Refuse routing service desk email on slug collision

What does this MR do and why?

full_path_slug is lossy, so different routes can collapse to the same service desk address. On self-managed instances without a Topology Service claim, legacy or backfilled data can contain duplicate slugs. The resolver previously returned the first arbitrary match, allowing cross-project ticket interception.

Fail closed: when more than one project matches, log a warning and return no project so the sender receives a generic ProjectNotFound rejection instead of the email reaching the wrong project.

Related to #606780

Merge request reports

Loading
Loading