Delegate organization on wikis and snippets so org maintenance mode covers their LFS/Git access

What does this MR do and why?

Fixes two container types that slipped through the organization maintenance mode guard in Gitlab::GitAccess#check_organization_maintenance! (introduced in !251067 (merged)).

The guard checks container.respond_to?(:organization) before enforcing read-only mode during org maintenance. Two container types were not covered:

  1. Wikis (ProjectWiki / GroupWiki): Wiki defined no organization method, so respond_to?(:organization) returned false and the guard was skipped entirely. Fix: add delegate :organization, to: :container in Wiki — both Project and Group (via Namespace) already have belongs_to :organization, so the delegation works for both wiki types.

  2. Project snippets: ProjectSnippet responds to organization (via belongs_to :organization in Snippet), but organization_id stays NULL by design — a validated CHECK constraint (check_82c1d40fab) enforces exactly one of organization_id/project_id on the snippets table, and the org is resolved via project instead. So container.organization returned nil and the guard no-oped. An initial fix overriding organization on Snippet to fall back to project&.organization was rejected: Snippet also runs validates_with ExactlyOnePresentValidator, fields: [:project, :organization], and the override made both fields present for a ProjectSnippet, failing that check and breaking all 21 examples in spec/models/snippet_spec.rb. The shipped fix instead overrides check_organization_maintenance! in Gitlab::GitAccessSnippet to check snippet.organization || project&.organization, colocated with the existing #project override there, leaving the container-agnostic base class in Gitlab::GitAccess unchanged.

References

Screenshots or screen recordings

N/A — backend-only change.

How to set up and validate locally

  1. In a rails console, create an organization and put it in maintenance, then create a project in that org.
  2. Attempt a git push to the project wiki — it should now be blocked with the maintenance mode error.
  3. Create a project snippet in that project and attempt a git push — it should also be blocked.

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Edited by Chen Zhang

Merge request reports

Loading
Loading