diff --git a/debian/patches/cve-2017-0882.patch b/debian/patches/cve-2017-0882.patch index 8b9ed4f69c..2da61bec95 100644 --- a/debian/patches/cve-2017-0882.patch +++ b/debian/patches/cve-2017-0882.patch @@ -1,28 +1,26 @@ -Description: Security patch for CVE-2017-0882 -Author: Brian Neel -Bug: https://gitlab.com/gitlab-org/gitlab-ce/issues/29661 -Last-Update: 2017-03-21 ---- -This patch header follows DEP-3: http://dep.debian.net/deps/dep3/ +diff --git a/app/controllers/projects/issues_controller.rb b/app/controllers/projects/issues_controller.rb +index cb64926..d7928cb 100644 --- a/app/controllers/projects/issues_controller.rb +++ b/app/controllers/projects/issues_controller.rb -@@ -112,7 +112,7 @@ +@@ -112,7 +112,7 @@ class Projects::IssuesController < Projects::ApplicationController end format.json do - render json: @issue.to_json(include: { milestone: {}, assignee: { methods: :avatar_url }, labels: { methods: :text_color } }) -+ render json: @issue.to_json(include: { milestone: {}, assignee: { only: [:name, :username], methods: [:avatar_url] }, labels: { methods: :text_color } }, methods: [:task_status, :task_status_short]) ++ render json: @issue.to_json(include: { milestone: {}, assignee: { only: [:name, :username], methods: [:avatar_url] }, labels: { methods: :text_color } }) end end +diff --git a/app/controllers/projects/merge_requests_controller.rb b/app/controllers/projects/merge_requests_controller.rb +index 6e15c06..317011c 100644 --- a/app/controllers/projects/merge_requests_controller.rb +++ b/app/controllers/projects/merge_requests_controller.rb -@@ -278,7 +278,7 @@ +@@ -278,7 +278,7 @@ class Projects::MergeRequestsController < Projects::ApplicationController @merge_request.target_project, @merge_request]) end format.json do - render json: @merge_request.to_json(include: { milestone: {}, assignee: { methods: :avatar_url }, labels: { methods: :text_color } }) -+ render json: @merge_request.to_json(include: { milestone: {}, assignee: { only: [:name, :username], methods: [:avatar_url] }, labels: { methods: :text_color } }, methods: [:task_status, :task_status_short]) ++ render json: @merge_request.to_json(include: { milestone: {}, assignee: { only: [:name, :username], methods: [:avatar_url] }, labels: { methods: :text_color } }) end end else