Add ids filter to the policy store policies GraphQL query
What does this MR do and why?
Adds an optional ids argument to the policy store policies GraphQL query (organization.policyStore.policies) so callers can fetch a specific set of policies by id in one query, AND-composable with the existing triggerType argument. Filtering happens in Security::SecurityOrchestrationPolicies::PolicyStore::ListService against the gem list result — no per-id lookups. Unknown ids return an empty list; an explicitly empty ids array returns no policies; unauthorized access returns null, consistent with the existing gating.
Closes https://gitlab.com/gitlab-org/gitlab/-/work_items/617784 (confidential).
Review notes
- The argument type is
[Int!], notID/GlobalID:GovernPolicy.idis already exposed asIntand the REST endpoint takespolicy_idas Integer, so clients can round-trip what they read. Theidfield and this argument should move to a wider type together in a follow-up before the experiment widens (the column is bigint). - The
idsargument now has explicit length validation capped atTypes::BaseArgument::MAX_ARRAY_SIZE(1000), following the GraphQL array argument validation guide, with the maximum documented in the argument description.
Adversarial pre-review verdict was "pass with findings"; all in-scope findings were applied (cross-organization leak spec, Set-based membership, pinned empty-array semantics, persistent-repository coverage).
References
- Plan (approved) on the issue: https://gitlab.com/gitlab-org/gitlab/-/issues/617784#note_3725210752
- Epic: https://gitlab.com/groups/gitlab-org/-/epics/22542
- Prior MR that added the
policiesfield: !250240 (merged)
Screenshots or screen recordings
No UI changes.
How to set up and validate locally
- Enable the experiment (rails console):
Feature.enable(:security_policies_v2)andGitlab::CurrentSettings.current_application_settings.update!(policy_store_experiment_enabled: true)— requires an Ultimate license. - Create two policies via REST (as an organization owner, org id 1):
curl -X POST -H "PRIVATE-TOKEN: $TOKEN" "http://gdk.test:3000/api/v4/organizations/1/security/policy_store" --data 'name=Policy A&trigger_type=deployment_requested&rules[][type]=custom&rules[][value]=package policy'(and once more with name=Policy B). - Query GraphQL (as the same user) at /-/graphql-explorer:
query {
organization(id: "gid://gitlab/Organizations::Organization/1") {
policyStore {
policies(ids: [1], triggerType: "deployment_requested") {
id
name
triggerType
}
}
}
}- Expect only Policy A. Repeat with
ids: [999]→ empty array, no error. Repeat withids: []→ empty array.
Verification
Local run of the three changed spec files — 47 examples, 0 failures, 1 pending (the pending example is a pre-existing skip in a shared granular-token example, unrelated). RuboCop: 5 files inspected, no offenses detected.
MR acceptance checklist
Evaluate this MR against the MR acceptance checklist.