enforce reqRepoReader(unit.TypeIssues) POST /repos/{owner}/{repo}/issues

(cherry picked from commit d3db2fa8bc85e9d67f30854bba0a4c1e8b57b015)
This commit is contained in:
Loïc Dachary 2023-11-02 15:42:22 +01:00
parent c70eb32280
commit 6b4cb070cc
No known key found for this signature in database
GPG key ID: 992D23B392F9E4F2

View file

@ -1154,7 +1154,7 @@ func Routes(ctx gocontext.Context) *web.Route {
m.Group("/{username}/{reponame}", func() {
m.Group("/issues", func() {
m.Combo("").Get(repo.ListIssues).
Post(reqToken(), mustNotBeArchived, bind(api.CreateIssueOption{}), repo.CreateIssue)
Post(reqToken(), mustNotBeArchived, bind(api.CreateIssueOption{}), reqRepoReader(unit.TypeIssues), repo.CreateIssue)
m.Get("/pinned", reqRepoReader(unit.TypeIssues), repo.ListPinnedIssues)
m.Group("/comments", func() {
m.Get("", repo.ListRepoIssueComments)