Remove audit_event_pat_unseen_ip feature flag

What does this MR do?

Removes the audit_event_pat_unseen_ip feature flag from the codebase. The feature (audit event for a personal access token used from a previously unseen IP address) has been enabled for 100% of users on production since 2026-06-16 and has been stable throughout the 19.2 milestone.

Changes:

  • Remove the Feature.enabled?(:audit_event_pat_unseen_ip, user) check in PersonalAccessTokens::LastUsedService#log_audit_event_for_unseen_ip so the audit event is always recorded.
  • Remove the feature flag YAML definition (config/feature_flags/gitlab_com_derisk/audit_event_pat_unseen_ip.yml).
  • Remove now-obsolete stub_feature_flags(audit_event_pat_unseen_ip: false) usages and the "feature flag is disabled" spec context.

References

Merge request reports

Loading
Loading