summaryrefslogtreecommitdiff
path: root/lib/gitlab/reference_extractor.rb
diff options
context:
space:
mode:
authorRobert Speicher <rspeicher@gmail.com>2015-04-14 17:32:51 -0400
committerRobert Speicher <rspeicher@gmail.com>2015-04-20 13:01:45 -0400
commit52909f8bdba4673cc87f7729f05f1b7fb19074c8 (patch)
treec14287dd59d2c53f90585dcaa724ea2911838613 /lib/gitlab/reference_extractor.rb
parentb0ea7b3b3dd3be2d8ce0c0f53a64bcd01f8b2118 (diff)
downloadgitlab-ce-52909f8bdba4673cc87f7729f05f1b7fb19074c8.tar.gz
Add permission check to ReferenceExtractor's user mentions
Diffstat (limited to 'lib/gitlab/reference_extractor.rb')
-rw-r--r--lib/gitlab/reference_extractor.rb2
1 files changed, 1 insertions, 1 deletions
diff --git a/lib/gitlab/reference_extractor.rb b/lib/gitlab/reference_extractor.rb
index 64e8a650107..34aae384355 100644
--- a/lib/gitlab/reference_extractor.rb
+++ b/lib/gitlab/reference_extractor.rb
@@ -32,7 +32,7 @@ module Gitlab
project.team.members.flatten
elsif namespace = Namespace.find_by(path: identifier)
if namespace.is_a?(Group)
- namespace.users
+ namespace.users if can?(current_user, :read_group, namespace)
else
namespace.owner
end