Fix AI Catalog explore ordering for anonymous users

What does this MR do and why?

Fixes #608286 (closed). On the public AI Catalog explore page, GitLab-maintained items like Amazon Q Developer are supposed to always show up at the top of the list. That worked fine if you were signed in, but visitors who weren't logged in saw the list ordered newest-first instead, so those items ended up buried further down. The cause was simple: the code had a shortcut for logged-out visitors that skipped the special ordering step entirely and just handed back the plain list, which then defaulted to newest-first.

This MR removes that shortcut, so logged-out visitors go through the same ordering as signed-in users. Everyone now sees the same order, with the GitLab-maintained items on top. Nothing changes about which items people can see, only the order they show up in. Logged-out visitors still can't see anything private or restricted.

Also fixed a small gap where Amazon Q Developer was missing from the internal list of GitLab-maintained agents, even though the Claude and Codex agents were already on it. Checked this against production data to confirm. Tests were added so this ordering issue can't silently come back for logged-out visitors.

References

#608286 (closed)

Screenshots or screen recordings

Before After
image image
image image

How to set up and validate locally

  1. In GDK, first run Feature.disable(:ai_catalog_synthetic_foundational_items) in the rails console. This flag masks the bug locally: when it's on, synthetic foundational items are added with NULL ids, which happen to sort first anyway.
  2. Open http://gdk.test:3000/explore/ai-catalog/agents in an incognito/private window (logged out). The foundational items (the GitLab-maintained ones) should now be at the top. Then open the same page logged in and confirm the order matches. The flows tab behaves the same way.

Database Query

Click to expand

Anonymous explore listing (default catalog_priority sort)

Query plan on Master branch - https://console.postgres.ai/gitlab/projects/gitlab-production-main/sessions/55385/commands/159066

Query plan on this branch - https://console.postgres.ai/gitlab/projects/gitlab-production-main/sessions/55385/commands/159068

SQL Query on this branch

SELECT "ai_catalog_items".*, CASE WHEN "ai_catalog_items"."id" IN (348, 356, 1003596, 1004583, 1005590, 1003979) THEN 1 WHEN "ai_catalog_items"."id" IN (2337, 2334, 2332) THEN 2 WHEN "ai_catalog_items"."verification_level" = 100 THEN 3 WHEN access_level IS NOT NULL THEN 4 ELSE 5 END AS catalog_priority
FROM (
  SELECT *, NULL::integer AS access_level
  FROM "ai_catalog_items"
  WHERE "ai_catalog_items"."deleted_at" IS NULL
    AND "ai_catalog_items"."organization_id" = 1
) ai_catalog_items
WHERE ("ai_catalog_items"."access_level" >= 10 OR "ai_catalog_items"."visibility" IN (1, 2))
  AND "ai_catalog_items"."visibility" != 1
ORDER BY CASE WHEN "ai_catalog_items"."id" IN (348, 356, 1003596, 1004583, 1005590, 1003979) THEN 1 WHEN "ai_catalog_items"."id" IN (2337, 2334, 2332) THEN 2 WHEN "ai_catalog_items"."verification_level" = 100 THEN 3 WHEN access_level IS NOT NULL THEN 4 ELSE 5 END ASC, "ai_catalog_items"."id" DESC
LIMIT 21

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Related to #608286 (closed)

Merge request reports

Loading
Loading