Track dependency_firewall_enabled setting toggle via InternalEvents

Summary

Fires a dependency_firewall_setting_changed internal event whenever a namespace's dependency_firewall_enabled setting is toggled on or off.

Event shape

  • Event name: dependency_firewall_setting_changed
  • Identifier: namespace
  • additional_properties.value: 1 when enabled, 0 when disabled

Implementation

Tracking lives in EE::Groups::UpdateService#after_update, guarded by group.namespace_settings.previous_changes.include?(:dependency_firewall_enabled). This places the instrumentation:

  • At the service layer rather than as an after_commit callback on the model, per review feedback.
  • Post-save, so the event is only emitted after group.save succeeds (avoiding false-positive events on failed saves).
  • Next to sibling post-save side effects (update_cascading_settings, schedule_remove_dormant_users, log_audit_events), where the planned audit event for this same setting is expected to land.

Testing

Specs live in ee/spec/services/groups/update_service_spec.rb and cover: enable-path, disable-path, unrelated-attribute-change, and failed-save. All use the trigger_internal_events / not_trigger_internal_events matchers.

MR acceptance checklist

  • This MR does not harm GitLab availability
  • This MR meets GitLab's definition of done
Edited by Michael Eddington

Merge request reports

Loading
Loading