Merge branch 'security-fix-pat-web-access' into 'master'
[master] Resolve "Personal access token with only `read_user` scope can be used to authenticate any web request" See merge request gitlab/gitlabhq!2583
显示
- app/controllers/application_controller.rb 1 个添加, 22 个删除app/controllers/application_controller.rb
- app/controllers/concerns/sessionless_authentication.rb 28 个添加, 0 个删除app/controllers/concerns/sessionless_authentication.rb
- app/controllers/dashboard/projects_controller.rb 1 个添加, 0 个删除app/controllers/dashboard/projects_controller.rb
- app/controllers/dashboard_controller.rb 3 个添加, 0 个删除app/controllers/dashboard_controller.rb
- app/controllers/graphql_controller.rb 1 个添加, 0 个删除app/controllers/graphql_controller.rb
- app/controllers/groups_controller.rb 3 个添加, 0 个删除app/controllers/groups_controller.rb
- app/controllers/projects/commits_controller.rb 1 个添加, 0 个删除app/controllers/projects/commits_controller.rb
- app/controllers/projects/issues_controller.rb 9 个添加, 8 个删除app/controllers/projects/issues_controller.rb
- app/controllers/projects/tags_controller.rb 2 个添加, 0 个删除app/controllers/projects/tags_controller.rb
- app/controllers/projects_controller.rb 2 个添加, 0 个删除app/controllers/projects_controller.rb
- app/controllers/users_controller.rb 1 个添加, 0 个删除app/controllers/users_controller.rb
- changelogs/unreleased/security-fix-pat-web-access.yml 5 个添加, 0 个删除changelogs/unreleased/security-fix-pat-web-access.yml
- config/initializers/rack_attack_global.rb 5 个添加, 5 个删除config/initializers/rack_attack_global.rb
- lib/gitlab/auth/request_authenticator.rb 10 个添加, 4 个删除lib/gitlab/auth/request_authenticator.rb
- lib/gitlab/auth/user_auth_finders.rb 37 个添加, 2 个删除lib/gitlab/auth/user_auth_finders.rb
- spec/controllers/application_controller_spec.rb 0 个添加, 151 个删除spec/controllers/application_controller_spec.rb
- spec/controllers/dashboard/projects_controller_spec.rb 5 个添加, 0 个删除spec/controllers/dashboard/projects_controller_spec.rb
- spec/controllers/dashboard_controller_spec.rb 18 个添加, 13 个删除spec/controllers/dashboard_controller_spec.rb
- spec/controllers/graphql_controller_spec.rb 45 个添加, 2 个删除spec/controllers/graphql_controller_spec.rb
- spec/controllers/groups_controller_spec.rb 20 个添加, 0 个删除spec/controllers/groups_controller_spec.rb
加载中
想要评论请 注册 或 登录