Draft: Drive the Policy Store editor from the URL
What does this MR do and why?
Gives the Policy Store editor URL-addressable state, so a refresh or a shared link restores the exact editor view instead of falling back to the list.
- no params — the policy list
?editor=new&step=build|scope|review— creating a policy?editor=edit&policy=<id-or-name>&step=…— editing a policy, addressed by id when it has one, by name otherwise
Guard rails: an unknown step normalizes to build; an unknown editor value reads as the list; an edit link to a policy the list does not know returns to the list.
Implementation — plain frontend routing, no Vue Router and no backend changes (query params survive a refresh on the existing index route):
editor_url.jsowns the URL shape over~/lib/utils/url_utility(queryToObject,setUrlParams,removeParams).Appholds the state parsed from the URL, navigates withupdateHistory, and followspopstate, so browser Back/Forward walk the wizard.StepWizardtakes the step as a prop and emitschange-step; Next/Back/Edit all round-trip through the URL.
Stacked on !248607 (merged) (targets 607341-policy-store-editor-design); merge that first.
References
- Issue: https://gitlab.com/gitlab-org/gitlab/-/issues/607341
- Epic: https://gitlab.com/groups/gitlab-org/-/epics/22027
- Predecessor MR: !248607 (merged)
Screenshots or screen recordings
No visual changes — the list and editor render exactly as before; only the URL bar changes while navigating.
| Before | After |
|---|---|
/-/security/policy_store for every editor state |
/-/security/policy_store?editor=new&step=build, …?editor=edit&policy=1&step=review, … |
How to set up and validate locally
-
Enable the experiment for a top-level group:
# rails console Feature.enable(:security_policies_v2) ApplicationSetting.current.update!(policy_store_experiment_enabled: true) Group.find_by_full_path('flightjs').namespace_settings.update!(policy_store_experiment_enabled: true) -
Visit
http://gdk.test:3000/groups/flightjs/-/security/policy_store. -
Click Create new policy — the URL gains
?editor=new&step=build; Next/Back move it throughscopeandreview, and browser Back/Forward walk the steps. -
Refresh on any step — the editor reopens on that step.
-
Edit a policy from the list — the URL gains
?editor=edit&policy=1&step=build; refresh restores it. Replace1with the policy name (URL-encoded) — the same editor opens. -
Try a bogus step (
…&step=nonsense) or an unknown policy (…&policy=999) — you land onbuild/ the list respectively.
MR acceptance checklist
Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.