mirror of
1
Fork 0
forgejo/models/actions
Gusted 77db7655e0
fix(sec): web route update and delete runner variables
The web route to update and delete variables of runners did not check if
the ID that was given belonged to the context it was requested in, this
made it possible to update and delete every existing runner variable of
a instance for any authenticated user.

The code has been reworked to always take into account the context of
the request (owner and repository ID).
2025-02-08 06:04:14 +00:00
..
artifact.go Always update expiration time when creating an artifact (#32281) 2024-10-20 09:43:42 +02:00
forgejo.go feat(cli): allow updates to runners' secrets 2024-07-22 11:55:43 +02:00
forgejo_test.go Add testifylint to lint checks (#4535) 2024-07-30 19:41:10 +00:00
main_test.go fix(actions): prevent deleted records' UUID from colliding with new records (#3830) 2024-05-19 10:46:15 +00:00
run.go Detect whether action view branch was deleted (#32764) 2024-12-15 09:45:10 +01:00
run_job.go Improve Actions status aggregations (#32860) 2024-12-22 08:46:38 +01:00
run_job_list.go Add container.FilterSlice function (gitea#30339) 2024-04-16 11:49:44 +02:00
run_job_status_test.go Improve Actions status aggregations (#32860) 2024-12-22 08:46:38 +01:00
run_list.go Add container.FilterSlice function (gitea#30339) 2024-04-16 11:49:44 +02:00
runner.go fix(sec): web route delete runner 2025-02-08 06:04:14 +00:00
runner_list.go Refactor more filterslice (gitea#30370) 2024-04-16 11:51:00 +02:00
runner_test.go fix(sec): web route delete runner 2025-02-08 06:04:14 +00:00
runner_token.go Clarify Actions resources ownership (#31724) 2024-08-04 18:24:10 +02:00
runner_token_test.go Add testifylint to lint checks (#4535) 2024-07-30 19:41:10 +00:00
schedule.go Trim title before insert/update to database to match the size requirements of database (#32498) 2024-11-17 12:18:56 +01:00
schedule_list.go Add container.FilterSlice function (gitea#30339) 2024-04-16 11:49:44 +02:00
schedule_spec.go Use UTC as default timezone when schedule Actions cron tasks (#31742) 2024-08-04 18:24:10 +02:00
schedule_spec_list.go [BUG] Add early-return to loading items from `SpecList` 2024-07-20 01:27:11 +02:00
schedule_spec_test.go Use UTC as default timezone when schedule Actions cron tasks (#31742) 2024-08-04 18:24:10 +02:00
status.go Refactor locale&string&template related code (#29165) 2024-02-16 15:20:52 +01:00
task.go Harden runner updateTask and updateLog api (#32462) 2024-11-17 08:45:37 +01:00
task_list.go Drop `IDOrderDesc` for listing Actions task and always order by `id DESC` (#31150) 2024-06-02 16:26:54 +02:00
task_output.go Fix no ActionTaskOutput table waring (#28149) 2023-11-21 08:02:51 +00:00
task_step.go
tasks_version.go Add codespell support and fix a good number of typos with its help (#3270) 2024-05-09 13:49:37 +00:00
utils.go
utils_test.go
variable.go fix(sec): web route update and delete runner variables 2025-02-08 06:04:14 +00:00