From 237ddd60244526ab5869c78cc086cec637544399 Mon Sep 17 00:00:00 2001 From: Dmitriy Zaporozhets Date: Fri, 24 Jan 2014 21:29:52 +0200 Subject: Improve authorization for new/edit blob pages Signed-off-by: Dmitriy Zaporozhets --- app/controllers/projects/blob_controller.rb | 1 + 1 file changed, 1 insertion(+) (limited to 'app/controllers/projects/blob_controller.rb') diff --git a/app/controllers/projects/blob_controller.rb b/app/controllers/projects/blob_controller.rb index 2aa73471e2b..a1a8bed09f4 100644 --- a/app/controllers/projects/blob_controller.rb +++ b/app/controllers/projects/blob_controller.rb @@ -6,6 +6,7 @@ class Projects::BlobController < Projects::ApplicationController before_filter :authorize_read_project! before_filter :authorize_code_access! before_filter :require_non_empty_project + before_filter :authorize_push!, only: [:destroy] before_filter :blob -- cgit v1.2.1