diff options
author | Alexandru Croitor <acroitor@gitlab.com> | 2019-09-10 15:30:07 +0300 |
---|---|---|
committer | Alexandru Croitor <acroitor@gitlab.com> | 2019-09-20 10:29:43 +0300 |
commit | fcc8136a9e94615130c62a3c64485aa895673d54 (patch) | |
tree | b267ac28c290057b2a24a73d4bd8f4f9b08f0f87 /changelogs | |
parent | 39381519f294742e4083dfd6a50c0c8ceddecd5d (diff) |
Redirect user to root path after unsubscribing from private resource
If user unsubsrcribes from a resource that they no longer have
access to they should not be revealed the resource path, but be
redirected to app root instead.
https://gitlab.com/gitlab-org/gitlab-ce/issues/64938
Diffstat (limited to 'changelogs')
-rw-r--r-- | changelogs/unreleased/security-64938-dont-disclose-path.yml | 6 |
1 files changed, 6 insertions, 0 deletions
diff --git a/changelogs/unreleased/security-64938-dont-disclose-path.yml b/changelogs/unreleased/security-64938-dont-disclose-path.yml new file mode 100644 index 00000000000..0c858401233 --- /dev/null +++ b/changelogs/unreleased/security-64938-dont-disclose-path.yml @@ -0,0 +1,6 @@ +--- +title: Fix new project path being disclosed through unsubscribe link of issue/merge + requests +merge_request: +author: +type: security |