From 9a75c2741d2806f5bb12d21b5a9d7387b2d44073 Mon Sep 17 00:00:00 2001 From: zeripath Date: Wed, 26 Jan 2022 20:01:35 +0000 Subject: Only view milestones from current repo (#18414) The endpoint /{username}/{reponame}/milestone/{id} is not currently restricted to the repo. This PR restricts the milestones to those within the repo. Signed-off-by: Andrew Thornton --- routers/web/repo/milestone.go | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'routers/web/repo/milestone.go') diff --git a/routers/web/repo/milestone.go b/routers/web/repo/milestone.go index eadc89333f..df5fd411b4 100644 --- a/routers/web/repo/milestone.go +++ b/routers/web/repo/milestone.go @@ -264,7 +264,7 @@ func DeleteMilestone(ctx *context.Context) { // MilestoneIssuesAndPulls lists all the issues and pull requests of the milestone func MilestoneIssuesAndPulls(ctx *context.Context) { milestoneID := ctx.ParamsInt64(":id") - milestone, err := models.GetMilestoneByID(milestoneID) + milestone, err := models.GetMilestoneByRepoID(ctx.Repo.Repository.ID, milestoneID) if err != nil { if models.IsErrMilestoneNotExist(err) { ctx.NotFound("GetMilestoneByID", err) -- cgit v1.2.3