Skip to content

Commit

Permalink
code: Add logic to check for online commit permissions
Browse files Browse the repository at this point in the history
  • Loading branch information
doortts committed Mar 13, 2017
1 parent a4dd951 commit 06dd16b
Showing 1 changed file with 5 additions and 0 deletions.
5 changes: 5 additions & 0 deletions app/controllers/BoardApp.java
Original file line number Diff line number Diff line change
Expand Up @@ -173,6 +173,11 @@ public static Result newPostForm(String userName, String projectName) {
}

if (textFileEditRequested()) {
boolean isAllowedToFileEdit =
AccessControl.isProjectResourceCreatable(UserApp.currentUser(), project, ResourceType.COMMIT);
if(!isAllowedToFileEdit){
return forbidden(ErrorViews.Forbidden.render("error.forbidden", project));
}
preparedBodyText = GitUtil.getReadTextFile(project,
getBranchNameFromQueryString(), request().getQueryString("path"));
}
Expand Down

0 comments on commit 06dd16b

Please sign in to comment.