Disable README checkbox when user cannot push initial commit

What does this MR do and why?

Contributes to #415846 (closed)

Problem

When a Developer creates a project in a namespace where default branch protection is "Fully protected", the "Initialize repository with a README" checkbox appears functional but the README silently fails to be created. Commits::CreateService#validate_permissions! rejects the push, but Projects::CreateService#create_readme swallows the error, leaving the user with an empty repo.

Solution

Add DefaultBranchProtection#can_initial_push? that encodes the access-level-vs-protection decision in one place. Refactor ProtectedBranch to delegate to it, eliminating logic duplication. Add Namespace#can_push_initial_commit? that reuses the same method. Expose this as a canPushInitialCommit GraphQL field on NamespaceType and propagate it through the new project form to disable the README checkbox with a message when the user's role does not permit pushing to the default branch.

References

Screenshots or screen recordings

Before After
Screenshot_2026-03-20_at_16.51.36 Screenshot_2026-03-20_at_16.50.04

How to set up and validate locally

Part 1: Verify the problem (before the fix)

  1. Create a group (e.g. protected-group) with default branch protection set to Fully protected
  2. Add a user as Developer to that group
  3. As the Developer, navigate to New project > Create blank project
  4. Select protected-group as the namespace
  5. Observe the "Initialize repository with a README" checkbox is enabled and checked
  6. Create the project with the checkbox checked
  7. Observe the repository is empty — the README was silently not created

Part 2: Verify the fix (after the fix)

Test A: Restricted namespace disables the checkbox

  1. As the same Developer, navigate to New project > Create blank project
  2. Select protected-group (Fully protected) as the namespace
  3. Verify the "Initialize repository with a README" checkbox is disabled and unchecked
  4. Verify the help text reads: "Your role does not allow pushing to the default branch of new projects in this namespace."

Test B: Permitted namespace enables the checkbox

  1. Switch the namespace to one where the user is Maintainer or Owner
  2. Verify the checkbox becomes enabled again
  3. Verify the help text reverts to: "Allows you to immediately clone this project's repository. Skip this if you plan to push up an existing repository."

Test C: Switching namespaces toggles dynamically

  1. Alternate between a restricted namespace and a permitted namespace multiple times
  2. Verify the checkbox state and help text update correctly each time

Test D: Different protection levels

  1. Set a group's default branch protection to Protected against pushes (developers cannot push)
  2. As a Developer, verify the checkbox is disabled
  3. Set a group's default branch protection to Partially protected (developers can push)
  4. As a Developer, verify the checkbox is enabled
  5. Set a group's default branch protection to Protected after initial push (developers can do initial push)
  6. As a Developer, verify the checkbox is enabled

Test E: Admin override

  1. As an Admin, select any namespace regardless of protection level
  2. Verify the checkbox is always enabled

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Edited by Vasilii Iakliushin

Merge request reports

Loading
Loading