summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorRobert Speicher <rspeicher@gmail.com>2017-08-17 17:52:21 -0400
committerRobert Speicher <rspeicher@gmail.com>2017-08-17 17:52:21 -0400
commit7bfb6a61e561dc758a9b9b0dcb24852773eabb28 (patch)
tree0f1dbbbc453291743f9a1bfa8075122225a7db5c
parent6daa9c276c8817a11e385a9dbeb04ad4a83035d0 (diff)
downloadgitlab-ce-rs-gitlab-security-json-serialization.tar.gz
TEMP: Add FIXMEs for remaining violationsrs-gitlab-security-json-serialization
-rw-r--r--app/controllers/projects/deploy_keys_controller.rb1
-rw-r--r--app/controllers/projects/merge_requests_controller.rb3
-rw-r--r--app/controllers/projects/milestones_controller.rb1
3 files changed, 5 insertions, 0 deletions
diff --git a/app/controllers/projects/deploy_keys_controller.rb b/app/controllers/projects/deploy_keys_controller.rb
index c2e621fa190..b3379e65ee3 100644
--- a/app/controllers/projects/deploy_keys_controller.rb
+++ b/app/controllers/projects/deploy_keys_controller.rb
@@ -12,6 +12,7 @@ class Projects::DeployKeysController < Projects::ApplicationController
respond_to do |format|
format.html { redirect_to_repository_settings(@project) }
format.json do
+ # FIXME (rspeicher): `as_json`
render json: Projects::Settings::DeployKeysPresenter.new(@project, current_user: current_user).as_json
end
end
diff --git a/app/controllers/projects/merge_requests_controller.rb b/app/controllers/projects/merge_requests_controller.rb
index 8af8137316b..d774e23351e 100644
--- a/app/controllers/projects/merge_requests_controller.rb
+++ b/app/controllers/projects/merge_requests_controller.rb
@@ -136,6 +136,9 @@ class Projects::MergeRequestsController < Projects::MergeRequests::ApplicationCo
end
format.json do
+ # FIXME (rspeicher): no whitelist for `MergeRequest`
+ # FIXME (rspeicher): no whitelist for `Milestone`
+ # FIXME (rspeicher): no whitelist for `Label`
render json: @merge_request.to_json(
include: {
milestone: {},
diff --git a/app/controllers/projects/milestones_controller.rb b/app/controllers/projects/milestones_controller.rb
index c94384d2a1a..a546affc911 100644
--- a/app/controllers/projects/milestones_controller.rb
+++ b/app/controllers/projects/milestones_controller.rb
@@ -26,6 +26,7 @@ class Projects::MilestonesController < Projects::ApplicationController
@milestones = @milestones.page(params[:page])
end
format.json do
+ # FIXME (rspeicher): `to_json`
render json: @milestones.to_json(methods: :name)
end
end