Account for the minimal_access role during 2FA enforcement

What does this MR do and why?

backend

What?

  • All user roles in a group, from owner to guest, respect top-group-level 2FA settings. Minimum Access role is the exception.
  • This MR fixes it by accounting for the minimum_access role during top-group-level 2FA enforcement.

Why?

  • Users with the Minimal Access role in a top-level group with 2FA enforcement enabled are not required to set up 2FA for their account when they should. The least-trusted user in a group must follow the strictest 2FA setting.

  • There are ~4450 users with a minimal_access role in gitlab.com alone that do not have 2FA enforced on them, in groups with 2FA enabled.

Screenshots or screen recordings

After

How to set up and validate locally

The invite members button will only show on .com. So you can switch to SAAS mode to make verification easier for yourself. You can skip to 3 if you do switch.

  1. Checkout the branch
  2. Impersonate or log in as a random test user and navigate to a top-level-group.
  3. Click on the vertical ellipsis to request access.
  4. Log-in as your GDK admin, go-to your top-level-group and enforce 2FA
  5. Click on the Request Access tab, switch the user role to Minimum Access role, and accept the request.
  6. Log back in as your test user & verify that you are redirected to your 2FA page.

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Edited by Hakeem Abdul-Razak

Merge request reports

Loading
Loading