mirror of
				https://github.com/go-gitea/gitea.git
				synced 2025-10-31 02:46:04 +01:00 
			
		
		
		
	Fix Agit pull request permission check (#32999)
user with read permission should also can create agit flow pull request. looks this logic was broken in https://github.com/go-gitea/gitea/pull/31033 this pull request try fix it and add test code. --------- Signed-off-by: a1012112796 <1012112796@qq.com> Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
This commit is contained in:
		| @@ -64,7 +64,8 @@ func NewPullRequest(ctx context.Context, opts *NewPullRequestOptions) error { | |||||||
| 	} | 	} | ||||||
|  |  | ||||||
| 	// user should be a collaborator or a member of the organization for base repo | 	// user should be a collaborator or a member of the organization for base repo | ||||||
| 	if !issue.Poster.IsAdmin { | 	canCreate := issue.Poster.IsAdmin || pr.Flow == issues_model.PullRequestFlowAGit | ||||||
|  | 	if !canCreate { | ||||||
| 		canCreate, err := repo_model.IsOwnerMemberCollaborator(ctx, repo, issue.Poster.ID) | 		canCreate, err := repo_model.IsOwnerMemberCollaborator(ctx, repo, issue.Poster.ID) | ||||||
| 		if err != nil { | 		if err != nil { | ||||||
| 			return err | 			return err | ||||||
|   | |||||||
| @@ -12,6 +12,7 @@ import ( | |||||||
| 	"strings" | 	"strings" | ||||||
| 	"testing" | 	"testing" | ||||||
|  |  | ||||||
|  | 	"code.gitea.io/gitea/modules/git" | ||||||
| 	"code.gitea.io/gitea/modules/test" | 	"code.gitea.io/gitea/modules/test" | ||||||
| 	"code.gitea.io/gitea/tests" | 	"code.gitea.io/gitea/tests" | ||||||
|  |  | ||||||
| @@ -226,3 +227,21 @@ func TestPullCreatePrFromBaseToFork(t *testing.T) { | |||||||
| 		assert.Regexp(t, "^/user1/repo1/pulls/[0-9]*$", url) | 		assert.Regexp(t, "^/user1/repo1/pulls/[0-9]*$", url) | ||||||
| 	}) | 	}) | ||||||
| } | } | ||||||
|  |  | ||||||
|  | func TestCreateAgitPullWithReadPermission(t *testing.T) { | ||||||
|  | 	onGiteaRun(t, func(t *testing.T, u *url.URL) { | ||||||
|  | 		dstPath := t.TempDir() | ||||||
|  |  | ||||||
|  | 		u.Path = "user2/repo1.git" | ||||||
|  | 		u.User = url.UserPassword("user4", userPassword) | ||||||
|  |  | ||||||
|  | 		t.Run("Clone", doGitClone(dstPath, u)) | ||||||
|  |  | ||||||
|  | 		t.Run("add commit", doGitAddSomeCommits(dstPath, "master")) | ||||||
|  |  | ||||||
|  | 		t.Run("do agit pull create", func(t *testing.T) { | ||||||
|  | 			err := git.NewCommand(git.DefaultContext, "push", "origin", "HEAD:refs/for/master", "-o").AddDynamicArguments("topic=" + "test-topic").Run(&git.RunOpts{Dir: dstPath}) | ||||||
|  | 			assert.NoError(t, err) | ||||||
|  | 		}) | ||||||
|  | 	}) | ||||||
|  | } | ||||||
|   | |||||||
		Reference in New Issue
	
	Block a user