diff options
author | GitLab Bot <gitlab-bot@gitlab.com> | 2021-01-05 03:10:20 +0300 |
---|---|---|
committer | GitLab Bot <gitlab-bot@gitlab.com> | 2021-01-05 03:10:20 +0300 |
commit | b28aa8bd7d9f4289d6e73df2eb9d308b80b70d95 (patch) | |
tree | f2b8ee3eea854b76543b52ca1bc63f46d9ccb2c8 /lib/gitlab/auth.rb | |
parent | 9248363e3eb740b2f1dccb3a63f09aff4fcdf94f (diff) |
Add latest changes from gitlab-org/gitlab@master
Diffstat (limited to 'lib/gitlab/auth.rb')
-rw-r--r-- | lib/gitlab/auth.rb | 6 |
1 files changed, 4 insertions, 2 deletions
diff --git a/lib/gitlab/auth.rb b/lib/gitlab/auth.rb index 1aabb05f19e..1f5cce249d8 100644 --- a/lib/gitlab/auth.rb +++ b/lib/gitlab/auth.rb @@ -198,7 +198,9 @@ module Gitlab return unless valid_scoped_token?(token, all_available_scopes) - if token.user.can?(:log_in) || token.user.can?(:bot_log_in, project) + return if project && token.user.project_bot? && !project.bots.include?(token.user) + + if token.user.can?(:log_in) || token.user.project_bot? Gitlab::Auth::Result.new(token.user, nil, :personal_access_token, abilities_for_scopes(token.scopes)) end end @@ -283,7 +285,7 @@ module Gitlab return unless build.project.builds_enabled? if build.user - return unless build.user.can?(:log_in) || build.user.can?(:bot_log_in, build.project) + return unless build.user.can?(:log_in) || (build.user.project_bot? && build.project.bots&.include?(build.user)) # If user is assigned to build, use restricted credentials of user Gitlab::Auth::Result.new(build.user, build.project, :build, build_authentication_abilities) |