ElasticSearch returns internal code, snippets, issues, wiki pages and MRs on public projects
Follow-up to https://gitlab.com/gitlab-org/gitlab-ee/issues/1046
As with the "normal" IssuableFinder
in gitlab-ce, project feature access levels are not being taken into account WIP MR here:
The problem is that a project may be public, yet have its issues and MRs visibility level as "internal" (10), in project_features, meaning that non-team-members should not be able to see them.
I've not verified whether this is a problem or not yet, I just don't want to forget about it!This is a problem on current master