fix(repo): require organization owners for team access (#39046)

Require organization ownership before changing repository team
associations when team access is restricted.

---------

Co-authored-by: silverwind <me@silverwind.io>
This commit is contained in:
bircni
2026-08-23 08:35:55 +02:00
committed by GitHub
parent bedd2afb47
commit 204c0bafd3
10 changed files with 106 additions and 45 deletions
+3 -6
View File
@@ -659,16 +659,13 @@ func getRepositoryByParams(ctx *context.APIContext) *repo_model.Repository {
}
func canChangeTeamRepository(ctx *context.APIContext) bool {
if ctx.Org.Organization.RepoAdminChangeTeamAccess {
return true
}
isOwner, err := ctx.Org.Organization.IsOwnedBy(ctx, ctx.Doer.ID)
canChange, err := ctx.Org.Organization.CanChangeRepoTeamAccess(ctx, ctx.Doer)
if err != nil {
ctx.APIErrorInternal(err)
return false
}
if !isOwner {
ctx.APIError(http.StatusForbidden, "user is nor repo admin nor owner")
if !canChange {
ctx.APIError(http.StatusForbidden, "Must be an organization owner")
return false
}
return true