summaryrefslogtreecommitdiff
path: root/app
diff options
context:
space:
mode:
authorGiorgenes Gelatti <ggelatti@gitlab.com>2019-07-23 19:57:28 +1000
committerNathan Friend <nathan@gitlab.com>2019-07-30 13:49:48 -0300
commitc2d1fbe507cc1732927ca7c656078cf47754ceeb (patch)
tree5675a04d4ca55c51d71f6f9334fa9740e5d445ae /app
parent786133d31434d1dbb185b2c0ff5eee663f5841d5 (diff)
downloadgitlab-ce-c2d1fbe507cc1732927ca7c656078cf47754ceeb.tar.gz
Validates tag names and tags#bulk_destroy
Diffstat (limited to 'app')
-rw-r--r--app/controllers/projects/registry/tags_controller.rb9
1 files changed, 9 insertions, 0 deletions
diff --git a/app/controllers/projects/registry/tags_controller.rb b/app/controllers/projects/registry/tags_controller.rb
index 22c87dfe1c0..633a7865cfe 100644
--- a/app/controllers/projects/registry/tags_controller.rb
+++ b/app/controllers/projects/registry/tags_controller.rb
@@ -29,7 +29,16 @@ module Projects
end
def bulk_destroy
+ unless params[:ids].present?
+ head :bad_request
+ return
+ end
+
@tags = (params[:ids] || []).map { |tag_name| image.tag(tag_name) }
+ unless @tags.all? { |tag| tag.valid_name? }
+ head :bad_request
+ return
+ end
success_count = 0
@tags.each do |tag|