-badges-leaked-to-unauthorized-users.yml
- spec/controllers/projects/badges_controller_spec.rb 94 additions, 30 deletionsspec/controllers/projects/badges_controller_spec.rb
Please register or sign in to comment