Grant create_approval_rule to eligible Developer MR authors
What does this MR do and why?
Grant create_approval_rule to eligible Developer MR authors
Developers who are the MR author or assignee could create approval rules through the UI but received a 403 when calling POST /api/v4/projects/:id/merge_requests/:iid/approval_rules directly.
ApprovalRules::CreateService#authorized? checks can?(current_user, :create_approval_rule, target), where target is the MergeRequest. MergeRequestPolicy delegates to ProjectPolicy via IssuablePolicy#subject_container, and create_approval_rule in ProjectPolicy is Maintainer-only via maintainer.yml. A prior fix added the enable rule to ApprovalMergeRequestRulePolicy, but that policy is only consulted when the subject is an ApprovalMergeRequestRule, not a MergeRequest, so it was never reached by this code path.
Grant create_approval_rule in EE::MergeRequestPolicy under the existing approval_rules_editable condition, which already encodes the full eligibility check (can_override_approvers? + Developer role + MR author/assignee). This matches the convention that create_ abilities are checked against the parent object, and aligns with how :update_approvers is already granted in the same policy.
References
https://gitlab.com/gitlab-com/request-for-help/-/work_items/5256+
How to set up and validate locally
You'll need to update the project and merge request ID values in the examples. You can generate a PAT for a user in the rails console with:
token = user.personal_access_tokens.create!(
name: 'API token',
scopes: [:api],
expires_at: 1.year.from_now
)
token.tokenThen in shell export the token
export GITLAB_TOKEN="MYTOKENHERE"-
Checkout
master -
Navigate to the gitlab-org/gitlab-test project in GDK
-
Add a separate user account as a direct Developer member.
-
Disable Prevent editing approval rules in merge requests at the applicable project/group scope.
-
Have the Developer create a merge request so the Developer is the MR author.
-
Create a project-level approval rule requiring one approval.
-
Using a short-lived PAT belonging to the MR author, call the documented merge request approval rules API with an explicit approver:
curl --write-out "\nHTTP %{http_code}\n" \ --request POST \ --header "PRIVATE-TOKEN: $GITLAB_TOKEN" \ --data-urlencode "name=REPRO-API-WITH-USER" \ --data-urlencode "approvals_required=0" \ --data-urlencode "user_ids[]=1" \ "https://gdk.test:3443/api/v4/projects/2/merge_requests/1/approval_rules" -
Observe
{"message":["Prohibited"]}withHTTP 403. -
Checkout
fix/mr-approval-rule-create-developer-author -
Call the same API:
curl --write-out "\nHTTP %{http_code}\n" \ --request POST \ --header "PRIVATE-TOKEN: $GITLAB_TOKEN" \ --data-urlencode "name=REPRO-API-WITH-USER" \ --data-urlencode "approvals_required=1" \ --data-urlencode "user_ids[]=1" \ "https://gdk.test:3443/api/v4/projects/2/merge_requests/1/approval_rules" -
Observe approval rule json and
HTTP 201
MR acceptance checklist
Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.