User cannot be granted access to project if there is a pending "join group" request
Summary
Granting Permissions to a user fails (but the site says it succeeds) if the user already has requested access to the group/namespace.
Steps to reproduce
- User requests access to the group that the project is hosted under
- (The request is ignored)
- An administrator grants developer access to the user just for that project
- The system returns with a success
- User is still unable to see the project. User is not actually listed as a member of the group either.
What is the current bug behavior?
System says that the user has access, but he does not
What is the expected correct behavior?
User should actually have access
Relevant logs and/or screenshots
Results of GitLab environment info
System information
System: Debian 8.11
Proxy: no
Current User: git
Using RVM: no
Ruby Version: 2.5.3p105
Gem Version: 2.7.6
Bundler Version:1.16.6
Rake Version: 12.3.2
Redis Version: 3.2.12
Git Version: 2.18.1
Sidekiq Version:5.2.3
Go Version: unknown
GitLab information
Version: 11.7.5-ee
Revision: ed04633
Directory: /opt/gitlab/embedded/service/gitlab-rails
DB Adapter: postgresql
DB Version: 9.6.8
URL: https://git.domain.tld
HTTP Clone URL: https://git.domain.tld/some-group/some-project.git
SSH Clone URL: git@git.domain.tld:some-group/some-project.git
Elasticsearch: no
Geo: no
Using LDAP: yes
Using Omniauth: yes
Omniauth Providers:
GitLab Shell
Version: 8.4.4
Repository storage paths:
- default: /var/opt/gitlab/git-data/repositories
Hooks: /opt/gitlab/embedded/service/gitlab-shell/hooks
Git: /opt/gitlab/embedded/bin/git```
#### Results of GitLab application Check
```# gitlab-rake gitlab:check SANITIZE=true
Checking GitLab subtasks ...
Checking GitLab Shell ...
GitLab Shell: ... GitLab Shell version >= 8.4.4 ? ... OK (8.4.4)
Running /opt/gitlab/embedded/service/gitlab-shell/bin/check
Check GitLab API access: OK
Redis available via internal API: OK
Access to /var/opt/gitlab/.ssh/authorized_keys: OK
gitlab-shell self-check successful
Checking GitLab Shell ... Finished
Checking Gitaly ...
Gitaly: ... default ... OK
Checking Gitaly ... Finished
Checking Sidekiq ...
Sidekiq: ... Running? ... yes
Number of Sidekiq processes ... 1
Checking Sidekiq ... Finished
Checking Incoming Email ...
Incoming Email: ... Reply by email is disabled in config/gitlab.yml
Checking Incoming Email ... Finished
Checking LDAP ...
LDAP: ... Server: ldapmain
LDAP authentication... Success
LDAP users with access to your GitLab server (only showing the first 100 results)
<LDAP users>
Checking LDAP ... Finished
Checking GitLab App ...
Git configured correctly? ... yes
Database config exists? ... yes
All migrations up? ... yes
Database contains orphaned GroupMembers? ... no
GitLab config exists? ... yes
GitLab config up to date? ... yes
Log directory writable? ... yes
Tmp directory writable? ... yes
Uploads directory exists? ... yes
Uploads directory has correct permissions? ... yes
Uploads directory tmp has correct permissions? ... no
Try fixing it:
sudo chown -R git /var/opt/gitlab/gitlab-rails/uploads
sudo find /var/opt/gitlab/gitlab-rails/uploads -type f -exec chmod 0644 {} \;
sudo find /var/opt/gitlab/gitlab-rails/uploads -type d -not -path /var/opt/gitlab/gitlab-rails/uploads -exec chmod 0700 {} \;
For more information see:
doc/install/installation.md in section "GitLab"
Please fix the error above and rerun the checks.
Init script exists? ... skipped (omnibus-gitlab has no init script)
Init script up-to-date? ... skipped (omnibus-gitlab has no init script)
Projects have namespace: ...
