Grant create_approval_rule to eligible Developer MR authors

What does this MR do and why?

Grant create_approval_rule to eligible Developer MR authors

Developers who are the MR author or assignee could create approval rules through the UI but received a 403 when calling POST /api/v4/projects/:id/merge_requests/:iid/approval_rules directly.

ApprovalRules::CreateService#authorized? checks can?(current_user, :create_approval_rule, target), where target is the MergeRequest. MergeRequestPolicy delegates to ProjectPolicy via IssuablePolicy#subject_container, and create_approval_rule in ProjectPolicy is Maintainer-only via maintainer.yml. A prior fix added the enable rule to ApprovalMergeRequestRulePolicy, but that policy is only consulted when the subject is an ApprovalMergeRequestRule, not a MergeRequest, so it was never reached by this code path.

Grant create_approval_rule in EE::MergeRequestPolicy under the existing approval_rules_editable condition, which already encodes the full eligibility check (can_override_approvers? + Developer role + MR author/assignee). This matches the convention that create_ abilities are checked against the parent object, and aligns with how :update_approvers is already granted in the same policy.

References

https://gitlab.com/gitlab-com/request-for-help/-/work_items/5256+

How to set up and validate locally

You'll need to update the project and merge request ID values in the examples. You can generate a PAT for a user in the rails console with:

token = user.personal_access_tokens.create!(
  name: 'API token',
  scopes: [:api],
  expires_at: 1.year.from_now
)
token.token

Then in shell export the token

export GITLAB_TOKEN="MYTOKENHERE"
  1. Checkout master

  2. Navigate to the gitlab-org/gitlab-test project in GDK

  3. Add a separate user account as a direct Developer member.

  4. Disable Prevent editing approval rules in merge requests at the applicable project/group scope.

  5. Have the Developer create a merge request so the Developer is the MR author.

  6. Create a project-level approval rule requiring one approval.

  7. Using a short-lived PAT belonging to the MR author, call the documented merge request approval rules API with an explicit approver:

    curl --write-out "\nHTTP %{http_code}\n" \
      --request POST \
      --header "PRIVATE-TOKEN: $GITLAB_TOKEN" \
      --data-urlencode "name=REPRO-API-WITH-USER" \
      --data-urlencode "approvals_required=0" \
      --data-urlencode "user_ids[]=1" \
      "https://gdk.test:3443/api/v4/projects/2/merge_requests/1/approval_rules"
  8. Observe {"message":["Prohibited"]} with HTTP 403.

  9. Checkout fix/mr-approval-rule-create-developer-author

  10. Call the same API:

    curl --write-out "\nHTTP %{http_code}\n" \
      --request POST \
      --header "PRIVATE-TOKEN: $GITLAB_TOKEN" \
      --data-urlencode "name=REPRO-API-WITH-USER" \
      --data-urlencode "approvals_required=1" \
      --data-urlencode "user_ids[]=1" \
      "https://gdk.test:3443/api/v4/projects/2/merge_requests/1/approval_rules"
  11. Observe approval rule json and HTTP 201

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Edited by Joe Woodward

Merge request reports

Loading
Loading