Create projects via REST API v4 does not work anymore (403 Error)

Summary

We have two GitLab CE instances both on version 14.5.0 (one even on Version 14.5.1 since a few minutes). Before the update to 14.5 we could create projects via the REST API (Docs).

e.g:

curl --location --request POST 'https://gitlab.xxx.xx/api/v4/projects' \
--header 'Authorization: Bearer XXX_PersonalAccessTokens_XXX' \
--header 'Content-Type: application/json' \
--data-raw '{
    "name": "TestRepo"
}'

After the update to 14.5 we can't create projects via the API anymore.

We did not change the personal access token and personal access token has the scope api. Furthermore, the user can create projects via the UI.

Steps to reproduce

  1. (Not sure if this would happen also on a fresh instance)
  2. Create Personal Access Token with api scope
  3. Do following curl request
curl --location --request POST 'https://gitlab.xxx.de/api/v4/projects' \
--header 'Authorization: Bearer XXX_PersonalAccessTokens_XXX' \
--header 'Content-Type: application/json' \
--data-raw '{
    "name": "TestRepo"
}'

Example Project

Not applicable

What is the current bug behavior?

API responds with 403 even thought that the personal access token is valid and the user can create projects via the UI.

{
    "message": "403 Forbidden"
}

What is the expected correct behavior?

A project should be created in the user namespace.

Relevant logs and/or screenshots

{
    "message": "403 Forbidden"
}

Output of checks

Results of GitLab environment info

Expand for output related to GitLab environment info
System information
System:		
Current User:	git
Using RVM:	no
Ruby Version:	2.7.4p191
Gem Version:	3.1.4
Bundler Version:2.1.4
Rake Version:	13.0.6
Redis Version:	6.0.16
Git Version:	2.33.1.
Sidekiq Version:6.2.2
Go Version:	unknown

GitLab information
Version:	14.5.1
Revision:	9d9ee598bc5
Directory:	/opt/gitlab/embedded/service/gitlab-rails
DB Adapter:	PostgreSQL
DB Version:	12.7
URL:		https://gitlab.xxx.xx
HTTP Clone URL:	https://gitlab.xxx.xx/some-group/some-project.git
SSH Clone URL:	git@gitlab.xxx.xx:some-group/some-project.git
Using LDAP:	yes
Using Omniauth:	yes
Omniauth Providers: 

GitLab Shell
Version:	13.22.1
Repository storage paths:
- default: 	/var/opt/gitlab/git-data/repositories
GitLab Shell path:		/opt/gitlab/embedded/service/gitlab-shell
Git:		/opt/gitlab/embedded/bin/git

Results of GitLab application Check

Expand for output related to the GitLab application check

Checking GitLab subtasks ...

Checking GitLab Shell ...

GitLab Shell: ... GitLab Shell version >= 13.22.1 ? ... OK (13.22.1) Running /opt/gitlab/embedded/service/gitlab-shell/bin/check Internal API available: OK Redis available via internal API: OK gitlab-shell self-check successful

Checking GitLab Shell ... Finished

Checking Gitaly ...

Gitaly: ... default ... OK

Checking Gitaly ... Finished

Checking Sidekiq ...

Sidekiq: ... Running? ... yes Number of Sidekiq processes (cluster/worker) ... 1/1

Checking Sidekiq ... Finished

Checking Incoming Email ...

Incoming Email: ... Reply by email is disabled in config/gitlab.yml

Checking Incoming Email ... Finished

Checking LDAP ...

LDAP: ... Server: ldapmain LDAP authentication... Success LDAP users with access to your GitLab server (only showing the first 100 results) User output sanitized. Found 100 users of 100 limit.

Checking LDAP ... Finished

Checking GitLab App ...

