Add organization-level Policy Store controller

What does this MR do and why?

Adds an organization-scoped home for the experimental Policy Store, mirroring the group-level Groups::Security::PolicyStoreController. Organizations are the target architecture for Policy Platform ownership/scoping; this gives the experiment an organization entry point while the group-level path remains available.

Everything is behind the security_policies_v2 experiment (feature flag + instance setting + the security_orchestration_policies license, via Organization#policy_store_experiment_active?).

  • Navigation — a Policy store item in the organization Secure menu (Sidebars::Organizations::Menus::SecureMenu), shown when the security dashboard or the Policy Store experiment is available.
  • Controller + routes — Organizations::Security::PolicyStoreController (index/new/edit) under the org - scope; the edit route id is constrained to digits (/\d+/). JS route helpers regenerated.
  • Views — index, new, and edit mount the shared Policy Store app on #js-policy-store, passing organization_id, namespace_path, empty_list_svg_path, and the new/edit/list paths.
  • Frontend — the shared app renders the API-backed list (fetchPolicies) on index and the editor (step wizard) on new/edit; navigation between them uses the backend-provided paths (visitUrl), and each row's edit path is derived from the list path and policy id.
  • Authorization — the govern_policy resource: index requires read_govern_policy, new/edit require update_govern_policy, granted to organization owners and admins. Adds the create_govern_policy and update_govern_policy definitions (the resource already carries read/delete), giving it the full action-specific CRUD vocabulary.

References

Screenshots or screen recordings

List (empty state) New (editor)
org-policy-store-list org-policy-store-new

Edit page (/…/1/edit):

org-policy-store-edit

How to set up and validate locally

  1. Enable the experiment: security_policies_v2 feature flag on, the policy_store_experiment_enabled instance setting on, and an Ultimate (security_orchestration_policies) license.
  2. As an organization owner/admin, open /o/<org>/-/security/policy_store — the Secure sidebar shows Policy store; the list loads from the API.
  3. Create new policy navigates to /new (editor); a policy row links to /:id/edit; Cancel returns to the list.
  4. Without the experiment, or as a non-owner, the routes return 404 and the item is hidden.

Visual verification

Verified on GDK (security_policies_v2 active, root on org default), 0 console errors on every state:

  • List: the API fetch succeeds and the empty result renders the "No policies found" empty state; both create links point to /o/default/-/security/policy_store/new.
  • /new: the editor (step wizard) renders; no list fetch on the blank page.
  • Cancel: returns to the list via visitUrl.
  • /1/edit: the editor renders via the /\d+/ route.
  • /not-a-number/edit: returns 404 — the numeric constraint rejects non-numeric ids.

Testing

  • Frontend (ee/spec/frontend/policy_store/components/app_spec.js, .../list/list_wrapper_spec.js): the list is API-backed with loading/error states and link navigation; the editor renders by initial view and resolves the policy by id; cancel navigates via visitUrl.
  • Policy (ee/spec/policies/organizations/organization_policy_spec.rb): the govern_policy read/write abilities role matrix.
  • Menu, request, and routing specs for the organization Policy Store.
  • Local run: Jest 19/0, org RSpec suite 141/0, policy 15/0, permissions:validate clean, ESLint/RuboCop/HAML-lint clean, plus the browser verification above.

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist.

Edited by Alexander Turinske

Merge request reports

Loading
Loading