summaryrefslogtreecommitdiff
path: root/app/policies
diff options
context:
space:
mode:
authorMayra Cabrera <mcabrera@gitlab.com>2019-06-14 20:40:21 +0000
committerStan Hu <stanhu@gmail.com>2019-06-14 20:40:21 +0000
commitd7f10c2949cef3fb6c15d4972cf8e8186d6d84a0 (patch)
treecc17c353be14a903723f55a715f70128e31439e8 /app/policies
parentad722a4e1f588382f5c5c1848c0502864993c7e7 (diff)
downloadgitlab-ce-d7f10c2949cef3fb6c15d4972cf8e8186d6d84a0.tar.gz
Do not blindly expose public project statistics
Add the missing check on GraphQL API for project statistics
Diffstat (limited to 'app/policies')
-rw-r--r--app/policies/project_statistics_policy.rb5
1 files changed, 5 insertions, 0 deletions
diff --git a/app/policies/project_statistics_policy.rb b/app/policies/project_statistics_policy.rb
new file mode 100644
index 00000000000..c0592f1ea13
--- /dev/null
+++ b/app/policies/project_statistics_policy.rb
@@ -0,0 +1,5 @@
+# frozen_string_literal: true
+
+class ProjectStatisticsPolicy < BasePolicy
+ delegate { @subject.project }
+end