Skip to content

Redact search to include code and wiki

Mark Chao requested to merge 36439-git-redact into master

What does this MR do?

Currently active records returned by Elasticsearch will be filtered one last time, checking the record is accessible by the user. This MR expands that to also filter Git related data (blob and wiki).

For #36439

Does this MR meet the acceptance criteria?

Conformity

Availability and Testing

Security

If this MR contains changes to processing or storing of credentials or tokens, authorization and authentication methods and other items described in the security review guidelines:

  • Label as security and @ mention @gitlab-com/gl-security/appsec
  • The MR includes necessary changes to maintain consistency between UI, API, email, or other methods
  • Security reports checked/validated by a reviewer from the AppSec team

Closes #36439

Edited by 🤖 GitLab Bot 🤖

Merge request reports