Separate instance and organization admin contexts

What does this MR do?

Implements context separation between the instance admin and organization admin areas so each area resolves the current organization correctly.

  1. Context separation via ApplicationController hierarchy

    • Admin::ApplicationController skips set_current_organization so Current.organization is not set in the instance admin area. A private admin_current_organization fallback returns the first/default organization for legacy instance admin features that still rely on an organization; over time these should move to the organization admin area.
    • Admin::Organizations::ApplicationController re-enables set_current_organization, resolving the organization from the path so Current.organization is set in the org admin area.
  2. Organization admin area authorization

    • The organization admin area is gated by the access_organization_admin_area ability (see config/authz/permissions/organization_admin_area/access.yml), granted to instance admins and organization owners.
    • The org admin area resolves the organization strictly from the path (ignoring the X-GitLab-Organization-ID header), so admins can only administer the organization named in the URL.

Part of the admin organization context stack, decomposed from !226689 (closed).

Stacked (each targets the branch below it, so each diff shows only its own changes):

  1. !247881 (merged) – Centralize admin area organization resolution (targets master)
  2. !247426 (merged) – Separate instance and organization admin contexts ⬅️ you are here (targets dblessing_admin_current_organization_refactor, the branch of 1)
  3. !244408 (merged) – Org admin area routing changes (targets org-scoped-admin-permissions, the branch of 2)

This branch is built directly on top of !247881 (merged) and already incorporates its organization-resolution refactor.

Relates to #587370 (closed)

Edited by Drew Blessing

Merge request reports

Loading
Loading