Merge pull request #3485 from okriuchykhin/ok_SCI_6002

Fix permission checks in reports controller [SCI-6002]
This commit is contained in:
artoscinote 2021-08-18 15:27:49 +02:00 committed by GitHub
commit 80dfb04976
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23

View file

@ -372,7 +372,6 @@ class ReportsController < ApplicationController
.accessible_by_teams(current_team)
.name_like(search_params[:q])
.limit(Constants::SEARCH_LIMIT)
.select(:id, :name, :team_id, :permission_level)
repositories.each do |repository|
next unless can_manage_repository_rows?(current_user, repository)