fix: represent a deleted assignee team as a Ghost team - #38413
Merged
bircni merged 3 commits intoJul 12, 2026
Merged
Conversation
LoadAssigneeUserAndTeam already falls back to a Ghost user when the assignee user has been deleted, but silently left AssigneeTeam nil when the assignee team had been deleted (#35472), causing a nil pointer panic in code paths that assume AssigneeTeam is non-nil once LoadAssigneeUserAndTeam has run. Added organization.NewGhostTeam, mirroring user_model.NewGhostUser, and used it in the same fallback branch as the user case. Fixes #35472
wxiaoguang
approved these changes
Jul 12, 2026
bircni
approved these changes
Jul 12, 2026
wxiaoguang
added a commit
that referenced
this pull request
Jul 12, 2026
zjjhot
added a commit
to zjjhot/gitea
that referenced
this pull request
Jul 13, 2026
* 'main' of https://github.com/go-gitea/gitea: fix: various security fixes (go-gitea#38406) fix(util): reject invalid characters between time-estimate units (go-gitea#38416) feat(actions): implement adaptive auto-refresh for workflow runs list (go-gitea#38329) fix(turnstile): route CAPTCHA verification through the configured proxy (go-gitea#38412) fix: represent a deleted assignee team as a Ghost team (go-gitea#38413) [skip ci] Updated translations via Crowdin fix: refresh pull request merge box when the commit status is pending (go-gitea#38410) chore: remove Yarden Shoham from maintainers (go-gitea#38407) fix: actions task state concurrent update (go-gitea#38405) fix(actions): keep workflow run trailing on one row with long branch names (go-gitea#38382) fix(pull): re-evaluate review official flag on target branch change (go-gitea#38319) fix(web): use locale-aware date formatting for contribution calendar tooltips (go-gitea#38398) fix(security): harden access checks and migration validation (go-gitea#38324) fix: enforce public-only token scope and harden push options / locale parsing (go-gitea#38323) fix: co-author detection (go-gitea#38392) fix(api): stop leaking private repo metadata after access revocation (go-gitea#38321) fix(lfs): require proof of possession for cross-repo objects (go-gitea#38322) fix: incorrect co-author detection on commit page (go-gitea#38386)
zjjhot
added a commit
to zjjhot/gitea
that referenced
this pull request
Jul 13, 2026
* main: fix: various security fixes (go-gitea#38406) fix(util): reject invalid characters between time-estimate units (go-gitea#38416) feat(actions): implement adaptive auto-refresh for workflow runs list (go-gitea#38329) fix(turnstile): route CAPTCHA verification through the configured proxy (go-gitea#38412) fix: represent a deleted assignee team as a Ghost team (go-gitea#38413) [skip ci] Updated translations via Crowdin fix: refresh pull request merge box when the commit status is pending (go-gitea#38410) chore: remove Yarden Shoham from maintainers (go-gitea#38407) fix: actions task state concurrent update (go-gitea#38405) fix(actions): keep workflow run trailing on one row with long branch names (go-gitea#38382) fix(pull): re-evaluate review official flag on target branch change (go-gitea#38319) fix(web): use locale-aware date formatting for contribution calendar tooltips (go-gitea#38398) fix(security): harden access checks and migration validation (go-gitea#38324) fix: enforce public-only token scope and harden push options / locale parsing (go-gitea#38323) fix: co-author detection (go-gitea#38392) fix(api): stop leaking private repo metadata after access revocation (go-gitea#38321) fix(lfs): require proof of possession for cross-repo objects (go-gitea#38322) fix: incorrect co-author detection on commit page (go-gitea#38386)
zeekay
pushed a commit
to hanzoai/git
that referenced
this pull request
Jul 26, 2026
Fixes go-gitea#35472. `Comment.LoadAssigneeUserAndTeam` already has a Ghost user fallback for a deleted assignee user, but the parallel branch for a deleted assignee team just swallowed the not-found error and left `AssigneeTeam` as `nil`. This is inconsistent (the reporter's example shows `assignee` becoming a Ghost user while `assignee_team` becomes `null`), and it's also a latent nil pointer bug: other code that assumes `AssigneeTeam` is set once this function returns without error will panic. Added `organization.NewGhostTeam()` / `Team.IsGhost()`, mirroring the existing `user_model.NewGhostUser()` / `User.IsGhost()` pattern, and used it in the same fallback branch. Co-authored-by: wxiaoguang <wxiaoguang@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #35472.
Comment.LoadAssigneeUserAndTeamalready has a Ghost user fallbackfor a deleted assignee user, but the parallel branch for a deleted
assignee team just swallowed the not-found error and left
AssigneeTeamasnil. This is inconsistent (the reporter's exampleshows
assigneebecoming a Ghost user whileassignee_teambecomesnull), and it's also a latent nil pointer bug: other code thatassumes
AssigneeTeamis set once this function returns withouterror will panic.
Added
organization.NewGhostTeam()/Team.IsGhost(), mirroring theexisting
user_model.NewGhostUser()/User.IsGhost()pattern, andused it in the same fallback branch.