Disable Enable button for Developers at the Explore level
What does this MR do and why?
Disables the Enable button at the Explore level for users who cannot enable the item, and shows a "Contact maintainer to enable" tooltip.
Before this change, the button was active for every logged-in user with the read_ai_catalog ability, including Developers who could not enable an item anywhere. They only found out when the backend rejected the request. The maintainer check already existed, but only the consumer modal used it. This MR applies it to the button itself:
- Public items: the button is enabled when the user is a Maintainer of at least one Duo-licensed project (the existing
projectsIsUserMaintainerquery). The check is skipped while that query is in flight, so maintainers never see a briefly disabled button. - Private items: broad maintainership is not enough because the owning project is the only valid target. The button now requires the
createAiCatalogItemConsumerpermission on the item's own project, which this MR adds to the agent and flow detail queries (field introduced in 19.3).
The consumer modal uses the same canEnable value, so it applies the same private-item check.
Relationship to the reverted MR
A previous attempt (!242407 (merged)) replaced the maintainer query entirely with the owning-project permission, which was the crux of the problem. That disabled the button for public items too, because most users have no permission on someone else's project. So that MR was reverted. This MR keeps the maintainer query for public items and uses the owning-project permission only for private items.
References
- Closes #604007 (closed)
- Previous attempt (merged, then reverted): !242407 (merged)
- Subgroup concern from #613551 (closed): verified benign. Maintainers of subgroup projects are included, because
authorized_projects(MAINTAINER)counts inherited memberships and the Duo plan check resolves against the root namespace.
Screenshots or screen recordings
| Before | After |
|---|---|
How to set up and validate locally
- As a user who is not a Maintainer of any project, visit Explore > AI Catalog and open a public agent or flow. The Enable button should be disabled with a "Contact maintainer to enable" tooltip.
- As a Maintainer of any Duo-licensed project, the same button should be enabled.
- Open a private item you can view but whose owning project you cannot enable in (below Maintainer there). The button should be disabled.
- As a Maintainer of the private item's owning project, the button should be enabled.
MR acceptance checklist
Evaluate this MR against the MR acceptance checklist.