From 68d13322290a52360cd485d24bcfff995d98cf97 Mon Sep 17 00:00:00 2001 From: Oswaldo Ferreira Date: Wed, 9 Jan 2019 17:24:05 -0200 Subject: Don't process MR refs for guests in the notes --- app/policies/project_policy.rb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'app/policies/project_policy.rb') diff --git a/app/policies/project_policy.rb b/app/policies/project_policy.rb index 12f9f29dcc1..d90bb647018 100644 --- a/app/policies/project_policy.rb +++ b/app/policies/project_policy.rb @@ -393,7 +393,7 @@ class ProjectPolicy < BasePolicy end.enable :read_issue_iid rule do - (can?(:read_project_for_iids) & merge_requests_visible_to_user) | can?(:read_merge_request) + (~guest & can?(:read_project_for_iids) & merge_requests_visible_to_user) | can?(:read_merge_request) end.enable :read_merge_request_iid rule { ~can_have_multiple_clusters & has_clusters }.prevent :add_cluster -- cgit v1.2.3