From 52909f8bdba4673cc87f7729f05f1b7fb19074c8 Mon Sep 17 00:00:00 2001 From: Robert Speicher <rspeicher@gmail.com> Date: Tue, 14 Apr 2015 17:32:51 -0400 Subject: [PATCH] Add permission check to ReferenceExtractor's user mentions --- lib/gitlab/reference_extractor.rb | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/lib/gitlab/reference_extractor.rb b/lib/gitlab/reference_extractor.rb index 64e8a65010..34aae38435 100644 --- a/lib/gitlab/reference_extractor.rb +++ b/lib/gitlab/reference_extractor.rb @@ -32,7 +32,7 @@ module Gitlab project.team.members.flatten elsif namespace = Namespace.find_by(path: identifier) if namespace.is_a?(Group) - namespace.users + namespace.users if can?(current_user, :read_group, namespace) else namespace.owner end -- 2.30.9