diff options
author | Michael Kozono <mkozono@gmail.com> | 2019-08-27 01:40:42 +0300 |
---|---|---|
committer | Michael Kozono <mkozono@gmail.com> | 2019-08-27 01:40:42 +0300 |
commit | 452b5d605c7ef88c8385cb62afcfc78f45ea2d4c (patch) | |
tree | 86a871fb97446df0061b6a8d3710b7affe8fab1d | |
parent | 0f8058bc580ae09df71563c83fca2cc3ceb751fa (diff) | |
parent | 6fa5f510e83a91e19a1601bf6c01a9cffe6fd5c9 (diff) |
Merge branch 'sh-guard-against-orphaned-project-feature' into 'master'
Guard against deleted project feature entry
Closes #66482
See merge request gitlab-org/gitlab-ce!32187
-rw-r--r-- | app/policies/project_policy.rb | 2 | ||||
-rw-r--r-- | changelogs/unreleased/sh-guard-against-orphaned-project-feature.yml | 5 | ||||
-rw-r--r-- | spec/policies/project_policy_spec.rb | 13 |
3 files changed, 20 insertions, 0 deletions
diff --git a/app/policies/project_policy.rb b/app/policies/project_policy.rb index b8dee1b0789..e2634692dc7 100644 --- a/app/policies/project_policy.rb +++ b/app/policies/project_policy.rb @@ -502,6 +502,8 @@ class ProjectPolicy < BasePolicy end def feature_available?(feature) + return false unless project.project_feature + case project.project_feature.access_level(feature) when ProjectFeature::DISABLED false diff --git a/changelogs/unreleased/sh-guard-against-orphaned-project-feature.yml b/changelogs/unreleased/sh-guard-against-orphaned-project-feature.yml new file mode 100644 index 00000000000..99c8732c5b0 --- /dev/null +++ b/changelogs/unreleased/sh-guard-against-orphaned-project-feature.yml @@ -0,0 +1,5 @@ +--- +title: Guard against deleted project feature entry in project permissions +merge_request: 32187 +author: +type: fixed diff --git a/spec/policies/project_policy_spec.rb b/spec/policies/project_policy_spec.rb index 8fd54e0bf1d..71ba73d5661 100644 --- a/spec/policies/project_policy_spec.rb +++ b/spec/policies/project_policy_spec.rb @@ -94,6 +94,19 @@ describe ProjectPolicy do permissions.each { |p| is_expected.not_to be_allowed(p) } end + context 'with no project feature' do + subject { described_class.new(owner, project) } + + before do + project.project_feature.destroy + project.reload + end + + it 'returns false' do + is_expected.to be_disallowed(:read_build) + end + end + it 'does not include the read_issue permission when the issue author is not a member of the private project' do project = create(:project, :private) issue = create(:issue, project: project, author: create(:user)) |