Skip username stamp for dynamic OAuth apps on SaaS

What does this MR do and why?

Dynamic OAuth applications created via the OAuth/Authorize endpoint were previously stamped with the authorizing user's name so admins could track which user created an otherwise-anonymous app. However, on gitlab.com, Anthropic's MCP clients now cache and reuse a single DCR application across multiple users instead of registering new apps each time. Stamping a single user's name onto a shared app is misleading for admins, so skip the stamp on SaaS but keep it on self-managed instances where the one-app-per-user behavior still holds.

How it works

  • Added a hookable predicate skip_dynamic_application_name_stamp? (returns false) in CE controller app/controllers/oauth/authorizations_controller.rb to guard the existing stamp method.
  • Added EE override in ee/app/controllers/ee/oauth/authorizations_controller.rb returning the SaaS feature check.
  • Registered new SaaS feature skip_dynamic_oauth_app_user_stamp in ee/lib/gitlab/saas.rb and ee/config/saas_features/skip_dynamic_oauth_app_user_stamp.yml.
  • Added EE request spec covering both paths (SaaS without stamp, self-managed with stamp).

Testing

EE request spec validates that the username stamp is omitted on SaaS but present on self-managed. Existing CE request specs pass unchanged.

References

https://gitlab.com/gitlab-com/request-for-help/-/work_items/5254

Merge request reports

Loading
Loading