ensure visited repo's group owner is the same as the repo's owner, otherwise return 404

This commit is contained in:
☙◦ The Tablet ❀ GamerGirlandCo ◦❧
2026-04-02 20:00:59 -04:00
parent e6ee1a248f
commit d37bbd29d5
+1 -5
View File
@@ -282,10 +282,6 @@ func GetGroup(ctx *context.APIContext) {
ctx.APIErrorNotFound()
return
}
if group.OwnerID != ctx.Org.Organization.ID {
ctx.APIErrorNotFound()
return
}
if err != nil {
ctx.APIErrorInternal(err)
return
@@ -299,7 +295,7 @@ func GetGroup(ctx *context.APIContext) {
}
func DeleteGroup(ctx *context.APIContext) {
// swagger:operation DELETE /groups/{group_id} repositoryGroup groupDelete
// swagger:operation DELETE /groups/{group_id} repository-group groupDelete
// ---
// summary: Delete a repository group
// produces: