-
- Downloads
Anonymous user can enumerate all users through GraphQL endpoint
Merge branch 'security-571-anonymous-user-can-enumerate-all-users-through-graphql-endpoint-14-6' into '14-6-stable-ee' See merge request gitlab-org/security/gitlab!2102 Changelog: security
Showing
- app/graphql/resolvers/users_resolver.rb 6 additions, 3 deletionsapp/graphql/resolvers/users_resolver.rb
- lib/api/users.rb 3 additions, 3 deletionslib/api/users.rb
- spec/graphql/resolvers/users_resolver_spec.rb 16 additions, 3 deletionsspec/graphql/resolvers/users_resolver_spec.rb
- spec/requests/api/graphql/users_spec.rb 14 additions, 10 deletionsspec/requests/api/graphql/users_spec.rb
Please register or sign in to comment