Disable Enable button for private AI Catalog items outside managing project

What does this MR do and why?

Fixes the first of the two UX bugs described in #596801 (closed): private AI Catalog items show an active Enable button even when the user is viewing them from outside their managing project.

A private catalog item can only ever be enabled in the project it was created in. Today the Enable button is clickable from anywhere, and submitting it silently enables the item in the item's owning project rather than the context the user is in — a confusing cross-project side effect with no UI signal.

After this MR, the Enable button is disabled in those cases with a tooltip naming the managing project, matching the scope copy already shown in the consumer modal body ("This item is private and can only be enabled in the project it was created in…").

The second part of #596801 (closed) (filtering already-enabled projects from the Enable modal dropdown) ships separately in !233159 (merged).

How it works

  • New isOutsideOwningProject computed on AiCatalogItemActions:
    • Returns false for public items (no scope restriction).
    • For private items, compares the current projectId inject against item.project.id (converted with getIdFromGraphQLId).
    • Any namespace that isn't the owning project — another project, a group, or the Explore page — is treated as outside.
  • canEnable and enableButtonDisabled are extended with the new guard. canEnable flows into the consumer modal's primary action, so the modal's submit is also disabled in this state.
  • enableButtonTooltip explains the constraint with the managing project's nameWithNamespace: "This private agent can only be enabled in its managing project: Group 1 / Project 1."

No backend, GraphQL, or policy changes. No feature flag — the rule is a UI hardening on top of an already-correct model; the existing backend authorization remains the source of truth.

Steps to reproduce

  1. In your GDK, create a private agent in project group-a/project-1 (AI Catalog → New agent, set visibility to Private).
  2. Navigate to the same catalog from a different project (e.g. group-b/project-2) where you are at least a Maintainer, or from the global Explore catalog.
  3. Open the private agent's detail page.
  4. Before this MR: the Enable button is active. Clicking it opens the modal; submitting enables the agent in group-a/project-1 (the owning project), not where you are.
  5. After this MR: the Enable button is disabled and greyed out. Hovering shows: "This private agent can only be enabled in its managing project: Group A / Project 1."

Screenshots or screen recordings

Private Agent on Explore Level

before after
Screenshot_2026-04-24_at_09.26.53 Screenshot_2026-04-24_at_09.27.19

Private Agent on managing Group Level (no changes)

before after
Screenshot_2026-04-24_at_09.29.27 Screenshot_2026-04-24_at_09.29.27
Walkthrough before
Walkthrough after

Related to #596801 (closed).

Edited by Jannik Lehmann

Merge request reports

Loading
Loading