From 5e1a41a1ea3f66fa4a280cdf1792d75eb3811e5b Mon Sep 17 00:00:00 2001 From: Lukas Wanko Date: Mon, 1 Sep 2025 21:41:57 +0200 Subject: [PATCH] Add authorization to the group's members API endpoint --- lib/api/members.rb | 1 + 1 file changed, 1 insertion(+) diff --git a/lib/api/members.rb b/lib/api/members.rb index 1f3eeb73d62617..b54991de172309 100644 --- a/lib/api/members.rb +++ b/lib/api/members.rb @@ -121,6 +121,7 @@ class Members < ::API::Base post ":id/members", feature_category: feature_category do source = find_source(source_type, params[:id]) + authorize_admin_source_member!(source_type, source) create_service_params = params.merge(source: source) -- GitLab