From b359d5d57f4b836c04e9e2ef7e1fcb3775bd5305 Mon Sep 17 00:00:00 2001 From: Stan Hu Date: Tue, 24 May 2016 17:55:57 -0700 Subject: Fix groups API to list only user's accessible projects Closes #17496 --- lib/api/groups.rb | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) (limited to 'lib/api/groups.rb') diff --git a/lib/api/groups.rb b/lib/api/groups.rb index 91e420832f3..9d8b8d737a9 100644 --- a/lib/api/groups.rb +++ b/lib/api/groups.rb @@ -95,8 +95,7 @@ module API # GET /groups/:id/projects get ":id/projects" do group = find_group(params[:id]) - projects = group.projects - projects = filter_projects(projects) + projects = GroupProjectsFinder.new(group).execute(current_user) projects = paginate projects present projects, with: Entities::Project end -- cgit v1.2.1