gitlab-org--gitlab-foss/app/views
Douwe Maan 742cee756b Merge branch 'jej-22869' into 'security'
Fix information disclosure in `Projects::BlobController#update`

It was possible to discover private project names by modifying `from_merge_request`parameter in `Projects::BlobController#update`. This fixes that.

- [ ] [CHANGELOG](https://gitlab.com/gitlab-org/gitlab-ce/blob/master/CHANGELOG.md) entry added
- Tests
  - [x] Added for this feature/bug
  - [ ] All builds are passing
- [x] Conform by the [merge request performance guides](http://docs.gitlab.com/ce/development/merge_request_performance_guidelines.html)
- [x] Conform by the [style guides](https://gitlab.com/gitlab-org/gitlab-ce/blob/master/CONTRIBUTING.md#style-guides)
- [x] [Squashed related commits together](https://git-scm.com/book/en/Git-Tools-Rewriting-History#Squashing-Commits)

https://gitlab.com/gitlab-org/gitlab-ce/issues/22869

See merge request !2023
2016-11-28 21:25:18 -03:00
..
abuse_report_mailer
abuse_reports
admin Merge branch '24161-non-intuitive-buttons-for-import-sources-in-administrator-settings-enable-disable' into 'master' 2016-11-22 21:03:42 +00:00
award_emoji Disabled award emoji button when user is not logged in 2016-11-22 10:25:09 +00:00
ci/lints
dashboard
devise Un-un-revert signin tab order fix. 2016-11-18 21:40:18 +01:00
discussions resolves updated and resolved status is not showin 2016-11-23 14:02:53 +06:00
doorkeeper
email_rejection_mailer
emojis
errors
events Removed data-user-is view code 2016-11-25 13:45:34 +01:00
explore
groups Add a starting date to milestones 2016-11-23 13:41:04 +02:00
help
import
invites
issues
kaminari/gitlab
koding
layouts Removed data-user-is view code 2016-11-25 13:45:34 +01:00
notify Move partials to links directory, feedback: 2016-11-22 13:44:25 +08:00
profiles properly escape username validation error message flash 2016-11-23 17:33:55 -06:00
projects Merge branch 'jej-22869' into 'security' 2016-11-28 21:25:18 -03:00
repository_check_mailer
search Search for a filename in a project 2016-11-16 14:25:54 +02:00
sent_notifications
shared Refactor issuable_filters_present to reduce duplications 2016-11-28 14:48:03 +05:00
sherlock
snippets
u2f
users