Skip to content

Raise error when using invalid relation type in member finder

Max Woolf requested to merge enforce-relation-types-group-member-finder into master

What does this MR do?

  • Adds a method that checks the include_relations argument in GroupMembersFinder#execute to make sure that it only includes valid methods.
    • A single typo in any of the potential array values causes the entire method to return an empty array currently.

Does this MR meet the acceptance criteria?

Conformity

Availability and Testing

Security

Does this MR contain changes to processing or storing of credentials or tokens, authorization and authentication methods or other items described in the security review guidelines? If not, then delete this Security section.

  • Label as security and @ mention @gitlab-com/gl-security/appsec
  • The MR includes necessary changes to maintain consistency between UI, API, email, or other methods
  • Security reports checked/validated by a reviewer from the AppSec team
Edited by Max Woolf

Merge request reports

Loading