Delegate organization on wikis and snippets so org maintenance mode covers their LFS/Git access
What does this MR do and why?
Fixes two container types that slipped through the organization maintenance mode guard in Gitlab::GitAccess#check_organization_maintenance! (introduced in !251067 (merged)).
The guard checks container.respond_to?(:organization) before enforcing read-only mode during org maintenance. Two container types were not covered:
-
Wikis (
ProjectWiki/GroupWiki):Wikidefined noorganizationmethod, sorespond_to?(:organization)returned false and the guard was skipped entirely. Fix: adddelegate :organization, to: :containerinWiki— bothProjectandGroup(viaNamespace) already havebelongs_to :organization, so the delegation works for both wiki types. -
Project snippets:
ProjectSnippetresponds toorganization(viabelongs_to :organizationinSnippet), butorganization_idstays NULL by design — a validated CHECK constraint (check_82c1d40fab) enforces exactly one oforganization_id/project_idon thesnippetstable, and the org is resolved viaprojectinstead. Socontainer.organizationreturned nil and the guard no-oped. An initial fix overridingorganizationonSnippetto fall back toproject&.organizationwas rejected:Snippetalso runsvalidates_with ExactlyOnePresentValidator, fields: [:project, :organization], and the override made both fields present for aProjectSnippet, failing that check and breaking all 21 examples inspec/models/snippet_spec.rb. The shipped fix instead overridescheck_organization_maintenance!inGitlab::GitAccessSnippetto checksnippet.organization || project&.organization, colocated with the existing#projectoverride there, leaving the container-agnostic base class inGitlab::GitAccessunchanged.
References
- Closes #621577 (closed)
- Follow-up to !251067 (comment 3712950024)
Screenshots or screen recordings
N/A — backend-only change.
How to set up and validate locally
- In a rails console, create an organization and put it in maintenance, then create a project in that org.
- Attempt a git push to the project wiki — it should now be blocked with the maintenance mode error.
- Create a project snippet in that project and attempt a git push — it should also be blocked.
MR acceptance checklist
Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.