Loading
Move granular token authz from field extension to type-level check
What does this MR do and why?
- Replaces field extension to authorize granular tokens in GraphQL with object authorization (similar to the current auth check in GraphQL). This MR only focuses on queries. A follow-up MR will focus on mutations.
How to set up and validate locally
- Enable feature flag
granular_personal_access_tokens. - Create a fine-grained token from
/-/user_settings/personal_access_tokenswithGroup and project -> read_group, read_member + User -> read_userpermissions. - Make the following GraphQL request with the token:
curl --request POST \
--header "Authorization: Bearer <TOKEN>" \
--header "Content-Type: application/json" \
--data '{"query":"query { group(fullPath: <GROUP_PATH>) { name groupMembers { nodes { id user { username } } } } }"}' \
http://127.0.0.1:3000/api/graphql-
If you'd like to test list redaction, you can create another token with
read_group, read_memberpermissions and run the same query. You'll getuser: nullsince the token doesn't haveread_userpermission. -
In order to test that gPAT directives are working on
BaseField, create a gPAT token withread_work_itempermission. Then run the following GraphQL request.createNoteEmailshould returnnull
curl --request POST \
--header "Authorization: Bearer <TOKEN>" \
--header "Content-Type: application/json" \
--data '{"query":"query { workItem(id: \"gid://gitlab/WorkItem/1\") { id createNoteEmail } } "}' \
http://127.0.0.1:3000/api/graphqlMR acceptance checklist
Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.
Related to #601728 (closed)
Edited by Hinam Mehra