Add organization-aware admin users controller

What does this MR do and why?

Makes the admin users area organization-aware so an organization admin can manage users within their organization.

The shared user management actions are extracted from Admin::UsersController into an Admin::UsersActions concern. The instance controller keeps the actions that are not available to organizations (impersonate, reject, destroy) and continues to include the concern for everything else.

A new Admin::Organizations::UsersController inherits the organization admin authorization (access_organization_admin_area plus the org_admin_area release flag) and includes the shared concern, so it exposes the shared actions without the instance-only ones. Matching organization admin user routes are added under /o/:organization_path/admin/users.

Redirect helpers in the concern stay unscoped (admin_user_path, [:admin, @user]) and become organization-aware automatically via Current.organization, per the organization routing guidelines.

Related issue: #607559 (closed)

This MR is stacked on top of !244414 (merged) and targets its source branch.

Notes

  • Organization-unique actions are not part of this MR and will be added later.

Testing

  1. Create an organization and assign a test user as organization administrator/owner.
  2. With both the ui_for_organizations and org_experimental feature flags disabled, complete the next two steps.
    1. Navigate the instance admin area as an instance administrator. Things should work as normal.
    2. Attempt to access the admin area for the organization you created earlier - https://gdk.test:3443/o/acme/admin. You should receive a 404, despite being either instance admin or organization admin.
  3. Enable ui_for_organizations and org_experimental feature flags. Complete the remaining steps.
    1. Navigate the instance admin area as an instance administrator. Things should work as normal.
      • Accessing the same as an organization administrator should always result in a 404/access denied.
    2. Attempt to access the admin area for the organization you created earlier - https://gdk.test:3443/o/acme/admin. You should have access as both instance administrator and organization administrator.
    3. Select the 'Users' sidebar item.
      1. Note you can view users, but no actions exist - no three dots, no "Edit" button.
      2. View action still produces 404. We need to add an organization-specific view action in a follow-up.

MR acceptance checklist

This checklist encourages us to confirm any changes have been analyzed to reduce risks in quality, performance, reliability, security, and maintainability. Please review the acceptance checklist.

Edited by Drew Blessing

Merge request reports

Loading
Loading