Loading
Let the policy store own a policy by organization alone
What does this MR do and why?
Follows the schema change in
!249126 (merged), which made
govern_policies.namespace_id nullable so a governance policy can be owned by an
organization rather than by a top-level group.
Gitlab::PolicyStore is still stricter than the column it models, so it rejects the row
that change exists to allow. This drops namespace_id from
Ports::PolicyRepository::REQUIRED_ATTRIBUTES and gives it a nil default on the Policy
value object. The attribute stays, since both ownership forms are valid, and nothing that
passes a namespace today changes behaviour.
Gem-only, matching !249126. Govern::Policy keeps belongs_to :namespace, optional: false and is relaxed separately in the stack behind it.
How to set up and validate locally
- On the rails console, create an organization-owned policy and verify it is accepted rather than raising
Gitlab::PolicyStore.create(
organization_id: 1,
name: 'Organization owned',
trigger_type: 'merge_request'
)- Verify the returned policy has
namespace_idofnilandorganization_idof1. Before this change the same call raisedGitlab::PolicyStore::ValidationErrorwithMissing required attributes: namespace_id - Create a group-owned policy and verify the namespace still round-trips
Gitlab::PolicyStore.create(
organization_id: 1,
namespace_id: Group.first.id,
name: 'Group owned',
trigger_type: 'merge_request'
).namespace_idReferences
- The schema change this follows: !249126 (merged) (merged)
- The MR both were split out of: !248000 (closed)
- Part of https://gitlab.com/groups/gitlab-org/-/epics/22937
Edited by Marcos Rocha