mirror of
1
Fork 0
forgejo/models/actions
Gusted 0b17346cff
fix(sec): web route update and delete runner variables
The web route to update and delete variables of runners did not check if
the ID that was given belonged to the context it was requested in, this
made it possible to update and delete every existing runner variable of
a instance for any authenticated user.

The code has been reworked to always take into account the context of
the request (owner and repository ID).
2025-02-08 07:21:14 +00:00
..
artifact.go Always update expiration time when creating an artifact (#32281) 2024-10-20 09:43:42 +02:00
forgejo.go feat(cli): allow updates to runners' secrets 2024-07-22 11:55:43 +02:00
forgejo_test.go Add testifylint to lint checks (#4535) 2024-07-30 19:41:10 +00:00
main_test.go
run.go Detect whether action view branch was deleted (#32764) 2024-12-15 09:45:10 +01:00
run_job.go Add search action jobs for API routes, repo, org and global level (#6300) 2025-01-14 11:17:42 +00:00
run_job_list.go
run_job_status_test.go Improve Actions status aggregations (#32860) 2024-12-22 08:46:38 +01:00
run_job_test.go Add search action jobs for API routes, repo, org and global level (#6300) 2025-01-14 11:17:42 +00:00
run_list.go
runner.go fix(sec): web route delete runner 2025-02-08 07:21:14 +00:00
runner_list.go
runner_test.go fix(sec): web route delete runner 2025-02-08 07:21:14 +00:00
runner_token.go Clarify Actions resources ownership (#31724) 2024-08-04 18:24:10 +02:00
runner_token_test.go Add testifylint to lint checks (#4535) 2024-07-30 19:41:10 +00:00
schedule.go chore: Remove `ScheduleList` 2025-01-31 16:22:26 +01:00
schedule_spec.go Use UTC as default timezone when schedule Actions cron tasks (#31742) 2024-08-04 18:24:10 +02:00
schedule_spec_list.go
schedule_spec_test.go Use UTC as default timezone when schedule Actions cron tasks (#31742) 2024-08-04 18:24:10 +02:00
status.go
task.go Add search action jobs for API routes, repo, org and global level (#6300) 2025-01-14 11:17:42 +00:00
task_list.go Add search action jobs for API routes, repo, org and global level (#6300) 2025-01-14 11:17:42 +00:00
task_output.go
task_step.go
tasks_version.go
utils.go
utils_test.go
variable.go fix(sec): web route update and delete runner variables 2025-02-08 07:21:14 +00:00