Enforce action-specific govern_policy abilities on org Policy Store editor

What does this MR do and why?

Follow-up to !249442 (merged), which defines the create_govern_policy, update_govern_policy, and delete_govern_policy permissions on the govern_policy resource and grants them to organization owners and admins, but keeps the Policy Store editor gated on update_govern_policy for both new and edit while the Authorization reviewer confirms the design.

This MR wires the controller to enforce the action-specific abilities:

  • index (list) authorizes on read_govern_policy
  • new (create a policy) authorizes on create_govern_policy
  • edit (update a policy) authorizes on update_govern_policy

delete_govern_policy stays defined and granted but is intentionally not enforced here: the Policy Store has no delete action or endpoint yet (the editor is client-side). It is reserved for the delete flow that lands with the real Policy Store API and will be enforced there.

Everything is behind the security_policies_v2 experiment (feature flag + instance setting + security_orchestration_policies license), so no changelog entry.

References

Screenshots or screen recordings

Before After
N/A (backend authorization only) N/A (backend authorization only)

How to set up and validate locally

  1. Enable the experiment for an organization: security_policies_v2 feature flag on, the policy_store_experiment_enabled application setting on, and the security_orchestration_policies license available.
  2. As an organization owner, visit /o/<org>/-/security/policy_store/new and /o/<org>/-/security/policy_store/1/edit; both render the editor.
  3. Deny the owner's create_govern_policy and confirm new returns 404 while edit still renders; then deny update_govern_policy and confirm the reverse.
  4. Run bundle exec rspec ee/spec/requests/organizations/security/policy_store_controller_spec.rb.

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist.

Merge request reports

Loading
Loading