Reword burned path ID token failure messages

What does this MR do and why?

Follow-up to !248942 (merged), requested by @marcel.amirault in !248942 (comment 3678137946).

Every message a user sees for a burned project path starts with CI ID token. Reading CI ID first slows the sentence down, and the job page already states the CI context. This MR moves CI out of the leading position in all three strings and updates the message quoted in the troubleshooting topic to match.

Job page callout, in app/presenters/commit_status_presenter.rb:

  • Before: CI ID token issuance is disabled because this project's path was previously used by a different project. To restore CI ID tokens, set ...
  • After: ID token issuance is disabled in CI because this project's path was previously used by a different project. To restore ID tokens, set ...

Job status text, in lib/gitlab/ci/status/build/failed.rb:

  • Before: CI ID token issuance disabled for this project path
  • After: ID token issuance disabled for this project path

Error raised when minting the token, in lib/gitlab/ci/oidc_burned_path_error.rb:

  • Before: CI ID token issuance is disabled for this project because the project path was previously held by a different project. To restore CI ID token issuance, set ...
  • After: ID token issuance is disabled for this project because the project path was previously held by a different project. To restore ID token issuance, set ...

The wording for the error class is the suggestion @marcel.amirault left in !248942 (comment 3665028634).

doc/ci/secrets/id_token_authentication.md quotes the job page callout verbatim, so the code block there changes with it. The heading Error: ID token issuance is disabled and its anchor already dropped CI in the previous merge request, so no link changes.

🛠️ with ❤️ at Siemens

References

This branch is based on !248942 (merged). Until that one merges, its commit shows up in this diff. Merge it first.

Screenshots or screen recordings

Text-only change to messages already shown in !248942 (merged). The job page layout does not change.

Before After
CI ID token issuance is disabled because this project's path was previously used by a different project. ID token issuance is disabled in CI because this project's path was previously used by a different project.

How to set up and validate locally

  1. Start GDK and create a disposable project at root/id-token-error-message.

  2. Add and commit this .gitlab-ci.yml. The unmatched tag keeps the job pending:

    id-token-error-message:
      tags:
        - no-runner
      id_tokens:
        TEST_ID_TOKEN:
          aud: https://example.com
      script:
        - echo "This job should remain pending"
  3. Wait for pipeline creation to complete and confirm id-token-error-message is pending.

  4. From the GDK root, open the Rails console:

    gdk rails console
  5. Mark the pending job with the internal failure reason that renders this error:

    project = Project.find_by_full_path('root/id-token-error-message')
    job = project.builds.pending
      .where(name: 'id-token-error-message')
      .order(id: :desc)
      .first!
    job.drop!(:id_token_burned_project_path)
    Gitlab::Routing.url_helpers.project_job_url(project, job)
  6. Open the returned job URL.

  7. Confirm the callout starts with ID token issuance is disabled in CI and the status text reads ID token issuance disabled for this project path.

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Edited by Gerardo Navarro

Merge request reports

Loading
Loading