Skip to content

CSP: disable LFS url when not using object storage

What does this MR do and why?

This backports !129985 (merged) to 16-3-stable-ee.

Disable the allow_lfs when object storage is not enabled for LFS.

  1. When using local storage, the path will come from within GitLab's primary URL
  2. When using local storage, Fog/CarrierWave will fail, unless user always supplies a bogus connection hash.
    • Omnibus leave this empty unless provided.

Related to #422936 (closed)

MR acceptance checklist

This checklist encourages us to confirm any changes have been analyzed to reduce risks in quality, performance, reliability, security, and maintainability.

  • This MR is backporting a bug fix, documentation update, or spec fix, previously merged in the default branch.
  • The original MR has been deployed to GitLab.com (not applicable for documentation or spec changes).
  • This MR has a severity label assigned (if applicable).
  • This MR has been approved by a maintainer (only one approval is required).
  • Ensure the e2e:package-and-test-ee job has either succeeded or been approved by a Software Engineer in Test.

Note to the merge request author and maintainer

If you have questions about the patch release process, please:

Edited by Stan Hu

Merge request reports

Loading