summaryrefslogtreecommitdiff
path: root/spec
Commit message (Expand)AuthorAgeFilesLines
* Display only informaton visible to current userJarka Košanová2019-02-271-2/+93
* Display the correct number of MRs a user has access toIgor Drozdov2019-02-271-199/+309
* Merge branch 'security-2818_filter_impersonated_sessions-11-6' into '11-6-sta...Yorick Peterse2019-02-272-27/+26
|\
| * Remove ability to revoke active sessionImre Farkas2019-02-271-27/+0
| * Filter active sessions belonging to an admin impersonating the userImre Farkas2019-02-272-1/+27
* | Merge branch 'security-id-restricted-access-to-private-repo-11-6' into '11-6-...Yorick Peterse2019-02-273-49/+129
|\ \
| * | Forbid creating discussions for users with restricted accessIgor Drozdov2019-02-073-49/+129
| |/
* | Merge branch '11-6-security-2773-milestones-fix' into '11-6-stable'Yorick Peterse2019-02-2713-67/+157
|\ \
| * | Check issue milestone availabilityJarka Košanová2019-02-1313-67/+157
| |/
* | Merge branch 'security-2798-fix-boards-policy-11-6' into '11-6-stable'Yorick Peterse2019-02-271-8/+12
|\ \
| * | Disable board policies when issues are disabledHeinrich Lee Yu2019-02-141-8/+12
| |/
* | Merge branch '11-6-security-2797-milestone-mrs' into '11-6-stable'Yorick Peterse2019-02-271-1/+46
|\ \
| * | Show only MRs visible to user on milestone detailJarka Košanová2019-02-191-1/+46
| |/
* | Merge branch 'security-commit-private-related-mr-11-6' into '11-6-stable'Yorick Peterse2019-02-272-3/+38
|\ \
| * | Don't allow non-members to see private related MRsPatrick Bajao2019-02-152-3/+38
| |/
* | Merge branch 'security-kubernetes-google-login-csrf-11-6' into '11-6-stable'Yorick Peterse2019-02-271-19/+41
|\ \
| * | Validate session key when authorizing with GCP to create a clusterTiger2019-02-191-19/+41
| |/
* | Merge branch 'security-50334-11-6' into '11-6-stable'Yorick Peterse2019-02-272-64/+74
|\ \
| * | Fix git clone revealing private repo's presenceMark Chao2019-02-192-64/+74
| |/
* | Merge branch 'security-56348-11-6' into '11-6-stable'Yorick Peterse2019-02-273-2/+47
|\ \
| * | Check snippet attached file to be moved is within designated directoryMark Chao2019-02-213-2/+47
| |/
* | Check validity of prometheus_service before queryReuben Pereira2019-02-271-18/+43
* | Merge branch 'security-protect-private-repo-information-11-6' into '11-6-stable'Yorick Peterse2019-02-271-2/+57
|\ \
| * | Fix backported test for Rails 4Luke Duncalfe2019-02-211-2/+2
| * | Prevent leaking of private repo data through APILuke Duncalfe2019-02-201-2/+57
| |/
* | Arbitrary file read via MergeRequestDiffFrancisco Javier López2019-02-275-3/+75
* | Merge branch '11-6-security-2799-emails' into '11-6-stable'Yorick Peterse2019-02-271-13/+43
|\ \
| * | Remove link after issue move when no permissionsJarka Košanová2019-02-201-13/+43
| |/
* | Merge branch 'security-add-public-internal-groups-as-members-to-your-project-...Yorick Peterse2019-02-276-0/+60
|\ \
| * | Update specsMałgorzata Ksionek2019-02-211-1/+1
| * | Update specsMałgorzata Ksionek2019-02-211-6/+4
| * | Change how path is calledMałgorzata Ksionek2019-02-211-6/+4
| * | Fix conflictMałgorzata Ksionek2019-02-206-4/+68
| |/
* | Merge branch 'security-kubernetes-local-ssrf-11-6' into '11-6-stable'Yorick Peterse2019-02-272-0/+46
|\ \
| * | Do not allow local urls in Kubernetes formThong Kuah2019-02-212-0/+46
| |/
* | Merge branch 'security-11-6-57227-absolute-uri-missing-hierarchical-segment' ...Yorick Peterse2019-02-271-0/+7
|\ \
| * | Catch possible Addressable::URI::InvalidURIErrorBrett Walker2019-02-221-0/+7
| |/
* | Merge branch 'security-osw-stop-linking-to-packages-11-6' into '11-6-stable'Yorick Peterse2019-02-278-19/+72
|\ \
| * | Stop linking to unrecognized package sourcesOswaldo Ferreira2019-02-248-19/+72
| |/
* | Prevent disclosing project milestone titlesFelipe Artur2019-02-261-0/+37
|/
* Merge branch 'security-11-6-55320-stored-xss-in-user-status' into 'security-1...Tim Zallmann2019-02-041-3/+3
* Merge branch '56860-fix-spec-race-condition-upside-the-head' into 'master'Douglas Barbosa Alexandre2019-01-281-0/+3
* Merge branch 'security-11-6-22076-sanitize-url-in-names' into 'security-11-6'Yorick Peterse2019-01-252-3/+19
* Merge branch 'security-project-move-users-11-6' into 'security-11-6'Yorick Peterse2019-01-252-6/+38
* Merge branch '11-6-security-stored-xss-via-katex' into 'security-11-6'Yorick Peterse2019-01-251-3/+19
* Merge branch 'security-2780-disable-git-v2-protocol-11-6' into 'security-11-6'Yorick Peterse2019-01-251-1/+6
* Merge branch 'sh-fix-issue-56663-11-6' into 'security-11-6'Yorick Peterse2019-01-242-3/+16
* Merge branch 'security-fix-user-email-tag-push-leak-11-6' into 'security-11-6'Yorick Peterse2019-01-241-2/+2
* Merge branch 'security-import-path-logging-11-6' into 'security-11-6'Yorick Peterse2019-01-244-3/+51
* Merge branch 'security-contributed-projects-11-6' into 'security-11-6'Yorick Peterse2019-01-242-0/+44