-
- Downloads
Merge branch 'security-fix-lfs-import-project-ssrf-forgery-11-5' into 'security-11-5'
[11.5] LFS object forgery in project import See merge request gitlab/gitlabhq!2819 (cherry picked from commit 2bb4e59e6e24aaf25afa3325d9f043709d564129) ec8e01ab Added validations to prevent LFS object forgery
Showing
- app/models/lfs_download_object.rb 22 additions, 0 deletionsapp/models/lfs_download_object.rb
- app/services/projects/import_service.rb 4 additions, 4 deletionsapp/services/projects/import_service.rb
- app/services/projects/lfs_pointers/lfs_download_link_list_service.rb 7 additions, 6 deletions...s/projects/lfs_pointers/lfs_download_link_list_service.rb
- app/services/projects/lfs_pointers/lfs_download_service.rb 74 additions, 35 deletionsapp/services/projects/lfs_pointers/lfs_download_service.rb
- changelogs/unreleased/security-fix-lfs-import-project-ssrf-forgery.yml 5 additions, 0 deletions...released/security-fix-lfs-import-project-ssrf-forgery.yml
- lib/gitlab/github_import/importer/lfs_object_importer.rb 5 additions, 3 deletionslib/gitlab/github_import/importer/lfs_object_importer.rb
- lib/gitlab/github_import/representation/lfs_object.rb 2 additions, 2 deletionslib/gitlab/github_import/representation/lfs_object.rb
- spec/lib/gitlab/github_import/importer/lfs_object_importer_spec.rb 14 additions, 8 deletions...gitlab/github_import/importer/lfs_object_importer_spec.rb
- spec/lib/gitlab/github_import/importer/lfs_objects_importer_spec.rb 11 additions, 3 deletions...itlab/github_import/importer/lfs_objects_importer_spec.rb
- spec/models/lfs_download_object_spec.rb 68 additions, 0 deletionsspec/models/lfs_download_object_spec.rb
- spec/services/projects/import_service_spec.rb 7 additions, 2 deletionsspec/services/projects/import_service_spec.rb
- spec/services/projects/lfs_pointers/lfs_download_link_list_service_spec.rb 9 additions, 9 deletions...jects/lfs_pointers/lfs_download_link_list_service_spec.rb
- spec/services/projects/lfs_pointers/lfs_download_service_spec.rb 131 additions, 31 deletions...rvices/projects/lfs_pointers/lfs_download_service_spec.rb
app/models/lfs_download_object.rb
0 → 100644
spec/models/lfs_download_object_spec.rb
0 → 100644
Please register or sign in to comment