Loading
Skip username stamp for dynamic OAuth apps on SaaS
What does this MR do and why?
Dynamic OAuth applications created via the OAuth/Authorize endpoint were previously stamped with the authorizing user's name so admins could track which user created an otherwise-anonymous app. However, on gitlab.com, Anthropic's MCP clients now cache and reuse a single DCR application across multiple users instead of registering new apps each time. Stamping a single user's name onto a shared app is misleading for admins, so skip the stamp on SaaS but keep it on self-managed instances where the one-app-per-user behavior still holds.
How it works
- Added a hookable predicate
skip_dynamic_application_name_stamp?(returns false) in CE controllerapp/controllers/oauth/authorizations_controller.rbto guard the existing stamp method. - Added EE override in
ee/app/controllers/ee/oauth/authorizations_controller.rbreturning the SaaS feature check. - Registered new SaaS feature
skip_dynamic_oauth_app_user_stampinee/lib/gitlab/saas.rbandee/config/saas_features/skip_dynamic_oauth_app_user_stamp.yml. - Added EE request spec covering both paths (SaaS without stamp, self-managed with stamp).
Testing
EE request spec validates that the username stamp is omitted on SaaS but present on self-managed. Existing CE request specs pass unchanged.
References
https://gitlab.com/gitlab-com/request-for-help/-/work_items/5254