Security policy bot cannot access CI/CD components from internal projects referenced in pipeline snippets

Summary

When a pipeline execution policy references a pipeline snippet that in turn uses CI/CD components from other internal projects, the security policy bot cannot access those components. The bot user is treated as an external user and cannot access internal projects, even when the bot is explicitly added to those projects.

This is a bug because the bot should be able to access internal projects when it has been explicitly granted access via the "Security policy bot access" setting.

Steps to reproduce

  1. Create a pipeline execution policy that includes a CI config snippet from a project
  2. In that snippet, reference a CI/CD component from another internal project
  3. Enable the security policy bot access setting on the internal component project
  4. Trigger a pipeline on a project governed by the policy

Expected: The security policy bot can access the CI/CD component from the internal project, especially when explicitly added to the project.

Actual: The bot cannot access the component because it is an external user and internal project visibility blocks external users.

Investigation notes

The root cause is likely that the security policy bot is classified as an external user. While #425361 (closed) introduced a security fix that prevents external users from accessing internal projects, the bot access setting should override this restriction for explicitly allowed projects.

The access check needs investigation to determine if:

  • The bot access setting properly propagates to transitive project references (components referenced within snippets)
  • The external user classification can be bypassed for the bot when the access setting is enabled
  • There is a way to grant the bot access to component projects without re-introducing the vulnerability from #425361 (closed)

Reported by

@erik.petzold1 in #599022 (comment)