Fix permission check lapsus

This commit is contained in:
Urban Rotnik 2020-08-11 17:00:36 +02:00
parent 02bb29cf79
commit 7d186156a0

View file

@ -263,7 +263,9 @@ class SearchController < ApplicationController
def search_repository
@repository = Repository.find_by_id(params[:repository])
render_403 unless user.teams.include?(repository.team) || repository.private_shared_with?(user.teams)
unless current_user.teams.include?(@repository.team) || @repository.private_shared_with?(current_user.teams)
render_403
end
@repository_results = []
if @repository_search_count_total > 0
@repository_results =