Git configured correctly? ... yes Database config exists? ... yes All migrations up? ... yes Database contains orphaned GroupMembers? ... no GitLab config exists? ... yes GitLab config up to date? ... yes Log directory writable? ... yes Tmp directory writable? ... yes Uploads directory exists? ... yes Uploads directory has correct permissions? ... yes Uploads directory tmp has correct permissions? ... yes Systemd unit files or init script exist? ... skipped (omnibus-gitlab has neither init script nor systemd units) Systemd unit files or init script up-to-date? ... skipped (omnibus-gitlab has neither init script nor systemd units) Projects have namespace: ... 3/1 ... yes 41/2 ... yes 47/3 ... yes 47/4 ... yes 59/5 ... yes 62/6 ... yes 38/7 ... yes 64/8 ... yes 68/9 ... yes 68/10 ... yes 39/11 ... yes 68/13 ... yes 42/14 ... yes 71/17 ... yes 68/18 ... yes 77/20 ... yes 78/21 ... yes 79/23 ... yes 47/24 ... yes 79/25 ... yes 89/26 ... yes 89/27 ... yes 206/28 ... yes 55/29 ... yes 39/30 ... yes 106/33 ... yes 111/34 ... yes 114/35 ... yes 55/38 ... yes 206/39 ... yes 118/40 ... yes 120/41 ... yes 55/42 ... yes 55/44 ... yes 50/45 ... yes 65/46 ... yes 55/47 ... yes 89/48 ... yes 135/49 ... yes 135/50 ... yes 50/51 ... yes 47/52 ... yes 55/53 ... yes 135/54 ... yes 106/55 ... yes 78/56 ... yes 68/57 ... yes 130/59 ... yes 100/60 ... yes 50/61 ... yes 120/62 ... yes 157/64 ... yes 118/65 ... yes 68/66 ... yes 50/70 ... yes 163/71 ... yes 163/72 ... yes 55/73 ... yes 55/74 ... yes 169/75 ... yes 111/76 ... yes 170/77 ... yes 55/79 ... yes 79/82 ... yes 174/83 ... yes 55/84 ... yes 55/85 ... yes 90/86 ... yes 42/87 ... yes 55/88 ... yes 44/89 ... yes 79/90 ... yes 79/91 ... yes 79/92 ... yes 79/93 ... yes 90/95 ... yes 206/96 ... yes 47/97 ... yes 203/98 ... yes 39/99 ... yes 206/100 ... yes 206/101 ... yes 206/102 ... yes 206/103 ... yes 47/104 ... yes 206/105 ... yes 206/106 ... yes 206/107 ... yes 79/108 ... yes 79/109 ... yes 79/110 ... yes 79/111 ... yes 206/112 ... yes 90/113 ... yes 206/115 ... yes 206/116 ... yes 118/117 ... yes 206/118 ... yes 42/119 ... yes 79/120 ... yes 201/121 ... yes 106/123 ... yes 290/124 ... yes 90/125 ... yes 240/126 ... yes 89/127 ... yes 42/128 ... yes 206/130 ... yes 90/131 ... yes 206/133 ... yes 244/135 ... yes 245/136 ... yes 248/137 ... yes 206/138 ... yes 55/139 ... yes 255/140 ... yes 255/141 ... yes 206/142 ... yes 206/145 ... yes 118/146 ... yes 90/147 ... yes 163/148 ... yes 163/149 ... yes 64/150 ... yes 264/151 ... yes 78/152 ... yes 255/154 ... yes 255/155 ... yes 163/156 ... yes 44/157 ... yes 206/158 ... yes 206/159 ... yes 111/160 ... yes 268/161 ... yes 270/162 ... yes 271/163 ... yes 206/164 ... yes 55/167 ... yes 55/168 ... yes 279/169 ... yes 279/170 ... yes 279/171 ... yes 279/172 ... yes 79/173 ... yes 79/174 ... yes 79/175 ... yes 79/176 ... yes 79/177 ... yes 78/178 ... yes 78/179 ... yes 78/180 ... yes 