Move granular token authz from field extension to type-level check

What does this MR do and why?

  • Replaces field extension to authorize granular tokens in GraphQL with object authorization (similar to the current auth check in GraphQL). This MR only focuses on queries. A follow-up MR will focus on mutations.

How to set up and validate locally

  1. Enable feature flag granular_personal_access_tokens.
  2. Create a fine-grained token from /-/user_settings/personal_access_tokens with Group and project -> read_group, read_member + User -> read_user permissions.
  3. Make the following GraphQL request with the token:
curl --request POST \
    --header "Authorization: Bearer <TOKEN>" \
    --header "Content-Type: application/json" \
    --data '{"query":"query { group(fullPath: <GROUP_PATH>) { name groupMembers { nodes { id user { username } } } } }"}' \
    http://127.0.0.1:3000/api/graphql
  1. If you'd like to test list redaction, you can create another token with read_group, read_member permissions and run the same query. You'll get user: null since the token doesn't have read_user permission.

  2. In order to test that gPAT directives are working on BaseField, create a gPAT token with read_work_item permission. Then run the following GraphQL request. createNoteEmail should return null

curl --request POST \
  --header "Authorization: Bearer <TOKEN>" \
  --header "Content-Type: application/json" \
  --data '{"query":"query { workItem(id: \"gid://gitlab/WorkItem/1\") { id createNoteEmail } } "}' \
  http://127.0.0.1:3000/api/graphql

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Related to #601728 (closed)

Edited by Hinam Mehra

Merge request reports

Loading
Loading