diff options
author | GitLab Bot <gitlab-bot@gitlab.com> | 2020-06-18 14:18:50 +0300 |
---|---|---|
committer | GitLab Bot <gitlab-bot@gitlab.com> | 2020-06-18 14:18:50 +0300 |
commit | 8c7f4e9d5f36cff46365a7f8c4b9c21578c1e781 (patch) | |
tree | a77e7fe7a93de11213032ed4ab1f33a3db51b738 /app/controllers/projects/snippets | |
parent | 00b35af3db1abfe813a778f643dad221aad51fca (diff) |
Add latest changes from gitlab-org/gitlab@13-1-stable-ee
Diffstat (limited to 'app/controllers/projects/snippets')
-rw-r--r-- | app/controllers/projects/snippets/application_controller.rb | 19 |
1 files changed, 19 insertions, 0 deletions
diff --git a/app/controllers/projects/snippets/application_controller.rb b/app/controllers/projects/snippets/application_controller.rb new file mode 100644 index 00000000000..3f488b07e96 --- /dev/null +++ b/app/controllers/projects/snippets/application_controller.rb @@ -0,0 +1,19 @@ +# frozen_string_literal: true + +class Projects::Snippets::ApplicationController < Projects::ApplicationController + include FindSnippet + include SnippetAuthorizations + + private + + # This overrides the default snippet create authorization + # because ProjectSnippets are checked against the project rather + # than the user + def authorize_create_snippet! + return render_404 unless can?(current_user, :create_snippet, project) + end + + def snippet_klass + ProjectSnippet + end +end |