GitlabAppPolicy previously allowed any authenticated user to update, delete, and create GitLab sources. Align it with GithubAppPolicy, require Application create authorization on the private-repo wizard, and reject OAuth callbacks from non-admins so members cannot escalate privileges. |
||
|---|---|---|
| .. | ||
| Browser | ||
| Feature | ||
| Scripts | ||
| Support | ||
| Traits | ||
| Unit | ||
| v4 | ||
| v5/Browser | ||
| CreatesApplication.php | ||
| DuskTestCase.php | ||
| Pest.php | ||
| TestCase.php | ||