mirror of
https://github.com/go-gitea/gitea.git
synced 2026-08-03 12:34:34 +00:00
Backport #38321 by @bircni The `/user/starred` and `/user/subscriptions` endpoints returned private repositories a user had starred/watched even after their access to those repositories was revoked, still exposing the repository name, description and visibility (including later metadata changes). Private repositories in the starred/watched queries are now gated on the actor's current access via `AccessibleRepositoryCondition`, so users who no longer have access no longer receive the metadata. Public repositories and public-only tokens are unaffected. Co-authored-by: bircni <bircni@icloud.com>
This commit is contained in:
@@ -24,6 +24,7 @@ func getStarredRepos(ctx *context.APIContext, user *user_model.User, private boo
|
||||
ListOptions: utils.GetListOptions(ctx),
|
||||
StarrerID: user.ID,
|
||||
IncludePrivate: private,
|
||||
Actor: user,
|
||||
}
|
||||
opts.ApplyPublicOnly(ctx.PublicOnly)
|
||||
|
||||
|
||||
@@ -22,6 +22,7 @@ func getWatchedRepos(ctx *context.APIContext, user *user_model.User, private boo
|
||||
ListOptions: utils.GetListOptions(ctx),
|
||||
WatcherID: user.ID,
|
||||
IncludePrivate: private,
|
||||
Actor: user,
|
||||
}
|
||||
opts.ApplyPublicOnly(ctx.PublicOnly)
|
||||
|
||||
|
||||
Reference in New Issue
Block a user