Add the policy store actions endpoint
What does this MR do and why?
Adds GET /security/policy_store/actions, the second of the Policy Store REST endpoints.
It builds on the Grape class and the shared gates the triggers endpoint introduced, now on
master, so the change here is just the catalogue, the entity, and the route.
The catalogue lives in the gem as Gitlab::PolicyStore::Actions, next to the triggers
one, so the domain owns it and the endpoint is only a way to read it. Action ids are
written into the stored policy, so renaming one invalidates every policy already written
against it.
The route is public and takes no permission, matching the triggers route: the response is
a static catalogue, identical for every caller, so there is nothing to authorize against,
and reserving read_govern_policy for the endpoints that return policy records keeps that
permission meaningful. Both decisions are argued in the triggers MR, linked below, which
is where to discuss them.
Which actions a policy can take will eventually depend on the trigger it targets. Both catalogues are returned whole for now. Narrowing one against the other is left until the create endpoint gives it a purpose, and it will need a rule for what the frontend does with a trigger that has no actions.
The gate coverage is identical for every catalogue route, so the request spec moves it into a shared example rather than repeating five contexts per endpoint. The rules endpoint reuses it next.
How to set up and validate locally
Requires an Ultimate licence.
- Enable the
security_policies_v2feature flag on the rails console
Feature.enable(:security_policies_v2)- As an administrator, go to Admin > Settings > Security and compliance and turn on the policy store experiment
- List the actions a policy can take, with no token, since the endpoint is public
curl --url "http://gdk.test:3000/api/v4/security/policy_store/actions"- Verify the response is
[
{ "id": "block", "name": "Block" },
{ "id": "require_approval", "name": "Require approval" }
]- Turn the instance setting back off, repeat the call, and verify it returns
404rather than403, so an instance that has not enabled the experiment does not confirm the endpoint exists
References
- Related to https://gitlab.com/gitlab-org/gitlab/-/work_items/606971
- Part of https://gitlab.com/groups/gitlab-org/-/epics/22937
- Targets !249164 (merged) (open), which lets the store own a policy by organization alone and is the root of this chain. GitLab retargets this to
masteronce that merges. - Builds on !248934 (merged) (merged), which carries the Grape class, the shared gates, and the mount.
- Reordered behind the triggers endpoint, and the catalogue moved into the gem, following !248872 (comment 3651804154) and !248872 (comment 3651804120)