mirror of
https://github.com/go-gitea/gitea.git
synced 2026-10-04 07:33:44 +09:00
Backport #39501 by @silverwind Several handlers skipped checks that their sibling routes or settings already enforce. This brings them in line. - Push mirror API honors `DISABLE_NEW_PUSH` and checks the caller's permission - Media API serves small files with the usual content headers - Issue attachment API ignores comment attachments - Push-to-create respects `FORCE_PRIVATE` - Profile feeds and follow actions respect `ENABLE_FEED` and owner visibility - Tag delete route refuses release tags - Refresh token grant only accepts refresh tokens - Gitea migrations bound the source's page size Co-authored-by: silverwind <me@silverwind.io> Co-authored-by: bircni <bircni@icloud.com>
This commit is contained in:
@@ -734,18 +734,10 @@ func UsernameSubRoute(ctx *context.Context) {
|
||||
ShowGPGKeys(ctx)
|
||||
}
|
||||
case strings.HasSuffix(username, ".rss"):
|
||||
if !setting.Other.EnableFeed {
|
||||
ctx.HTTPError(http.StatusNotFound)
|
||||
return
|
||||
}
|
||||
if reloadParam(".rss") {
|
||||
feed.ShowUserFeedRSS(ctx)
|
||||
}
|
||||
case strings.HasSuffix(username, ".atom"):
|
||||
if !setting.Other.EnableFeed {
|
||||
ctx.HTTPError(http.StatusNotFound)
|
||||
return
|
||||
}
|
||||
if reloadParam(".atom") {
|
||||
feed.ShowUserFeedAtom(ctx)
|
||||
}
|
||||
|
||||
@@ -322,6 +322,13 @@ func prepareUserProfileTabData(ctx *context.Context, profileDbRepo *repo_model.R
|
||||
|
||||
// ActionUserFollow is for follow/unfollow user request
|
||||
func ActionUserFollow(ctx *context.Context) {
|
||||
isOrg := ctx.ContextUser.IsOrganization()
|
||||
if isOrg && !organization.HasOrgOrUserVisible(ctx, ctx.ContextUser, ctx.Doer) ||
|
||||
!isOrg && !user_model.IsUserVisibleToViewer(ctx, ctx.ContextUser, ctx.Doer) {
|
||||
ctx.NotFound(nil)
|
||||
return
|
||||
}
|
||||
|
||||
var err error
|
||||
switch ctx.FormString("action") {
|
||||
case "follow":
|
||||
|
||||
Reference in New Issue
Block a user