Reset legacy 'gl' instance token prefix
What does this MR do and why?
instance_token_prefix defaulted to gl between 2025-02-27 (4156bc0c) and 2025-05-11 (36c2cc83), before being intentionally changed to ''. That default was written into application_settings.token_prefixes on any instance that saved its application settings during that window, even with the feature flag diabled.
The stale value has no effect today, but once custom_prefix_for_all_token_types is enabled, it composes the token prefix as <instance_prefix>-<type_prefix>, so every newly generated token comes out as gl-glpat-… (and equivalent for other token types) even though no administrator configured a prefix. It also overrides a configured custom PAT prefix without indication. The feature flag has not been enabled yet, so no token has ever been issued with a gl- prefix. This makes clearing the stale value safe.
This MR:
- Makes
Authn::TokenField::PrefixHelper.instance_prefixtreat a stored gl as unset (returns ''), sogl-is never prepended, regardless of whether the data migration below has run yet. - Rejects setting
instance_token_prefixtoglgoing forward in ApplicationSetting, but only when the value is being changed (if: :instance_token_prefix_changed?), so instances that still have gl persisted can keep saving other settings without being blocked. This avoids confusion in the future. - Adds a regular data migration that resets persisted
glvalues back to ''. It runs as a regular migration so it executes before the applying code on every upgrade path. down is a no-op: a reset row is indistinguishable from an intentionally empty one, and the old gl must not (and cannot) be restored, because we don't know if the the previous value was empty orgl.
References
- Default value for instance wide custom token pr... (#608221 - closed)
- Allow custom instance token prefix for all toke... (#388379 - closed)
- #388379 (comment 3648325675)
- Default
glintrocuded in 4156bc0c03ed - Changed to
in 36c2cc83519f
How to set up and validate locally
- Reproduce a legacy instance in bin/rails console:
s = ApplicationSetting.current
s.update_column(:token_prefixes, s.token_prefixes.merge('instance_token_prefix' => 'gl'))
Feature.enable(:custom_prefix_for_all_token_types)- Confirm the stored gl is treated as unset:
Authn::TokenField::PrefixHelper.instance_prefixreturns, and a newly created personal access token has the prefixglpat-xyz123..., notgl-glpat-xyz123.... - You can confirm unrelated settings still can be saved while
glis in the database by changing any other setting in the general admin view. - Confirm setting the prefix to gl is now rejected:
ApplicationSetting.current.update(instance_token_prefix: 'gl')
# => false, error: "is reserved and cannot be used"- Run the migration and confirm the stored value is cleared:
bin/rails db:migrate
ApplicationSetting.current.reload.instance_token_prefix
# => ""MR acceptance checklist
MR Checklist ( @nwittstruck)
- Changelog entry added, if necessary
- Documentation created/updated via this MR
- Documentation reviewed by technical writer or follow-up review issue created
- Tests added for this feature/bug
- Tested in all supported browsers
- Conforms to the code review guidelines
- Conforms to the merge request performance guidelines
- Conforms to the style guides
- Conforms to the javascript style guides
- Conforms to the database guides
Related to #608221 (closed)