From 82715da50dad90948f336680cb4f16112b9738b1 Mon Sep 17 00:00:00 2001 From: Marcin Kuzminski Date: Mon, 15 Apr 2013 02:11:06 +0200 Subject: added missing perms check on history call --- rhodecode/controllers/files.py | 3 +++ 1 file changed, 3 insertions(+) (limited to 'rhodecode') diff --git a/rhodecode/controllers/files.py b/rhodecode/controllers/files.py index 61cb5f01..14f35e74 100644 --- a/rhodecode/controllers/files.py +++ b/rhodecode/controllers/files.py @@ -182,6 +182,9 @@ class FilesController(BaseRepoController): return render('files/files.html') + @LoginRequired() + @HasRepoPermissionAnyDecorator('repository.read', 'repository.write', + 'repository.admin') def history(self, repo_name, revision, f_path, annotate=False): if request.environ.get('HTTP_X_PARTIAL_XHR'): c.changeset = self.__get_cs_or_redirect(revision, repo_name) -- cgit v1.2.3