Allow MINIMAL_ACCESS as group_access when sharing groups via API

What does this MR do and why?

Fixes a bug where groups could not be invited to another group using a custom role that has Minimal Access (access level 5) as its base role.

Root cause

When sharing a group via POST /api/v4/groups/:id/share with group_access: 5 (Minimal Access), the API returned:

group_access does not have a valid value

This happened because two places validated group_access against Gitlab::Access.all_values, which does not include MINIMAL_ACCESS (5):

  1. GroupGroupLink model validation
  2. The POST /groups/:id/share API endpoint parameter validation

Gitlab::Access.values_with_minimal_access already existed as an EE-only method that includes MINIMAL_ACCESS, but it was not used in these two places.

Fix

  • Add Gitlab::Access.values_with_minimal_access to CE as an alias for all_values (preserving CE behavior — MINIMAL_ACCESS is not a valid CE role)
  • Add the override guard to the EE values_with_minimal_access method (since CE now defines it)
  • Use values_with_minimal_access in GroupGroupLink validation and the group share API endpoint, so that EE correctly accepts MINIMAL_ACCESS as a valid group_access value

This follows the existing EE pattern used by ee/lib/api/ldap_group_links.rb and ee/lib/api/saml_group_links.rb, which already use values_with_minimal_access.

References

Screenshots or screen recordings

N/A — API-only change.

How to set up and validate locally

  1. Enable EE features and create a custom role with Minimal Access base:
    member_role = MemberRole.create!(name: 'Custom Minimal', base_access_level: 5, namespace: Group.first)
  2. Try sharing a group with group_access: 5 and member_role_id: member_role.id via the API:
    curl --request POST --header "PRIVATE-TOKEN: <token>" \
      "http://localhost:3000/api/v4/groups/<group_id>/share" \
      --data "group_id=<other_group_id>&group_access=5&member_role_id=<member_role_id>"
  3. Before fix: {"error":"group_access does not have a valid value"}
  4. After fix: 201 Created with the group link created

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Merge request reports

Loading
Loading