286/181 ... yes 286/182 ... yes 78/183 ... yes 290/184 ... yes 2/185 ... yes 55/186 ... yes 206/187 ... yes 292/188 ... yes 292/189 ... yes 111/190 ... yes 111/191 ... yes 293/192 ... yes 111/194 ... yes 42/195 ... yes 111/196 ... yes 78/199 ... yes 309/203 ... yes 111/204 ... yes 206/206 ... yes 206/207 ... yes 206/208 ... yes 311/209 ... yes 311/210 ... yes 206/211 ... yes 78/212 ... yes 111/213 ... yes 78/214 ... yes 120/215 ... yes 39/216 ... yes 206/218 ... yes 118/219 ... yes 324/220 ... yes 324/221 ... yes 68/222 ... yes 78/223 ... yes 170/224 ... yes 329/225 ... yes 55/226 ... yes 330/227 ... yes 330/228 ... yes 206/229 ... yes 332/230 ... yes 39/231 ... yes 42/232 ... yes 248/233 ... yes 335/234 ... yes 336/235 ... yes 2/236 ... yes 268/237 ... yes 340/238 ... yes 90/239 ... yes 345/240 ... yes 348/241 ... yes 348/242 ... yes 348/243 ... yes 348/244 ... yes 348/245 ... yes 348/246 ... yes 348/247 ... yes 348/248 ... yes 348/249 ... yes 348/250 ... yes 349/251 ... yes 350/252 ... yes 308/253 ... yes 38/254 ... yes 68/255 ... yes 64/256 ... yes 248/257 ... yes 248/258 ... yes 78/259 ... yes 248/260 ... yes 78/261 ... yes 354/262 ... yes 47/263 ... yes 356/264 ... yes 357/265 ... yes 360/266 ... yes 44/267 ... yes 39/268 ... yes 39/269 ... yes 364/270 ... yes 367/271 ... yes 367/272 ... yes 368/273 ... yes 348/274 ... yes 348/275 ... yes 348/276 ... yes 39/277 ... yes 39/278 ... yes 377/285 ... yes 348/312 ... yes 423/331 ... yes 433/339 ... yes 206/340 ... yes 434/341 ... yes 438/342 ... yes 55/343 ... yes 440/344 ... yes 55/345 ... yes 279/346 ... yes 441/347 ... yes 55/351 ... yes 39/352 ... yes 330/356 ... yes 55/357 ... yes 55/358 ... yes 330/359 ... yes 449/361 ... yes 449/362 ... yes 39/363 ... yes 452/364 ... yes 255/365 ... yes 255/369 ... yes 453/370 ... yes 455/371 ... yes 456/372 ... yes 349/373 ... yes 55/374 ... yes 459/375 ... yes 460/376 ... yes 463/378 ... yes 465/379 ... yes 466/380 ... yes 467/381 ... yes 55/382 ... yes 470/383 ... yes 470/384 ... yes 470/385 ... yes 345/386 ... yes 472/387 ... yes 472/388 ... yes 473/389 ... yes 78/390 ... yes 477/393 ... yes 478/394 ... yes 479/395 ... yes 480/396 ... yes 482/398 ... yes 483/401 ... yes 483/402 ... yes 89/403 ... yes 2/405 ... yes 485/406 ... yes 486/407 ... yes 487/408 ... yes 488/409 ... yes 489/410 ... yes 490/411 ... yes 491/412 ... yes 492/413 ... yes 483/414 ... yes 494/416 ... yes 494/417 ... yes Redis version >= 5.0.0? ... yes Ruby version >= 2.7.2 ? ... yes (2.7.4) Git version >= 2.33.0 ? ... yes (2.33.1) Git user has default SSH configuration? ... yes Active users: ... 250 Is authorized keys file accessible? ... yes GitLab configured to store new projects in hashed storage? ... yes All projects are in hashed storage? ... yes

Checking GitLab App ... Finished

Checking GitLab subtasks ... Finished

Possible fixes

Workaround

See note

Edited by Cleveland Bledsoe Jr