Add BaseMutation#authorized?

What does this MR do and why?

  • Follows from !238311 (merged)
  • Implements authorized? method in BaseMutation to check if the granular token is authorized
  • Adds a boundary value to the gPAT directives in mutations as well, just like queries, so we don't have to run this chain when resolving the boundary.

How to set up and validate locally

  1. Enable feature flag granular_personal_access_tokens.
  2. Create a fine-grained token from /-/user_settings/personal_access_tokens with Group and project -> update_group permission.
  3. Run the following mutation
curl --request POST \
  --header "Content-Type: application/json" \
  --header "Authorization: Bearer <TOKEN>" \
  --url "http://127.0.0.1:3000/api/graphql" \
  --data @- <<'EOF'
{
  "query": "mutation GroupUpdate($input: GroupUpdateInput!) { groupUpdate(input: $input) { errors } }",
  "variables": {
    "input": {
      "fullPath": <GROUP_PATH>,
      "name": "Group new name"
    }
  }
}
EOF

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Related to #601728 (closed)

Edited by Hinam Mehra

Merge request reports

Loading
Loading