##// END OF EJS Templates
pull-requests: security, check for permissions on exposure of repo-refs
ergo -
r2379:76c34f08 default
parent child Browse files
Show More
@@ -681,6 +681,13 b' class RepoPullRequestsView(RepoAppView, '
681 repo = Repository.get_by_repo_name(target_repo_name)
681 repo = Repository.get_by_repo_name(target_repo_name)
682 if not repo:
682 if not repo:
683 raise HTTPNotFound()
683 raise HTTPNotFound()
684
685 target_perm = HasRepoPermissionAny(
686 'repository.read', 'repository.write', 'repository.admin')(
687 target_repo_name)
688 if not target_perm:
689 raise HTTPNotFound()
690
684 return PullRequestModel().generate_repo_data(
691 return PullRequestModel().generate_repo_data(
685 repo, translator=self.request.translate)
692 repo, translator=self.request.translate)
686
693
General Comments 0
You need to be logged in to leave comments. Login now