Commit a0626e79 authored by Jan Provaznik's avatar Jan Provaznik

Authorize user when listing board resources

Make sure that user is authorized to read users/milestones
on board users/milestone index actions.
parent 1c1a43fe
......@@ -85,3 +85,5 @@ module BoardsResponses
end
end
end
BoardsResponses.prepend(EE::BoardsResponses)
module Boards
class MilestonesController < Boards::ApplicationController
include BoardsResponses
before_action :authorize_read_milestone, only: [:index]
def index
milestones_finder = Boards::MilestonesFinder.new(board, current_user)
......
......@@ -5,6 +5,11 @@ module Boards
# If board parent is a group it enumerates all members of current group,
# ancestors, and descendants
# rubocop: disable CodeReuse/ActiveRecord
include BoardsResponses
before_action :authorize_read_parent, only: [:index]
def index
user_ids = user_finder.execute.select(:user_id)
......
module EE
module BoardsResponses
extend ActiveSupport::Concern
def authorize_read_parent
ability = board.group_board? ? :read_group : :read_project
authorize_action_for!(board.parent, ability)
end
def authorize_read_milestone
ability = board.group_board? ? :read_group : :read_milestone
authorize_action_for!(board.parent, ability)
end
end
end
---
title: Authorize users when listing board users and milestones.
merge_request:
author:
type: security
......@@ -5,6 +5,8 @@ describe Boards::MilestonesController do
let(:board) { create(:board, project: project) }
let(:user) { create(:user) }
describe 'GET index' do
context 'with authorized user' do
before do
create(:milestone, project: project)
......@@ -12,7 +14,6 @@ describe Boards::MilestonesController do
sign_in(user)
end
describe 'GET index' do
it 'returns a list of all milestones of board parent' do
get :index, board_id: board.to_param, format: :json
......@@ -24,4 +25,30 @@ describe Boards::MilestonesController do
expect(parsed_response.size).to eq(1)
end
end
context 'with unauthorized user' do
before do
sign_in(user)
end
shared_examples 'unauthorized board milestone listing' do
it 'returns a forbidden 403 response' do
get :index, board_id: board.to_param, format: :json
expect(response).to have_gitlab_http_status(403)
end
end
context 'with private group board' do
let(:group) { create(:group, :private) }
let(:board) { create(:board, group: group) }
it_behaves_like 'unauthorized board milestone listing'
end
context 'with private project board' do
it_behaves_like 'unauthorized board milestone listing'
end
end
end
end
require 'spec_helper'
describe Boards::UsersController do
let(:group) { create(:group) }
let(:group) { create(:group, :private) }
let(:board) { create(:board, group: group) }
let(:guest) { create(:user) }
let(:user) { create(:user) }
describe 'GET index' do
context 'with authorized user' do
before do
group.add_maintainer(user)
group.add_guest(guest)
......@@ -13,7 +15,6 @@ describe Boards::UsersController do
sign_in(user)
end
describe 'GET index' do
it 'returns a list of all members of board parent' do
get :index, namespace_id: group.to_param,
board_id: board.to_param,
......@@ -27,4 +28,30 @@ describe Boards::UsersController do
expect(parsed_response.length).to eq 2
end
end
context 'with unauthorized user' do
before do
sign_in(user)
end
shared_examples 'unauthorized board user listing' do
it 'returns a forbidden 403 response' do
get :index, board_id: board.to_param, format: :json
expect(response).to have_gitlab_http_status(403)
end
end
context 'with private group board' do
it_behaves_like 'unauthorized board user listing'
end
context 'with private project board' do
let(:project) { create(:project) }
let(:board) { create(:board, project: project) }
it_behaves_like 'unauthorized board user listing'
end
end
end
end
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment