From bbf83f5d4bd8dbe1cd6dbcf7b45ef47072e5add0 Mon Sep 17 00:00:00 2001 From: yp05327 <576951401@qq.com> Date: Thu, 6 Apr 2023 23:18:29 +0900 Subject: Improve permission check of packages (#23879) At first, we have one unified team unit permission which is called `Team.Authorize` in DB. But since https://github.com/go-gitea/gitea/pull/17811, we allowed different units to have different permission. The old code is only designed for the old version. So after #17811, if org users have write permission of other units, but have no permission of packages, they can also get write permission of packages. Co-authored-by: delvh --- models/fixtures/user.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) (limited to 'models/fixtures/user.yml') diff --git a/models/fixtures/user.yml b/models/fixtures/user.yml index ce54defacd..3e302dfb9a 100644 --- a/models/fixtures/user.yml +++ b/models/fixtures/user.yml @@ -844,8 +844,8 @@ num_following: 0 num_stars: 0 num_repos: 2 - num_teams: 1 - num_members: 0 + num_teams: 2 + num_members: 1 visibility: 2 repo_admin_change_team_access: false theme: "" -- cgit v1.2.3