Loading
Account for the minimal_access role during 2FA enforcement
- Related to #534094 (closed) & BBM
What does this MR do and why?
What?
- All user roles in a group, from
ownertoguest, respect top-group-level 2FA settings.Minimum Accessrole is the exception. - This MR fixes it by accounting for the minimum_access role during top-group-level 2FA enforcement.
Why?
-
Users with the
Minimal Accessrole in a top-level group with 2FA enforcement enabled are not required to set up 2FA for their account when they should. The least-trusted user in a group must follow the strictest 2FA setting. -
There are ~4450 users with a minimal_access role in gitlab.com alone that do not have 2FA enforced on them, in groups with 2FA enabled.
Screenshots or screen recordings
| After |
|---|
How to set up and validate locally
The
invite membersbutton will only show on .com. So you can switch to SAAS mode to make verification easier for yourself. You can skip to 3 if you do switch.
- Checkout the branch
- Impersonate or log in as a random test user and navigate to a top-level-group.
- Click on the vertical ellipsis to request access.
- Log-in as your GDK admin, go-to your top-level-group and enforce 2FA
- Click on the
Request Accesstab, switch the user role toMinimum Accessrole, and accept the request. - Log back in as your test user & verify that you are redirected to your 2FA page.
MR acceptance checklist
Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.
Edited by Hakeem Abdul-Razak