Skip to content

Restrict issue type attribute being edited by guest users

What does this MR do?

A guest user in a project or logged-in user in a public project should be able to set issue type(issue or incident) but should not be able to change it afterwards.

re #337665 (comment 655291065)

Screenshots or Screencasts (strongly suggested)

issue type before after
issue Screen_Recording_2021-08-23_at_11.26.20 Screen_Recording_2021-08-23_at_11.28.16
incident Screen_Recording_2021-08-23_at_11.31.34 Screen_Recording_2021-08-23_at_11.29.35

How to setup and validate locally (strongly suggested)

Does this MR meet the acceptance criteria?

Conformity

Availability and Testing

Security

Does this MR contain changes to processing or storing of credentials or tokens, authorization and authentication methods or other items described in the security review guidelines? If not, then delete this Security section.

  • Label as security and @ mention @gitlab-com/gl-security/appsec
  • The MR includes necessary changes to maintain consistency between UI, API, email, or other methods
  • Security reports checked/validated by a reviewer from the AppSec team

Related to #337665 (closed)

Edited by Alexandru Croitor

Merge request reports