Add ids filter to the policy store policies GraphQL query

What does this MR do and why?

Adds an optional ids argument to the policy store policies GraphQL query (organization.policyStore.policies) so callers can fetch a specific set of policies by id in one query, AND-composable with the existing triggerType argument. Filtering happens in Security::SecurityOrchestrationPolicies::PolicyStore::ListService against the gem list result — no per-id lookups. Unknown ids return an empty list; an explicitly empty ids array returns no policies; unauthorized access returns null, consistent with the existing gating.

Closes https://gitlab.com/gitlab-org/gitlab/-/work_items/617784 (confidential).

Review notes

  • The argument type is [Int!], not ID/GlobalID: GovernPolicy.id is already exposed as Int and the REST endpoint takes policy_id as Integer, so clients can round-trip what they read. The id field and this argument should move to a wider type together in a follow-up before the experiment widens (the column is bigint).
  • The ids argument now has explicit length validation capped at Types::BaseArgument::MAX_ARRAY_SIZE (1000), following the GraphQL array argument validation guide, with the maximum documented in the argument description.

Adversarial pre-review verdict was "pass with findings"; all in-scope findings were applied (cross-organization leak spec, Set-based membership, pinned empty-array semantics, persistent-repository coverage).

References

Screenshots or screen recordings

No UI changes.

How to set up and validate locally

  1. Enable the experiment (rails console): Feature.enable(:security_policies_v2) and Gitlab::CurrentSettings.current_application_settings.update!(policy_store_experiment_enabled: true) — requires an Ultimate license.
  2. Create two policies via REST (as an organization owner, org id 1): curl -X POST -H "PRIVATE-TOKEN: $TOKEN" "http://gdk.test:3000/api/v4/organizations/1/security/policy_store" --data 'name=Policy A&trigger_type=deployment_requested&rules[][type]=custom&rules[][value]=package policy' (and once more with name=Policy B).
  3. Query GraphQL (as the same user) at /-/graphql-explorer:
query {
  organization(id: "gid://gitlab/Organizations::Organization/1") {
    policyStore {
      policies(ids: [1], triggerType: "deployment_requested") {
        id
        name
        triggerType
      }
    }
  }
}
  1. Expect only Policy A. Repeat with ids: [999] → empty array, no error. Repeat with ids: [] → empty array.

Verification

Local run of the three changed spec files — 47 examples, 0 failures, 1 pending (the pending example is a pre-existing skip in a shared granular-token example, unrelated). RuboCop: 5 files inspected, no offenses detected.

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist.

Edited by Artur Fedorov

Merge request reports

Loading
Loading