Backport of 'Fix 500 when fetching vulnerability notes via REST API'

What does this MR do and why?

Fix 500 when fetching vulnerability notes via REST API. Discovered through incident https://gitlab.enterprise.slack.com/archives/C0BNGLQ8GAF

This is a scoped backport to 19.1 of the fix from !244620 (merged).

Details

The vulnerability notes endpoints (/projects/:id/vulnerabilities/:noteable_id/notes) returned HTTP 500 with "RuntimeError: no policy for Vulnerabilities::Read".

NotesFinder#target resolves vulnerabilities through the vulnerability_reads table and returns a Vulnerabilities::Read record, which has no DeclarativePolicy class, so the notes permission check raised instead of returning a decision.

Override find_noteable to map the Vulnerabilities::Read back to its Vulnerability before the permission check runs.

Changelog: fixed EE: true

References

Related https://gitlab.com/gitlab-org/gitlab/-/work_items/609126

Incident channel: https://gitlab.enterprise.slack.com/archives/C0BNGLQ8GAF

MR acceptance checklist

This checklist encourages us to confirm any changes have been analyzed to reduce risks in quality, performance, reliability, security, and maintainability.

  • This MR is backporting a bug fix, documentation update, or spec fix, previously merged in the default branch.
  • The MR that fixed the bug on the default branch has been deployed to GitLab.com (not applicable for documentation or spec changes).
  • The MR title is descriptive (e.g. "Backport of 'title of default branch MR'"). This is important, since the title will be copied to the patch blog post.
  • Required labels have been applied to this merge request
  • This MR has been approved by a maintainer (only one approval is required).
  • Ensure the e2e:test-on-omnibus-ee job has succeeded, or if it has failed, investigate the failures. If you determine the failures are unrelated, you may proceed. If you need assistance investigating, request help in the #s_developer_experience Slack channel to confirm the failures are unrelated to the merge request.

Note to the merge request author and maintainer

If you have questions about the patch release process, please:

Edited by Alex Buijs

Merge request reports

Loading