Skip to content

Using tickets in private repositories #1037

@mliebelt

Description

@mliebelt

We are using GitBlit 1.6.2, and have enabled tickets on one server (due to the demand of one project). We use the projects and repositories in a multi-tenant way, which means that only some groups of users are allowed to see the repositories.

I have tried now the following:

  • Went to a private repository.
  • Selected there "tickets"
  • Created a new ticket.
  • Opened a different browser.
  • Logged in with a different user that has no access to the private repository before.
  • Went to "my tickets"
  • Searched there for something I knew was included in the ticket in the private repository.
  • Found the new created ticket. (which is wrong in my opinion)
  • When selecting the ticket, I get an error message: Unauthorized access for repository <PROJECT/repo>.git (which is ok)

In my opinion, tickets should behave in the same manner as the other artifacts in GitBlit. You should only have access to tickets, which are in repositories you could at least see (have view access).

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions