diff options
author | Yorick Peterse <yorickpeterse@gmail.com> | 2019-01-24 15:47:40 +0300 |
---|---|---|
committer | Yorick Peterse <yorickpeterse@gmail.com> | 2019-01-24 15:47:43 +0300 |
commit | 2692cee68bb961019e555168a55f729a7e125095 (patch) | |
tree | 5d8b5e989bade9ff727c7386b951ba39d9808fff /spec | |
parent | 9128a397824d6e402bc5098fc5427c8280604881 (diff) |
Merge branch 'security-2776-fix-add-reaction-permissions-11-6' into 'security-11-6'
[11.6] Revoke award_emoji permissions for confidential issues
See merge request gitlab/gitlabhq!2850
(cherry picked from commit f645472619fe1e1ec4fdaa02010408d548287efb)
47d86827 Prevent award_emoji to notes not visible to user
Diffstat (limited to 'spec')
-rw-r--r-- | spec/policies/note_policy_spec.rb | 2 |
1 files changed, 2 insertions, 0 deletions
diff --git a/spec/policies/note_policy_spec.rb b/spec/policies/note_policy_spec.rb index 7e25c53e77c..0e848c74659 100644 --- a/spec/policies/note_policy_spec.rb +++ b/spec/policies/note_policy_spec.rb @@ -28,6 +28,7 @@ describe NotePolicy, mdoels: true do expect(policy).to be_disallowed(:admin_note) expect(policy).to be_disallowed(:resolve_note) expect(policy).to be_disallowed(:read_note) + expect(policy).to be_disallowed(:award_emoji) end end @@ -40,6 +41,7 @@ describe NotePolicy, mdoels: true do expect(policy).to be_allowed(:admin_note) expect(policy).to be_allowed(:resolve_note) expect(policy).to be_allowed(:read_note) + expect(policy).to be_allowed(:award_emoji) end end end |