Add the policy store actions endpoint

What does this MR do and why?

Adds GET /security/policy_store/actions, the second of the Policy Store REST endpoints.

It builds on the Grape class and the shared gates the triggers endpoint introduced, now on master, so the change here is just the catalogue, the entity, and the route.

The catalogue lives in the gem as Gitlab::PolicyStore::Actions, next to the triggers one, so the domain owns it and the endpoint is only a way to read it. Action ids are written into the stored policy, so renaming one invalidates every policy already written against it.

The route is public and takes no permission, matching the triggers route: the response is a static catalogue, identical for every caller, so there is nothing to authorize against, and reserving read_govern_policy for the endpoints that return policy records keeps that permission meaningful. Both decisions are argued in the triggers MR, linked below, which is where to discuss them.

Which actions a policy can take will eventually depend on the trigger it targets. Both catalogues are returned whole for now. Narrowing one against the other is left until the create endpoint gives it a purpose, and it will need a rule for what the frontend does with a trigger that has no actions.

The gate coverage is identical for every catalogue route, so the request spec moves it into a shared example rather than repeating five contexts per endpoint. The rules endpoint reuses it next.

How to set up and validate locally

Requires an Ultimate licence.

  1. Enable the security_policies_v2 feature flag on the rails console
Feature.enable(:security_policies_v2)
  1. As an administrator, go to Admin > Settings > Security and compliance and turn on the policy store experiment
  2. List the actions a policy can take, with no token, since the endpoint is public
curl --url "http://gdk.test:3000/api/v4/security/policy_store/actions"
  1. Verify the response is
[
  { "id": "block", "name": "Block" },
  { "id": "require_approval", "name": "Require approval" }
]
  1. Turn the instance setting back off, repeat the call, and verify it returns 404 rather than 403, so an instance that has not enabled the experiment does not confirm the endpoint exists

References

Edited by Marcos Rocha

Merge request reports

Loading
Loading