Allow admins to change enterprise user primary email via Users API

What does this MR do and why?

Allows admins to change an enterprise user's primary email via the Users API, aligning with what is already possible in the Admin area UI (source).

References

Screenshots or screen recordings

Before After
{
    "message": {
        "email": [
            "must be owned by the user's enterprise group"
        ]
    }
}

How to set up and validate locally

  1. Simulate SaaS
  2. Create a test user with an example.com email
  3. Create a top-level group
  4. Create a project within the group
  5. Verify the domain within the top-level group
    • group = Group.find(GROUP_ID)
      project = group.projects.first
      project.pages_domains.create!(domain: 'example.com', verified_at: Time.current)
  6. If set up correctly, the user will be claimed as an Enterprise user. For testing purposes in the local environment, you can claim the user manually from the Rails console:
    • user = User.find_by_username('USERNAME')
      user.user_detail.update(enterprise_group_id: group, enterprise_group_associated_at: Time.current)
  7. Add a secondary email to the user
    • Emails::CreateService.new(User.first, { user: user, email: "249641_repro@test.test", skip_confirmation: true }).execute
  8. Using an admin PAT, use the Users API to update the primary email:
    • curl --location --request PUT 'https://gdk.test:3443/api/v4/users/ID' \
      --header 'PRIVATE-TOKEN: TOKEN' \
      --header 'Content-Type: application/json' \
      --data-raw '{
          "email": "249641_repro@test.test"
      }'
  9. Observe that the primary email has changed, releasing them from the Enterprise group

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Edited by Jio Castillo

Merge request reports

Loading
Loading