mirror of
https://github.com/go-gitea/gitea.git
synced 2026-10-01 20:59:45 +09:00
Backport #39501 by @silverwind Several handlers skipped checks that their sibling routes or settings already enforce. This brings them in line. - Push mirror API honors `DISABLE_NEW_PUSH` and checks the caller's permission - Media API serves small files with the usual content headers - Issue attachment API ignores comment attachments - Push-to-create respects `FORCE_PRIVATE` - Profile feeds and follow actions respect `ENABLE_FEED` and owner visibility - Tag delete route refuses release tags - Refresh token grant only accepts refresh tokens - Gitea migrations bound the source's page size Co-authored-by: silverwind <me@silverwind.io> Co-authored-by: bircni <bircni@icloud.com>
This commit is contained in:
@@ -162,7 +162,7 @@ func GetRawFileOrLFS(ctx *context.APIContext) {
|
||||
|
||||
// if it's not a pointer, just serve the data directly
|
||||
if !pointer.IsValid() {
|
||||
_, _ = ctx.Resp.Write(lfsPointerBuf)
|
||||
httplib.ServeUserContentByReader(ctx.Req, ctx.Resp, int64(len(lfsPointerBuf)), bytes.NewReader(lfsPointerBuf), httplib.ServeHeaderOptions{Filename: blob.Name()})
|
||||
return
|
||||
}
|
||||
|
||||
@@ -171,7 +171,7 @@ func GetRawFileOrLFS(ctx *context.APIContext) {
|
||||
|
||||
// If there isn't one, just serve the data directly
|
||||
if errors.Is(err, git_model.ErrLFSObjectNotExist) {
|
||||
_, _ = ctx.Resp.Write(lfsPointerBuf)
|
||||
httplib.ServeUserContentByReader(ctx.Req, ctx.Resp, int64(len(lfsPointerBuf)), bytes.NewReader(lfsPointerBuf), httplib.ServeHeaderOptions{Filename: blob.Name()})
|
||||
return
|
||||
} else if err != nil {
|
||||
ctx.APIErrorInternal(err)
|
||||
@@ -198,7 +198,7 @@ func GetRawFileOrLFS(ctx *context.APIContext) {
|
||||
return
|
||||
}
|
||||
defer lfsDataFile.Close()
|
||||
httplib.ServeUserContentByFile(ctx.Base.Req, ctx.Base.Resp, lfsDataFile, httplib.ServeHeaderOptions{Filename: ctx.Repo.TreePath})
|
||||
httplib.ServeUserContentByFile(ctx.Base.Req, ctx.Base.Resp, lfsDataFile, httplib.ServeHeaderOptions{Filename: blob.Name()})
|
||||
}
|
||||
|
||||
func getBlobForEntry(ctx *context.APIContext) (blob *git.Blob, entry *git.TreeEntry, lastModified *time.Time) {
|
||||
|
||||
@@ -386,8 +386,8 @@ func attachmentBelongsToRepoOrIssue(ctx *context.APIContext, attachment *repo_mo
|
||||
ctx.APIErrorNotFound("no such attachment in repo")
|
||||
return false
|
||||
}
|
||||
if attachment.IssueID == 0 {
|
||||
log.Debug("Requested attachment[%d] is not in an issue.", attachment.ID)
|
||||
if attachment.IssueID == 0 || attachment.CommentID != 0 {
|
||||
log.Debug("Requested attachment[%d] is not an issue attachment.", attachment.ID)
|
||||
ctx.APIErrorNotFound("no such attachment in issue")
|
||||
return false
|
||||
} else if issue != nil && attachment.IssueID != issue.ID {
|
||||
|
||||
@@ -291,6 +291,11 @@ func AddPushMirror(ctx *context.APIContext) {
|
||||
return
|
||||
}
|
||||
|
||||
if setting.Mirror.DisableNewPush {
|
||||
ctx.APIError(http.StatusForbidden, "the site administrator has disabled the creation of new push mirrors")
|
||||
return
|
||||
}
|
||||
|
||||
pushMirror := web.GetForm[*api.CreatePushMirrorOption](ctx)
|
||||
CreatePushMirror(ctx, pushMirror)
|
||||
}
|
||||
@@ -356,7 +361,7 @@ func CreatePushMirror(ctx *context.APIContext, mirrorOption *api.CreatePushMirro
|
||||
|
||||
address, err := git.ParseRemoteAddr(mirrorOption.RemoteAddress, mirrorOption.RemoteUsername, mirrorOption.RemotePassword)
|
||||
if err == nil {
|
||||
err = migrations.IsMigrateURLAllowed(address, ctx.ContextUser)
|
||||
err = migrations.IsMigrateURLAllowed(address, ctx.Doer)
|
||||
}
|
||||
if err != nil {
|
||||
HandleRemoteAddressError(ctx, err)
|
||||
|
||||
@@ -10,13 +10,36 @@ import (
|
||||
"gitea.dev/models/db"
|
||||
repo_model "gitea.dev/models/repo"
|
||||
"gitea.dev/models/unittest"
|
||||
user_model "gitea.dev/models/user"
|
||||
"gitea.dev/modules/setting"
|
||||
api "gitea.dev/modules/structs"
|
||||
"gitea.dev/modules/test"
|
||||
"gitea.dev/services/contexttest"
|
||||
|
||||
"github.com/stretchr/testify/assert"
|
||||
)
|
||||
|
||||
func TestCreatePushMirrorUsesCallerPermission(t *testing.T) {
|
||||
defer test.MockVariableValue(&setting.ImportLocalPaths, true)()
|
||||
ctx, resp := contexttest.MockAPIContext(t, "user2/repo1")
|
||||
ctx.Doer = &user_model.User{}
|
||||
ctx.ContextUser = &user_model.User{AllowImportLocal: true}
|
||||
|
||||
CreatePushMirror(ctx, &api.CreatePushMirrorOption{RemoteAddress: "local-mirror", Interval: "0"})
|
||||
|
||||
assert.Equal(t, http.StatusUnauthorized, resp.Code)
|
||||
}
|
||||
|
||||
func TestAddPushMirrorDisabled(t *testing.T) {
|
||||
defer test.MockVariableValue(&setting.Mirror.DisableNewPush, true)()
|
||||
ctx, resp := contexttest.MockAPIContext(t, "user2/repo1")
|
||||
|
||||
AddPushMirror(ctx)
|
||||
|
||||
assert.Equal(t, http.StatusForbidden, resp.Code)
|
||||
assert.Contains(t, resp.Body.String(), "the site administrator has disabled the creation of new push mirrors")
|
||||
}
|
||||
|
||||
// TestPushMirrorSync verifies the endpoint attempts every push mirror instead
|
||||
// of aborting on the first failure, reporting all failed remotes with a 422.
|
||||
// Each remote name is not a configured git remote, so SyncPushMirror fails fast
|
||||
|
||||
Reference in New Issue
Block a user