Backport of "Send Duo availability params only when changed" (19.1)

What does this MR do and why?

Backport of !247516 (merged) to 19-1-stable-ee.

The group Duo settings form submitted all seven availability params on every save. Each _availability= setter also writes its cascading lock_* column. If an ancestor group or the instance had locked one of those settings, the unchanged param still failed validation and the whole PUT returned a 400:

{"message":{"namespace_settings.lock_duo_foundational_flows_enabled":["cannot be changed because it is locked by an ancestor"]}}

Nothing saved, so unrelated changes made in the same form, such as enabling a foundational flow, were discarded too. submitForm now sends an availability param only when the user changed it.

The fix is in 19.3. It is not in any 19.1 or 19.2 patch. A GitLab Self-Managed customer hit this on 19.2.0. The same code path exists on 19.1, so this branch is affected too. The 19.2 backport is !251546 (merged).

Issue: #599212 (closed)

The cherry-pick was clean. 19-1-stable-ee differs from the default branch only in an unrelated event that the fix does not touch, so the diff matches the original merge request exactly.

MR acceptance checklist

This checklist encourages us to confirm any changes have been analyzed to reduce risks in quality, performance, reliability, security, and maintainability.

  • This MR is backporting a bug fix, documentation update, or spec fix, previously merged in the default branch.
  • The MR that fixed the bug on the default branch has been deployed to GitLab.com (not applicable for documentation or spec changes).
  • The MR title is descriptive (e.g. "Backport of 'title of default branch MR'"). This is important, since the title will be copied to the patch blog post.
  • Required labels have been applied to this merge request
  • This MR has been approved by a maintainer (only one approval is required).
  • Ensure the e2e:test-on-omnibus-ee job has succeeded, or if it has failed, investigate the failures. If you determine the failures are unrelated, you may proceed. If you need assistance investigating, request help in the #s_developer_experience Slack channel to confirm the failures are unrelated to the merge request.

Note to the merge request author and maintainer

If you have questions about the patch release process, please:

Edited by Justin Ho Tuan Duong

Merge request reports

Loading
Loading