Rémy Coutable
649382b1c2
Fix the /projects/:id/repository/branches endpoint to handle dots in the branch name when the project full patch contains a /
...
Signed-off-by: Rémy Coutable <remy@rymai.me>
2017-07-27 14:29:31 +02:00
Rémy Coutable
91f63820a5
Return is_admin
attribute in the GET /user endpoint for admins
...
Signed-off-by: Rémy Coutable <remy@rymai.me>
2017-07-12 12:45:46 +02:00
Felipe Artur
b5f596c3ff
Native group milestones
2017-07-07 15:08:49 +00:00
Valery Sizov
387c4b2c21
Backport of multiple_assignees_feature [ci skip]
2017-05-04 17:11:53 +03:00
Timothy Andrew
34b71e734b
Don't display the is_admin?
flag for user API responses.
...
- To prevent an attacker from enumerating the `/users` API to get a list of all
the admins.
- Display the `is_admin?` flag wherever we display the `private_token` - at the
moment, there are two instances:
- When an admin uses `sudo` to view the `/user` endpoint
- When logging in using the `/session` endpoint
2017-04-25 09:46:05 +00:00
Adam Niedzielski
c727d4328f
Remove "subscribed" field from API responses returning list of issues or merge requests
2017-03-06 14:17:07 +01:00
Adam Niedzielski
5753acfabc
Move schema definitions for our public API to a separate directory
2017-03-06 14:17:07 +01:00