3 class Internal < Grape::API
4 namespace 'internal' do
6 # Check if ssh key has access to project code
10 # project - project path with namespace
11 # action - git action (git-upload-pack or git-receive-pack)
15 # Check for *.wiki repositories.
16 # Strip out the .wiki from the pathname before finding the
17 # project. This applies the correct project permissions to
18 # the wiki repository as well.
19 project_path = params[:project]
20 project_path.gsub!(/\.wiki/,'') if project_path =~ /\.wiki/
22 key = Key.find(params[:key_id])
23 project = Project.find_with_namespace(project_path)
24 git_cmd = params[:action]
25 return false unless project
28 if key.is_a? DeployKey
29 key.projects.include?(project) && git_cmd == 'git-upload-pack'
33 return false if user.blocked?
36 when 'git-upload-pack', 'git-upload-archive'
38 when 'git-receive-pack'
40 if project.protected_branch?(params[:ref])
41 :push_code_to_protected_branches
47 user.can?(action, project)
52 # Discover user by ssh key
55 key = Key.find(params[:key_id])
56 present key.user, with: Entities::UserSafe
61 api_version: API.version,
62 gitlab_version: Gitlab::VERSION,
63 gitlab_rev: Gitlab::REVISION,