34b71e734b
- To prevent an attacker from enumerating the `/users` API to get a list of all the admins. - Display the `is_admin?` flag wherever we display the `private_token` - at the moment, there are two instances: - When an admin uses `sudo` to view the `/user` endpoint - When logging in using the `/session` endpoint |
||
---|---|---|
.. | ||
api | ||
assets | ||
backup | ||
banzai | ||
bitbucket | ||
ci | ||
constraints | ||
container_registry | ||
generators/rails/post_deployment_migration | ||
gitlab | ||
json_web_token | ||
mattermost | ||
microsoft_teams | ||
omni_auth | ||
rouge | ||
support | ||
tasks | ||
additional_email_headers_interceptor.rb | ||
banzai.rb | ||
disable_email_interceptor.rb | ||
email_template_interceptor.rb | ||
event_filter.rb | ||
expand_variables.rb | ||
extracts_path.rb | ||
file_size_validator.rb | ||
file_streamer.rb | ||
gitlab.rb | ||
gt_one_coercion.rb | ||
repository_cache.rb | ||
static_model.rb | ||
unfold_form.rb | ||
uploaded_file.rb | ||
version_check.rb |