Commit a0626e79 authored by Jan Provaznik's avatar Jan Provaznik

Authorize user when listing board resources

Make sure that user is authorized to read users/milestones
on board users/milestone index actions.
parent 1c1a43fe
...@@ -85,3 +85,5 @@ module BoardsResponses ...@@ -85,3 +85,5 @@ module BoardsResponses
end end
end end
end end
BoardsResponses.prepend(EE::BoardsResponses)
module Boards module Boards
class MilestonesController < Boards::ApplicationController class MilestonesController < Boards::ApplicationController
include BoardsResponses
before_action :authorize_read_milestone, only: [:index]
def index def index
milestones_finder = Boards::MilestonesFinder.new(board, current_user) milestones_finder = Boards::MilestonesFinder.new(board, current_user)
......
...@@ -5,6 +5,11 @@ module Boards ...@@ -5,6 +5,11 @@ module Boards
# If board parent is a group it enumerates all members of current group, # If board parent is a group it enumerates all members of current group,
# ancestors, and descendants # ancestors, and descendants
# rubocop: disable CodeReuse/ActiveRecord # rubocop: disable CodeReuse/ActiveRecord
include BoardsResponses
before_action :authorize_read_parent, only: [:index]
def index def index
user_ids = user_finder.execute.select(:user_id) user_ids = user_finder.execute.select(:user_id)
......
module EE
module BoardsResponses
extend ActiveSupport::Concern
def authorize_read_parent
ability = board.group_board? ? :read_group : :read_project
authorize_action_for!(board.parent, ability)
end
def authorize_read_milestone
ability = board.group_board? ? :read_group : :read_milestone
authorize_action_for!(board.parent, ability)
end
end
end
---
title: Authorize users when listing board users and milestones.
merge_request:
author:
type: security
...@@ -5,6 +5,8 @@ describe Boards::MilestonesController do ...@@ -5,6 +5,8 @@ describe Boards::MilestonesController do
let(:board) { create(:board, project: project) } let(:board) { create(:board, project: project) }
let(:user) { create(:user) } let(:user) { create(:user) }
describe 'GET index' do
context 'with authorized user' do
before do before do
create(:milestone, project: project) create(:milestone, project: project)
...@@ -12,7 +14,6 @@ describe Boards::MilestonesController do ...@@ -12,7 +14,6 @@ describe Boards::MilestonesController do
sign_in(user) sign_in(user)
end end
describe 'GET index' do
it 'returns a list of all milestones of board parent' do it 'returns a list of all milestones of board parent' do
get :index, board_id: board.to_param, format: :json get :index, board_id: board.to_param, format: :json
...@@ -24,4 +25,30 @@ describe Boards::MilestonesController do ...@@ -24,4 +25,30 @@ describe Boards::MilestonesController do
expect(parsed_response.size).to eq(1) expect(parsed_response.size).to eq(1)
end end
end end
context 'with unauthorized user' do
before do
sign_in(user)
end
shared_examples 'unauthorized board milestone listing' do
it 'returns a forbidden 403 response' do
get :index, board_id: board.to_param, format: :json
expect(response).to have_gitlab_http_status(403)
end
end
context 'with private group board' do
let(:group) { create(:group, :private) }
let(:board) { create(:board, group: group) }
it_behaves_like 'unauthorized board milestone listing'
end
context 'with private project board' do
it_behaves_like 'unauthorized board milestone listing'
end
end
end
end end
require 'spec_helper' require 'spec_helper'
describe Boards::UsersController do describe Boards::UsersController do
let(:group) { create(:group) } let(:group) { create(:group, :private) }
let(:board) { create(:board, group: group) } let(:board) { create(:board, group: group) }
let(:guest) { create(:user) } let(:guest) { create(:user) }
let(:user) { create(:user) } let(:user) { create(:user) }
describe 'GET index' do
context 'with authorized user' do
before do before do
group.add_maintainer(user) group.add_maintainer(user)
group.add_guest(guest) group.add_guest(guest)
...@@ -13,7 +15,6 @@ describe Boards::UsersController do ...@@ -13,7 +15,6 @@ describe Boards::UsersController do
sign_in(user) sign_in(user)
end end
describe 'GET index' do
it 'returns a list of all members of board parent' do it 'returns a list of all members of board parent' do
get :index, namespace_id: group.to_param, get :index, namespace_id: group.to_param,
board_id: board.to_param, board_id: board.to_param,
...@@ -27,4 +28,30 @@ describe Boards::UsersController do ...@@ -27,4 +28,30 @@ describe Boards::UsersController do
expect(parsed_response.length).to eq 2 expect(parsed_response.length).to eq 2
end end
end end
context 'with unauthorized user' do
before do
sign_in(user)
end
shared_examples 'unauthorized board user listing' do
it 'returns a forbidden 403 response' do
get :index, board_id: board.to_param, format: :json
expect(response).to have_gitlab_http_status(403)
end
end
context 'with private group board' do
it_behaves_like 'unauthorized board user listing'
end
context 'with private project board' do
let(:project) { create(:project) }
let(:board) { create(:board, project: project) }
it_behaves_like 'unauthorized board user listing'
end
end
end
end end
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment