Skip to content

Remove specific private project annotations on guest users

Joe Randazzo requested to merge update-guest-users-permission-column into master

What does this MR do?

Currently, our documented guest permissions column is not reflecting actual workflow based on private projects. The following permission actions ARE allowed on private projects;

  • Create an issue
  • Leave comments on an issue
  • Create confidential issue

This merge request removes the (1) annotation on the above actions because these can be performed on private projects.

The WHY: A prospect interested in GitLab.com brought this to my attention and caused confusion on how they can use guest users on GitLab.

This was tested on GitLab.com

Screenshots

Does this MR meet the acceptance criteria?

Conformity

Availability and Testing

Security

If this MR contains changes to processing or storing of credentials or tokens, authorization and authentication methods and other items described in the security review guidelines:

  • Label as security and @ mention @gitlab-com/gl-security/appsec
  • The MR includes necessary changes to maintain consistency between UI, API, email, or other methods
  • Security reports checked/validated by a reviewer from the AppSec team
Edited by Mike Jang

Merge request reports

Loading