Skip to content
Snippets Groups Projects

fix(sec): protect transition route

Merged f00wl requested to merge fix-security-issue into main
All threads resolved!

Fix a security issue that allowed anybody to apply a transition to any profile.

  • require user to be logged to apply a transition
  • only profile own and admin can apply a transition

Fix #135 Ref !80 (merged)

Merge request reports

Loading
Loading

Activity

Filter activity
  • Approvals
  • Assignees & reviewers
  • Comments (from bots)
  • Comments (from users)
  • Commits & branches
  • Edits
  • Labels
  • Lock status
  • Mentions
  • Merge request status
  • Tracking
  • ornanovitch added 1 commit

    added 1 commit

    • 0d6663c4 - fix(sec): use predefined `authorized` function from actions.py

    Compare with previous version

  • ornanovitch resolved all threads

    resolved all threads

  • kaiyou approved this merge request

    approved this merge request

  • ornanovitch added 1 commit

    added 1 commit

    Compare with previous version

  • ornanovitch enabled an automatic merge when the pipeline for 28d25c24 succeeds

    enabled an automatic merge when the pipeline for 28d25c24 succeeds

  • merged

  • ornanovitch mentioned in commit f173cf0d

    mentioned in commit f173cf0d

  • Please register or sign in to reply
    Loading