diff options
author | Giorgenes Gelatti <ggelatti@gitlab.com> | 2019-07-23 19:57:28 +1000 |
---|---|---|
committer | Nathan Friend <nathan@gitlab.com> | 2019-07-30 13:49:48 -0300 |
commit | c2d1fbe507cc1732927ca7c656078cf47754ceeb (patch) | |
tree | 5675a04d4ca55c51d71f6f9334fa9740e5d445ae /app | |
parent | 786133d31434d1dbb185b2c0ff5eee663f5841d5 (diff) | |
download | gitlab-ce-c2d1fbe507cc1732927ca7c656078cf47754ceeb.tar.gz |
Validates tag names and tags#bulk_destroy
Diffstat (limited to 'app')
-rw-r--r-- | app/controllers/projects/registry/tags_controller.rb | 9 |
1 files changed, 9 insertions, 0 deletions
diff --git a/app/controllers/projects/registry/tags_controller.rb b/app/controllers/projects/registry/tags_controller.rb index 22c87dfe1c0..633a7865cfe 100644 --- a/app/controllers/projects/registry/tags_controller.rb +++ b/app/controllers/projects/registry/tags_controller.rb @@ -29,7 +29,16 @@ module Projects end def bulk_destroy + unless params[:ids].present? + head :bad_request + return + end + @tags = (params[:ids] || []).map { |tag_name| image.tag(tag_name) } + unless @tags.all? { |tag| tag.valid_name? } + head :bad_request + return + end success_count = 0 @tags.each do |tag| |