diff options
author | Douwe Maan <douwe@gitlab.com> | 2017-12-11 15:51:07 +0000 |
---|---|---|
committer | Douwe Maan <douwe@gitlab.com> | 2017-12-11 15:51:07 +0000 |
commit | 0cc6eb8b0968b7f3a4101f786a4e980cad10f189 (patch) | |
tree | e384fd6fbca066d2d7ca94b105115a6268b38da7 /app/controllers | |
parent | a2d1648076cf55b09562f7ef081fd9e479398ab6 (diff) | |
parent | 429302b34c5d66bd79f49284964cfc21db794ba7 (diff) | |
download | gitlab-ce-0cc6eb8b0968b7f3a4101f786a4e980cad10f189.tar.gz |
Merge branch '40743-bug-accepting-new-group-members-when-permission-level-developer' into 'master'
Bugfix: User can't change the access level of an access requester
Closes #40743
See merge request gitlab-org/gitlab-ce!15832
Diffstat (limited to 'app/controllers')
-rw-r--r-- | app/controllers/groups/group_members_controller.rb | 2 | ||||
-rw-r--r-- | app/controllers/projects/project_members_controller.rb | 2 |
2 files changed, 2 insertions, 2 deletions
diff --git a/app/controllers/groups/group_members_controller.rb b/app/controllers/groups/group_members_controller.rb index 8fc234a62b1..5919bf54468 100644 --- a/app/controllers/groups/group_members_controller.rb +++ b/app/controllers/groups/group_members_controller.rb @@ -22,7 +22,7 @@ class Groups::GroupMembersController < Groups::ApplicationController end def update - @group_member = @group.group_members.find(params[:id]) + @group_member = @group.members_and_requesters.find(params[:id]) return render_403 unless can?(current_user, :update_group_member, @group_member) diff --git a/app/controllers/projects/project_members_controller.rb b/app/controllers/projects/project_members_controller.rb index d925dcd21ff..5a01a59481b 100644 --- a/app/controllers/projects/project_members_controller.rb +++ b/app/controllers/projects/project_members_controller.rb @@ -26,7 +26,7 @@ class Projects::ProjectMembersController < Projects::ApplicationController end def update - @project_member = @project.project_members.find(params[:id]) + @project_member = @project.members_and_requesters.find(params[:id]) return render_403 unless can?(current_user, :update_project_member, @project_member) |