Backport of 'Fix approval rule editing locked by non-instance settings'
What does this MR do and why?
Related to MR approval rules reappear after deletion when ... (#605117 - closed) Backports Fix approval rule editing locked by non-instanc... (!244198 - merged) to %19.0
Project maintainers could no longer edit or delete a project's approval rules when a group-level or project-level "Prevent editing approval rules in merge requests" setting was enabled. Updates returned 403 "Prohibited" and deletes returned a phantom 204 without actually removing the rule.
The root cause was that ApprovalProjectRulePolicy's lock was keyed off the project's resolved disable_overriding_approvers_per_merge_request? value, which folds together the instance, group, project, and merge request approval policy settings. Per the documentation, only the instance-level "Prevent editing approval rules in projects and merge requests" setting should lock the approval rules list in project settings. The group-level and project-level settings only prevent overriding approvers on individual merge requests — they must not lock the rules list.
This MR scopes the project approval rules list lock to the instance-level setting only, and consolidates the lock into the policy layer via delegation.
MR acceptance checklist
This checklist encourages us to confirm any changes have been analyzed to reduce risks in quality, performance, reliability, security, and maintainability.
- This MR is backporting a bug fix, documentation update, or spec fix, previously merged in the default branch.
- The MR that fixed the bug on the default branch has been deployed to GitLab.com (not applicable for documentation or spec changes).
- The MR title is descriptive (e.g. "Backport of 'title of default branch MR'"). This is important, since the title will be copied to the patch blog post.
- Required labels have been applied to this merge request
- severity label and bug subtype labels (if applicable)
- If this MR fixes a bug that affects customers, the customer label has been applied.
- This MR has been approved by a maintainer (only one approval is required).
- Ensure the
e2e:test-on-omnibus-eejob has succeeded, or if it has failed, investigate the failures. If you determine the failures are unrelated, you may proceed. If you need assistance investigating, request help in the #s_developer_experience Slack channel to confirm the failures are unrelated to the merge request.
Note to the merge request author and maintainer
If you have questions about the patch release process, please:
- Refer to the patch release runbook for engineers and maintainers for guidance.
- Ask questions on the
#releasesSlack channel (internal only). - Once the backport has been merged, the commit changes will be automatically deployed to a release environment that can be used for manual validation. See after merging runbook for details.