Developer sees a silent 404 when clicking "Create empty repository" when using a custom template which has no repo

Summary

When Developers are granted permission to create projects, and a custom instance-level project template has no repository, the project creation flow presents the Developer with options to import a repository or create a blank one. Both paths fail with a 404 because Developers do not have push permissions by default. No explanation is shown — not a permission denied message, just a 404.

Steps to reproduce

  1. Grant Developers the ability to create projects (Admin Area → Settings → General → Visibility and access controls).
  2. Create a custom instance-level project template that has no repository (no commits pushed).
  3. As a Developer, create a new project from that template.
  4. The project is created with no repository. The project creation flow presents options to import a repository or create a blank one.
  5. Click "Create empty repository" (or attempt to import).
  6. Observe: 404 response. No error message, no indication that the action requires a higher role.

Current behavior

Projects::RepositoriesController#create is gated by authorize_admin_project!, which requires the admin_project permission (Maintainer+). When a Developer hits this endpoint, Rails returns a 404 with no explanation. This is especially confusing because the Developer was able to create the project in the first place.

Expected behavior

The user should receive a clear permission error (e.g. 403 Forbidden or an in-page message) explaining that initialising a repository requires Maintainer or higher access.

Root cause

Projects::RepositoriesController#create calls authorize_admin_project! which resolves to a 404 for insufficient permissions, rather than surfacing a meaningful error to the user.

Partial fix context

#415846 (closed) was closed in GitLab 18.11 via !228305 (merged), which disables the "Initialize repository with a README" checkbox at project creation time when the user's role doesn't permit it. However, the post-creation "Create empty repository" button on an already-created project was not addressed and still 404s for Developers.

Environment

  • Reproducible on GitLab.com (SaaS) and self-managed instances

Possible fix

  • Change the authorize_admin_project! gate in Projects::RepositoriesController#create to return a 403 with a user-facing message, or
  • Conditionally hide/disable the "Create empty repository" button for users who lack the required permission (similar to how !228305 (merged) disabled the README checkbox)