Skip to content
Projects
Groups
Snippets
Help
Loading...
Help
Support
Keyboard shortcuts
?
Submit feedback
Contribute to GitLab
Sign in / Register
Toggle navigation
G
gitlab-ce
Project overview
Project overview
Details
Activity
Releases
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Issues
0
Issues
0
List
Boards
Labels
Milestones
Merge Requests
1
Merge Requests
1
Analytics
Analytics
Repository
Value Stream
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Create a new issue
Commits
Issue Boards
Open sidebar
nexedi
gitlab-ce
Commits
d2716cde
Commit
d2716cde
authored
Jan 28, 2016
by
Gabriel Mazetto
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
Geo: Redirect when using disallowed requests on readonly
parent
8e8731aa
Changes
1
Hide whitespace changes
Inline
Side-by-side
Showing
1 changed file
with
26 additions
and
8 deletions
+26
-8
lib/gitlab/middleware/readonly_geo.rb
lib/gitlab/middleware/readonly_geo.rb
+26
-8
No files found.
lib/gitlab/middleware/readonly_geo.rb
View file @
d2716cde
module
Gitlab
module
Middleware
class
ReadonlyGeo
READONLY
_METHODS
=
%w(PATCH PUT DELETE)
DISALLOWED
_METHODS
=
%w(PATCH PUT DELETE)
def
initialize
(
app
)
@app
=
app
end
def
call
(
env
)
if
READONLY_METHODS
.
include?
(
env
[
'REQUEST_METHOD'
])
&&
Gitlab
::
Geo
.
readonly?
@env
=
env
if
disallowed_request?
&&
Gitlab
::
Geo
.
readonly?
Rails
.
logger
.
debug
(
'Gitlab Geo: preventing possible non readonly operation'
)
rflash
=
rack_flash
(
env
)
rflash
.
alert
=
'You are using Gitlab Geo'
env
[
'rack.session'
][
'flash'
]
=
rflash
.
to_session_value
rack_flash
.
alert
=
'You cannot do writing operations on a readonly Gitlab Geo instance'
rack_session
[
'flash'
]
=
rack_flash
.
to_session_value
#TODO: should redirect to last visited page or root url
return
[
301
,
{
'Location'
=>
last_visited_url
},
[]
]
end
@app
.
call
(
env
)
...
...
@@ -23,8 +24,25 @@ module Gitlab
private
def
rack_flash
(
env
)
ActionDispatch
::
Flash
::
FlashHash
.
from_session_value
(
env
[
'rack.session'
])
def
disallowed_request?
DISALLOWED_METHODS
.
include?
(
@env
[
'REQUEST_METHOD'
])
end
def
rack_flash
@rack_flash
||=
ActionDispatch
::
Flash
::
FlashHash
.
from_session_value
(
rack_session
)
end
def
rack_session
@env
[
'rack.session'
]
end
def
request
@request
||=
Rack
::
Request
.
new
(
@env
)
end
def
last_visited_url
Rails
.
logger
.
debug
(
"SESSION:
#{
rack_session
.
inspect
}
"
)
@env
[
'HTTP_REFERER'
]
||
rack_session
[
'user_return_to'
]
||
Rails
.
application
.
routes
.
url_helpers
.
root_url
end
end
end
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment