GitlabAppPolicy previously allowed any authenticated user to update, delete, and create GitLab sources. Align it with GithubAppPolicy, require Application create authorization on the private-repo wizard, and reject OAuth callbacks from non-admins so members cannot escalate privileges. |
||
|---|---|---|
| .. | ||
| DockerCompose.php | ||
| DockerImage.php | ||
| EmptyProject.php | ||
| GithubPrivateRepository.php | ||
| GithubPrivateRepositoryDeployKey.php | ||
| GitlabPrivateRepository.php | ||
| PublicGitRepository.php | ||
| Select.php | ||
| SimpleDockerfile.php | ||