Skip to content
Projects
Groups
Snippets
Help
Loading...
Help
Support
Keyboard shortcuts
?
Submit feedback
Contribute to GitLab
Sign in / Register
Toggle navigation
G
gitlab-ce
Project overview
Project overview
Details
Activity
Releases
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Issues
0
Issues
0
List
Boards
Labels
Milestones
Merge Requests
1
Merge Requests
1
Analytics
Analytics
Repository
Value Stream
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Create a new issue
Commits
Issue Boards
Open sidebar
nexedi
gitlab-ce
Commits
2336e773
Commit
2336e773
authored
Feb 14, 2019
by
GitLab Bot
Browse files
Options
Browse Files
Download
Plain Diff
Automatic merge of gitlab-org/gitlab-ce master
parents
aef01a7b
a092b5ae
Changes
4
Hide whitespace changes
Inline
Side-by-side
Showing
4 changed files
with
79 additions
and
1 deletion
+79
-1
app/models/board.rb
app/models/board.rb
+4
-0
app/policies/board_policy.rb
app/policies/board_policy.rb
+3
-1
changelogs/unreleased/sh-fix-board-user-assigns.yml
changelogs/unreleased/sh-fix-board-user-assigns.yml
+5
-0
spec/policies/board_policy_spec.rb
spec/policies/board_policy_spec.rb
+67
-0
No files found.
app/models/board.rb
View file @
2336e773
...
...
@@ -21,6 +21,10 @@ class Board < ActiveRecord::Base
group_id
.
present?
end
def
project_board?
project_id
.
present?
end
def
backlog_list
lists
.
merge
(
List
.
backlog
).
take
end
...
...
app/policies/board_policy.rb
View file @
2336e773
...
...
@@ -4,10 +4,12 @@ class BoardPolicy < BasePolicy
delegate
{
@subject
.
parent
}
condition
(
:is_group_board
)
{
@subject
.
group_board?
}
condition
(
:is_project_board
)
{
@subject
.
project_board?
}
rule
{
is_
group_board
?
can?
(
:read_group
)
:
can?
(
:read_project
)
}.
enable
:read_parent
rule
{
is_
project_board
&
can?
(
:read_project
)
}.
enable
:read_parent
rule
{
is_group_board
&
can?
(
:read_group
)
}.
policy
do
enable
:read_parent
enable
:read_milestone
enable
:read_issue
end
...
...
changelogs/unreleased/sh-fix-board-user-assigns.yml
0 → 100644
View file @
2336e773
---
title
:
Fix 403 errors when adding an assignee list in project boards
merge_request
:
25263
author
:
type
:
fixed
spec/policies/board_policy_spec.rb
0 → 100644
View file @
2336e773
# frozen_string_literal: true
require
'spec_helper'
describe
BoardPolicy
do
let
(
:user
)
{
create
(
:user
)
}
let
(
:project
)
{
create
(
:project
,
:private
)
}
let
(
:group
)
{
create
(
:group
,
:private
)
}
let
(
:group_board
)
{
create
(
:board
,
group:
group
)
}
let
(
:project_board
)
{
create
(
:board
,
project:
project
)
}
let
(
:board_permissions
)
do
[
:read_parent
,
:read_milestone
,
:read_issue
]
end
def
expect_allowed
(
*
permissions
)
permissions
.
each
{
|
p
|
is_expected
.
to
be_allowed
(
p
)
}
end
def
expect_disallowed
(
*
permissions
)
permissions
.
each
{
|
p
|
is_expected
.
not_to
be_allowed
(
p
)
}
end
context
'group board'
do
subject
{
described_class
.
new
(
user
,
group_board
)
}
context
'user has access'
do
before
do
group
.
add_developer
(
user
)
end
it
do
expect_allowed
(
*
board_permissions
)
end
end
context
'user does not have access'
do
it
do
expect_disallowed
(
*
board_permissions
)
end
end
end
context
'project board'
do
subject
{
described_class
.
new
(
user
,
project_board
)
}
context
'user has access'
do
before
do
project
.
add_developer
(
user
)
end
it
do
expect_allowed
(
*
board_permissions
)
end
end
context
'user does not have access'
do
it
do
expect_disallowed
(
*
board_permissions
)
end
end
end
end
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment