Enforce action-specific govern_policy abilities on org Policy Store editor
What does this MR do and why?
Follow-up to !249442 (merged), which defines the create_govern_policy, update_govern_policy, and delete_govern_policy permissions on the govern_policy resource and grants them to organization owners and admins, but keeps the Policy Store editor gated on update_govern_policy for both new and edit while the Authorization reviewer confirms the design.
This MR wires the controller to enforce the action-specific abilities:
index(list) authorizes onread_govern_policynew(create a policy) authorizes oncreate_govern_policyedit(update a policy) authorizes onupdate_govern_policy
delete_govern_policy stays defined and granted but is intentionally not enforced here: the Policy Store has no delete action or endpoint yet (the editor is client-side). It is reserved for the delete flow that lands with the real Policy Store API and will be enforced there.
Everything is behind the security_policies_v2 experiment (feature flag + instance setting + security_orchestration_policies license), so no changelog entry.
References
- Parent MR: !249442 (merged)
- Permission definitions and the decision to add all three CRUD definitions: !249442 (merged)
- Policy Store work items: https://gitlab.com/gitlab-org/gitlab/-/work_items/604312, https://gitlab.com/gitlab-org/gitlab/-/work_items/604308, https://gitlab.com/gitlab-org/gitlab/-/work_items/604307
Screenshots or screen recordings
| Before | After |
|---|---|
| N/A (backend authorization only) | N/A (backend authorization only) |
How to set up and validate locally
- Enable the experiment for an organization:
security_policies_v2feature flag on, thepolicy_store_experiment_enabledapplication setting on, and thesecurity_orchestration_policieslicense available. - As an organization owner, visit
/o/<org>/-/security/policy_store/newand/o/<org>/-/security/policy_store/1/edit; both render the editor. - Deny the owner's
create_govern_policyand confirmnewreturns 404 whileeditstill renders; then denyupdate_govern_policyand confirm the reverse. - Run
bundle exec rspec ee/spec/requests/organizations/security/policy_store_controller_spec.rb.
MR acceptance checklist
Evaluate this MR against the MR acceptance checklist.