fix(security): 403 Access Denied for signed-in users on private repos #420

Merged
jmiller merged 1 commits from dev into main 2026-06-02 14:27:25 +00:00
Owner

Signed-in users see 403 instead of 404. Anonymous still gets 404.

Signed-in users see 403 instead of 404. Anonymous still gets 404.
jmiller added 1 commit 2026-06-02 14:27:08 +00:00
fix(security): show 403 Access Denied instead of 404 for signed-in users on private repos
Branch Policy Check / Verify merge target (pull_request) Successful in 1s
Universal: PR Check / Branch Policy (pull_request) Successful in 1s
Universal: PR Check / Validate PR (pull_request) Failing after 5s
Branch Cleanup / Delete merged branch (pull_request) Has been skipped
PR RC Release / Build RC Release (pull_request) Successful in 19s
Universal: PR Check / Build RC Package (pull_request) Has been cancelled
0add8bda72
Signed-in users who lack permission to a private repo now see a
403 "You do not have permission" instead of a misleading 404.
Anonymous users still get 404 to prevent repo enumeration.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
jmiller merged commit 2db1f4eaf6 into main 2026-06-02 14:27:25 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: MokoConsulting/MokoGitea#420