Loading
Separate instance and organization admin contexts
What does this MR do?
Implements context separation between the instance admin and organization admin areas so each area resolves the current organization correctly.
-
Context separation via ApplicationController hierarchy
Admin::ApplicationControllerskipsset_current_organizationsoCurrent.organizationis not set in the instance admin area. A privateadmin_current_organizationfallback returns the first/default organization for legacy instance admin features that still rely on an organization; over time these should move to the organization admin area.Admin::Organizations::ApplicationControllerre-enablesset_current_organization, resolving the organization from the path soCurrent.organizationis set in the org admin area.
-
Organization admin area authorization
- The organization admin area is gated by the
access_organization_admin_areaability (seeconfig/authz/permissions/organization_admin_area/access.yml), granted to instance admins and organization owners. - The org admin area resolves the organization strictly from the path (ignoring the
X-GitLab-Organization-IDheader), so admins can only administer the organization named in the URL.
- The organization admin area is gated by the
Related MRs
Part of the admin organization context stack, decomposed from !226689 (closed).
Stacked (each targets the branch below it, so each diff shows only its own changes):
- !247881 (merged) – Centralize admin area organization resolution (targets
master) - !247426 (merged) – Separate instance and organization admin contexts
⬅️ you are here (targetsdblessing_admin_current_organization_refactor, the branch of 1) - !244408 (merged) – Org admin area routing changes (targets
org-scoped-admin-permissions, the branch of 2)
This branch is built directly on top of !247881 (merged) and already incorporates its organization-resolution refactor.
Related issues
Relates to #587370 (closed)
Edited by Drew Blessing