Welcome to mirror list, hosted at ThFree Co, Russian Federation.

gitlab.com/gitlab-org/gitlab-foss.git - Unnamed repository; edit this file 'description' to name the repository.
summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorGiorgenes Gelatti <ggelatti@gitlab.com>2019-07-23 12:57:28 +0300
committerNathan Friend <nathan@gitlab.com>2019-07-30 19:49:48 +0300
commitc2d1fbe507cc1732927ca7c656078cf47754ceeb (patch)
tree5675a04d4ca55c51d71f6f9334fa9740e5d445ae /app/controllers/projects/registry
parent786133d31434d1dbb185b2c0ff5eee663f5841d5 (diff)
Validates tag names and tags#bulk_destroy
Diffstat (limited to 'app/controllers/projects/registry')
-rw-r--r--app/controllers/projects/registry/tags_controller.rb9
1 files changed, 9 insertions, 0 deletions
diff --git a/app/controllers/projects/registry/tags_controller.rb b/app/controllers/projects/registry/tags_controller.rb
index 22c87dfe1c0..633a7865cfe 100644
--- a/app/controllers/projects/registry/tags_controller.rb
+++ b/app/controllers/projects/registry/tags_controller.rb
@@ -29,7 +29,16 @@ module Projects
end
def bulk_destroy
+ unless params[:ids].present?
+ head :bad_request
+ return
+ end
+
@tags = (params[:ids] || []).map { |tag_name| image.tag(tag_name) }
+ unless @tags.all? { |tag| tag.valid_name? }
+ head :bad_request
+ return
+ end
success_count = 0
@tags.each do |tag|