1. 05 Mar, 2019 1 commit
  2. 27 Jul, 2018 4 commits
  3. 26 Jul, 2018 1 commit
  4. 24 Jul, 2018 1 commit
  5. 10 May, 2018 2 commits
    • Bob Van Landuyt's avatar
      Allows `access_(git|api)` to anonymous users · d801dd17
      Bob Van Landuyt authored
      The `access_git` and `access_api` were currently never checked for
      anonymous users. And they would also be allowed access:
      
        An anonymous user can clone and pull from a public repo
      
        An anonymous user can request public information from the API
      
      So the policy didn't actually reflect what we were enforcing.
      d801dd17
    • Bob Van Landuyt's avatar
      Block access to API & git when terms are enforced · f7f13f9d
      Bob Van Landuyt authored
      When terms are enforced, but the user has not accepted the terms
      access to the API & git is rejected with a message directing the user
      to the web app to accept the terms.
      f7f13f9d
  6. 29 Sep, 2017 1 commit
  7. 28 Sep, 2017 1 commit
  8. 01 Aug, 2017 1 commit
  9. 25 Jul, 2017 1 commit
  10. 03 Jul, 2017 1 commit
  11. 30 Jun, 2017 1 commit
    • Timothy Andrew's avatar
      Implement review comments for !12445 from @godfat and @rymai. · 3c88a786
      Timothy Andrew authored
      - Use `GlobalPolicy` to authorize the users that a non-authenticated user can
        fetch from `/api/v4/users`. We allow access if the `Gitlab::VisibilityLevel::PUBLIC`
        visibility level is not restricted.
      
      - Further, as before, `/api/v4/users` is only accessible to unauthenticated users if
        the `username` parameter is passed.
      
      - Turn off `authenticate!` for the `/api/v4/users` endpoint by matching on the actual
        route + method, rather than the description.
      
      - Change the type of `current_user` check in `UsersFinder` to be more
        compatible with EE.
      3c88a786
  12. 27 Jun, 2017 1 commit
  13. 15 Jun, 2017 1 commit
  14. 07 Apr, 2017 1 commit
  15. 09 Mar, 2017 3 commits
  16. 30 Aug, 2016 2 commits