Skip to content
GitLab
Projects Groups Topics Snippets
  • /
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
  • Register
  • Sign in
  • G gitlab-ce
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributor statistics
    • Graph
    • Compare revisions
  • Issues 0
    • Issues 0
    • List
    • Boards
    • Service Desk
    • Milestones
  • Merge requests 1
    • Merge requests 1
  • CI/CD
    • CI/CD
    • Pipelines
    • Jobs
    • Schedules
  • Deployments
    • Deployments
    • Environments
    • Releases
  • Monitor
    • Monitor
    • Metrics
    • Incidents
  • Analytics
    • Analytics
    • Value stream
    • CI/CD
    • Repository
  • Wiki
    • Wiki
  • Snippets
    • Snippets
  • Activity
  • Graph
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
Collapse sidebar
  • nexedinexedi
  • gitlab-ce
  • Repository
  • gitlab-ce
  • lib
  • gitlab
  • auth
  • request_authenticator.rb
Find file BlameHistoryPermalink
  • Stan Hu's avatar
    Prevent users from bypassing 2FA on certain pages · 5a525549
    Stan Hu authored Sep 22, 2021
    https://gitlab.com/gitlab-org/gitlab/-/merge_requests/63287 made it
    possible to rate limit authenticated Git requests properly. However, it
    also inadvertently made it possible for certain pages to be viewed via
    HTTP Basic Authentication. We now restrict the sessionless
    authentication mechanism based on the current route to avoid this.
    
    Relates to https://gitlab.com/gitlab-org/gitlab/-/issues/341522
    
    Changelog: security
    5a525549
GitLab Nexedi Edition | About GitLab | About Nexedi | 沪ICP备2021021310号-2 | 沪ICP备2021021310号-7