6/19 ... yes
6/21 ... yes
6/22 ... yes
6/23 ... yes
6/24 ... yes
6/25 ... yes
6/26 ... yes
6/48 ... yes
6/70 ... yes
6/71 ... yes
12/75 ... yes
12/76 ... yes
12/77 ... yes
12/78 ... yes
12/79 ... yes
12/80 ... yes
12/81 ... yes
12/82 ... yes
12/83 ... yes
12/84 ... yes
12/85 ... yes
12/86 ... yes
12/87 ... yes
12/88 ... yes
12/89 ... yes
12/90 ... yes
6/91 ... yes
12/92 ... yes
12/93 ... yes
12/94 ... yes
12/95 ... yes
5/96 ... yes
6/97 ... yes
6/98 ... yes
4/99 ... yes
6/100 ... yes
6/101 ... yes
6/102 ... yes
6/103 ... yes
6/104 ... yes
6/105 ... yes
6/106 ... yes
6/107 ... yes
4/108 ... yes
4/109 ... yes
6/111 ... yes
6/112 ... yes
4/114 ... yes
6/115 ... yes
21/116 ... yes
6/117 ... yes
6/118 ... yes
6/119 ... yes
5/120 ... yes
6/121 ... yes
6/122 ... yes
5/124 ... yes
5/125 ... yes
6/126 ... yes
23/127 ... yes
6/128 ... yes
6/130 ... yes
12/131 ... yes
6/132 ... yes
6/133 ... yes
6/136 ... yes
23/137 ... yes
22/138 ... yes
6/140 ... yes
6/141 ... yes
23/142 ... yes
6/143 ... yes
5/144 ... yes
6/145 ... yes
5/147 ... yes
23/148 ... yes
6/149 ... yes
6/150 ... yes
6/151 ... yes
5/152 ... yes
6/154 ... yes
6/155 ... yes
6/156 ... yes
6/157 ... yes
6/158 ... yes
6/159 ... yes
6/160 ... yes
17/161 ... yes
6/162 ... yes
5/163 ... yes
18/164 ... yes
6/165 ... yes
6/166 ... yes
12/167 ... yes
23/168 ... yes
6/170 ... yes
6/171 ... yes
6/172 ... yes
6/173 ... yes
6/174 ... yes
5/175 ... yes
6/176 ... yes
6/177 ... yes
6/178 ... yes
6/179 ... yes
6/180 ... yes
23/181 ... yes
23/182 ... yes
23/183 ... yes
23/184 ... yes
12/185 ... yes
30/187 ... yes
5/188 ... yes
17/189 ... yes
6/190 ... yes
6/192 ... yes
6/193 ... yes
23/194 ... yes
6/195 ... yes
6/196 ... yes
23/197 ... yes
6/198 ... yes
6/199 ... yes
6/200 ... yes
28/201 ... yes
6/202 ... yes
6/203 ... yes
6/204 ... yes
23/205 ... yes
6/206 ... yes
5/207 ... yes
6/208 ... yes
6/210 ... yes
6/211 ... yes
6/212 ... yes
30/213 ... yes
6/214 ... yes
5/215 ... yes
30/216 ... yes
5/217 ... yes
18/218 ... yes
6/219 ... yes
6/220 ... yes
28/221 ... yes
6/222 ... yes
34/223 ... yes
6/224 ... yes
28/225 ... yes
4/226 ... yes
6/227 ... yes
33/228 ... yes
4/229 ... yes
6/230 ... yes
28/231 ... yes
6/232 ... yes
Redis version >= 2.8.0? ... yes
Ruby version >= 2.3.5 ? ... yes (2.5.3)
Git version >= 2.18.0 ? ... yes (2.18.1)
Git user has default SSH configuration? ... yes
Active users: ... 33
Elasticsearch version 5.6 - 6.x? ... skipped (elasticsearch is disabled)
Checking GitLab App ... Finished
Checking GitLab subtasks ... Finished```
### Possible fixes
No idea about lines of code, but declining/removing the pending user request to join the group fixes the issue.