From c70eb32280e35ece8677497ed4c01fb6193563e2 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Lo=C3=AFc=20Dachary?= Date: Thu, 2 Nov 2023 15:41:10 +0100 Subject: [PATCH] enforce reqRepoReader(unit.TypeIssues) GET /repos/{owner}/{repo}/issues/pinned (cherry picked from commit 00fad97fc1b27db40a002c9ab3f709d04dc2cdd1) --- routers/api/v1/api.go | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/routers/api/v1/api.go b/routers/api/v1/api.go index a60552d590..90adeee809 100644 --- a/routers/api/v1/api.go +++ b/routers/api/v1/api.go @@ -1155,7 +1155,7 @@ func Routes(ctx gocontext.Context) *web.Route { m.Group("/issues", func() { m.Combo("").Get(repo.ListIssues). Post(reqToken(), mustNotBeArchived, bind(api.CreateIssueOption{}), repo.CreateIssue) - m.Get("/pinned", repo.ListPinnedIssues) + m.Get("/pinned", reqRepoReader(unit.TypeIssues), repo.ListPinnedIssues) m.Group("/comments", func() { m.Get("", repo.ListRepoIssueComments) m.Group("/{id}", func() {