mirror of
				https://codeberg.org/forgejo/forgejo.git
				synced 2025-10-30 22:11:07 +00:00 
			
		
		
		
	Fix comment permissions (#28213)
This PR will fix some missed checks for private repositories' data on web routes and API routes.
This commit is contained in:
		
					parent
					
						
							
								8b6f5a890b
							
						
					
				
			
			
				commit
				
					
						5504ce44d2
					
				
			
		
					 34 changed files with 417 additions and 105 deletions
				
			
		|  | @ -62,6 +62,11 @@ func GetHook(ctx *context.APIContext) { | |||
| 		return | ||||
| 	} | ||||
| 
 | ||||
| 	if !ctx.Doer.IsAdmin && hook.OwnerID != ctx.Doer.ID { | ||||
| 		ctx.NotFound() | ||||
| 		return | ||||
| 	} | ||||
| 
 | ||||
| 	apiHook, err := webhook_service.ToHook(ctx.Doer.HomeLink(), hook) | ||||
| 	if err != nil { | ||||
| 		ctx.InternalServerError(err) | ||||
|  |  | |||
		Loading…
	
	Add table
		Add a link
		
	
		Reference in a new issue