Evaluate permissions required to access import_url project information
Everyone can contribute. Help move this issue forward while earning points, leveling up and collecting rewards.
!82498 (merged) introduced import_url
field for projects API.
This is sanitized version of URL which does not expose any credentials
Right now this field is available only if user created that import and still has rights to admin project. So, for example in case of user losing access to the project, no one will be able to see that field
We need to evaluate if such strict permission is ok in terms of business logic or should be relaxed
Edited by 🤖 GitLab Bot 🤖