• Bob Van Landuyt's avatar
    Only assign merge params when allowed · 20cb4f7a
    Bob Van Landuyt authored
    When a user updates a merge request coming from a fork, they should
    not be able to set `force_remove_source_branch` if they cannot push
    code to the source project.
    
    Otherwise developers of the target project could remove the source
    branch of the source project by setting this flag through the API.
    20cb4f7a
security-bvl-validate-force-remove-branch-on-mrs.yml 154 Bytes