summaryrefslogtreecommitdiff
path: root/app/models/ability.rb
diff options
context:
space:
mode:
authorFelipe Artur <felipefac@gmail.com>2016-03-09 13:57:57 -0300
committerFelipe Artur <felipefac@gmail.com>2016-03-10 10:38:36 -0300
commit96fc1d90927624345c7426b28fb3fd135e901e60 (patch)
treed3e4fd45a242555f854a99531705c70b245c444a /app/models/ability.rb
parentc3e70280dffe7ee0859ebd73b902d424ca5f809a (diff)
downloadgitlab-ce-96fc1d90927624345c7426b28fb3fd135e901e60.tar.gz
Add security specs
Diffstat (limited to 'app/models/ability.rb')
-rw-r--r--app/models/ability.rb2
1 files changed, 1 insertions, 1 deletions
diff --git a/app/models/ability.rb b/app/models/ability.rb
index 1c9b15069aa..fe460ccdaca 100644
--- a/app/models/ability.rb
+++ b/app/models/ability.rb
@@ -296,7 +296,7 @@ class Ability
def can_read_group?(user, group)
is_project_member = ProjectsFinder.new.execute(user, group: group).any?
- user.admin? || group.public? || group.internal? || group.users.include?(user)
+ user.admin? || group.public? || group.internal? || is_project_member || group.users.include?(user)
end
def namespace_abilities(user, namespace)