Centralize admin area organization resolution
What does this MR do and why?
Introduces an admin_current_organization helper on Admin::ApplicationController and routes all admin controllers through it instead of referencing Current.organization directly.
This keeps organization resolution for the admin area in a single, overridable place. Behavior is unchanged: the helper returns Current.organization when assigned, and otherwise falls back to the single self-managed organization, which the admin area always operates on across SaaS, self-managed, and Dedicated. This is a behavior-preserving refactor that establishes a seam for follow-up work.
A follow-up change in !247426 (merged) can override admin_current_organization without touching each controller again. In the future, these controllers all need evaluated for moving to organization admin area which is likely more appropriate that instance admin area.
The shared WebHooks::HookActions#create now delegates to an overridable hook_organization method so the admin hooks controller can supply its own organization, while project and group hook controllers are unaffected.
Controllers migrated
- CE: applications, deploy_keys, groups, hooks, impersonation_tokens, integrations, labels, registrations/groups, slacks, topics, users
- EE: ai/amazon_q_settings, ai/duo_workflow_settings, application_settings/scim_oauth, push_rules
Testing
Affected controller/request specs pass unchanged (behavior-preserving refactor). The scim_oauth controller's inline default-organization fallback moved into the shared helper; its spec coverage for the unassigned case is retained.
MR acceptance checklist
- I have evaluated the MR acceptance checklist for this MR.