Anonymous committed 8f14ede

fix -- don't trust the search backend to only return repos that exist and are authorized to the current request

Comments (0)

Files changed (1)


         for filename, reponame in self.search_backend.find_words(query):
             repo = self.env.get_repository(reponame=reponame, authname=req.authname)
+            if repo is None:
+                # @@TODO: log it? ask the search backend to remove the reference?
+                continue
             node = repo.get_node(filename)
             if node.kind == Node.DIRECTORY: