debian-mirror-gitlab/debian/patches/cve-2017-0882.patch

27 lines
1.5 KiB
Diff
Raw Normal View History

2017-03-21 22:08:56 +05:30
diff --git a/app/controllers/projects/issues_controller.rb b/app/controllers/projects/issues_controller.rb
index cb64926..d7928cb 100644
2017-03-21 14:56:56 +05:30
--- a/app/controllers/projects/issues_controller.rb
+++ b/app/controllers/projects/issues_controller.rb
2017-03-21 22:08:56 +05:30
@@ -112,7 +112,7 @@ class Projects::IssuesController < Projects::ApplicationController
2017-03-21 14:56:56 +05:30
end
format.json do
- render json: @issue.to_json(include: { milestone: {}, assignee: { methods: :avatar_url }, labels: { methods: :text_color } })
2017-03-21 22:08:56 +05:30
+ render json: @issue.to_json(include: { milestone: {}, assignee: { only: [:name, :username], methods: [:avatar_url] }, labels: { methods: :text_color } })
2017-03-21 14:56:56 +05:30
end
end
2017-03-21 22:08:56 +05:30
diff --git a/app/controllers/projects/merge_requests_controller.rb b/app/controllers/projects/merge_requests_controller.rb
index 6e15c06..317011c 100644
2017-03-21 14:56:56 +05:30
--- a/app/controllers/projects/merge_requests_controller.rb
+++ b/app/controllers/projects/merge_requests_controller.rb
2017-03-21 22:08:56 +05:30
@@ -278,7 +278,7 @@ class Projects::MergeRequestsController < Projects::ApplicationController
2017-03-21 14:56:56 +05:30
@merge_request.target_project, @merge_request])
end
format.json do
- render json: @merge_request.to_json(include: { milestone: {}, assignee: { methods: :avatar_url }, labels: { methods: :text_color } })
2017-03-21 22:08:56 +05:30
+ render json: @merge_request.to_json(include: { milestone: {}, assignee: { only: [:name, :username], methods: [:avatar_url] }, labels: { methods: :text_color } })
2017-03-21 14:56:56 +05:30
end
end
else