Allow MINIMAL_ACCESS as group_access when sharing groups via API
What does this MR do and why?
Fixes a bug where groups could not be invited to another group using a custom role that has Minimal Access (access level 5) as its base role.
Root cause
When sharing a group via POST /api/v4/groups/:id/share with group_access: 5 (Minimal Access), the API returned:
group_access does not have a valid valueThis happened because two places validated group_access against Gitlab::Access.all_values, which does not include MINIMAL_ACCESS (5):
GroupGroupLinkmodel validation- The
POST /groups/:id/shareAPI endpoint parameter validation
Gitlab::Access.values_with_minimal_access already existed as an EE-only method that includes MINIMAL_ACCESS, but it was not used in these two places.
Fix
- Add
Gitlab::Access.values_with_minimal_accessto CE as an alias forall_values(preserving CE behavior — MINIMAL_ACCESS is not a valid CE role) - Add the
overrideguard to the EEvalues_with_minimal_accessmethod (since CE now defines it) - Use
values_with_minimal_accessinGroupGroupLinkvalidation and the group share API endpoint, so that EE correctly accepts MINIMAL_ACCESS as a validgroup_accessvalue
This follows the existing EE pattern used by ee/lib/api/ldap_group_links.rb and ee/lib/api/saml_group_links.rb, which already use values_with_minimal_access.
References
- Issue: #578025 (closed)
Screenshots or screen recordings
N/A — API-only change.
How to set up and validate locally
- Enable EE features and create a custom role with Minimal Access base:
member_role = MemberRole.create!(name: 'Custom Minimal', base_access_level: 5, namespace: Group.first) - Try sharing a group with
group_access: 5andmember_role_id: member_role.idvia the API:curl --request POST --header "PRIVATE-TOKEN: <token>" \ "http://localhost:3000/api/v4/groups/<group_id>/share" \ --data "group_id=<other_group_id>&group_access=5&member_role_id=<member_role_id>" - Before fix:
{"error":"group_access does not have a valid value"} - After fix:
201 Createdwith the group link created
MR acceptance checklist
Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.