Commit graph

4 commits

Author SHA1 Message Date
Charlie Ablett
d40b79021d Improper access control allows the attacker to comment in internal commit after they are no longer admin 2019-10-29 15:58:26 +00:00
Cindy Pallares
e122e14ac6
Merge branch 'security-guest-comments' into 'master'
[master]Fixed ability to comment on and edit/delete comments on locked or confidential issues

See merge request gitlab/gitlabhq!2612
2018-11-28 19:11:56 -05:00
Peter Leitzen
7fe85c1d42 Freeze string literals
See Danger's suggestions:
https://gitlab.com/gitlab-org/gitlab-ee/merge_requests/6869#note_93730253
2018-08-10 18:15:25 +02:00
Peter Leitzen
2022243a22 Create empty Commits::UpdateService and wire it up 2018-08-10 16:45:11 +02:00