From 0fcbe48468f0e566929599dda36b2dedd72e5708 Mon Sep 17 00:00:00 2001 From: GitLab Bot Date: Wed, 1 Mar 2023 18:33:31 +0000 Subject: Add latest changes from gitlab-org/security/gitlab@15-8-stable-ee --- app/services/resource_access_tokens/create_service.rb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'app/services/resource_access_tokens/create_service.rb') diff --git a/app/services/resource_access_tokens/create_service.rb b/app/services/resource_access_tokens/create_service.rb index f6fe23b4555..c6948536053 100644 --- a/app/services/resource_access_tokens/create_service.rb +++ b/app/services/resource_access_tokens/create_service.rb @@ -125,7 +125,7 @@ module ResourceAccessTokens def do_not_allow_owner_access_level_for_project_bot?(access_level) resource.is_a?(Project) && - access_level.to_i == Gitlab::Access::OWNER && + access_level == Gitlab::Access::OWNER && !current_user.can?(:manage_owners, resource) end end -- cgit v1.2.1