diff options
author | Grzegorz Bizon <grzesiek.bizon@gmail.com> | 2016-04-05 13:55:15 +0200 |
---|---|---|
committer | Grzegorz Bizon <grzesiek.bizon@gmail.com> | 2016-04-05 13:55:15 +0200 |
commit | c52b5c92fbd31dc6f76087c43a94243d382d3172 (patch) | |
tree | 3fa786904191b132c3d429e7a157c2418f282542 /spec/controllers/projects/project_members_controller_spec.rb | |
parent | b248ee93814e8521fa0c73c82ec9ed113698b945 (diff) | |
download | gitlab-ce-c52b5c92fbd31dc6f76087c43a94243d382d3172.tar.gz |
Do not leak project exists when importing members
When importing members, and user does not have permissions to read
members in a source project, do not leak information about source
project existence. Notifiy user that project has not been found instead.
Diffstat (limited to 'spec/controllers/projects/project_members_controller_spec.rb')
-rw-r--r-- | spec/controllers/projects/project_members_controller_spec.rb | 4 |
1 files changed, 2 insertions, 2 deletions
diff --git a/spec/controllers/projects/project_members_controller_spec.rb b/spec/controllers/projects/project_members_controller_spec.rb index 6d1df8d9fbe..6ff3d4199f6 100644 --- a/spec/controllers/projects/project_members_controller_spec.rb +++ b/spec/controllers/projects/project_members_controller_spec.rb @@ -41,8 +41,8 @@ describe Projects::ProjectMembersController do expect(project.team_members).to_not include member end - it 'notifies about invalid permissions' do - expect(response).to set_flash.to /not authorized/ + it 'pretends that source projects does not exist' do + expect(response).to set_flash.to /source project not found/ end end end |