Skip to content

Improve Permissions Checks for Feature Flag Issue Links

Jason Goodman requested to merge update-ffissue-create-permissions into master

What does this MR do?

Use Ability.issues_readable_by_user to check permissions when creating a link between a feature flag and an issue.

Follow up from !35377 (comment 369855794)

See also: #225170 (closed)

Issue: #26456 (closed)

Does this MR meet the acceptance criteria?

Conformity

Availability and Testing

Security

If this MR contains changes to processing or storing of credentials or tokens, authorization and authentication methods and other items described in the security review guidelines:

  • Label as security and @ mention @gitlab-com/gl-security/appsec
  • The MR includes necessary changes to maintain consistency between UI, API, email, or other methods
  • Security reports checked/validated by a reviewer from the AppSec team

Merge request reports