d801dd1774
The `access_git` and `access_api` were currently never checked for anonymous users. And they would also be allowed access: An anonymous user can clone and pull from a public repo An anonymous user can request public information from the API So the policy didn't actually reflect what we were enforcing. |
||
---|---|---|
.. | ||
application_setting | ||
ci | ||
clusters | ||
project_policy | ||
base_policy.rb | ||
commit_status_policy.rb | ||
deploy_key_policy.rb | ||
deploy_token_policy.rb | ||
deployment_policy.rb | ||
environment_policy.rb | ||
external_issue_policy.rb | ||
global_policy.rb | ||
group_label_policy.rb | ||
group_member_policy.rb | ||
group_policy.rb | ||
issuable_policy.rb | ||
issue_policy.rb | ||
merge_request_policy.rb | ||
namespace_policy.rb | ||
nil_policy.rb | ||
note_policy.rb | ||
personal_snippet_policy.rb | ||
project_label_policy.rb | ||
project_member_policy.rb | ||
project_policy.rb | ||
project_snippet_policy.rb | ||
protected_branch_policy.rb | ||
user_policy.rb |