Add governPolicyUpdate GraphQL mutation for the policy store

What does this MR do and why?

Adds a governPolicyUpdate GraphQL mutation so the frontend policy editor can update an existing policy-store policy without going through the REST endpoint. It performs a partial update: only fields supplied by the client change, and omitted fields keep their current values. Experiment and permission gating stay in PolicyStore::UpdateService; the mutation only maps service errors (not_found/forbidden/experiment_not_active → resource-not-available, invalid → payload errors).

Two things reviewers will notice:

  • The six optional arguments shared with governPolicyCreate move into Mutations::Govern::CommonMutationArguments. This reorders GovernPolicyCreateInput arguments in the introspection artifact — input object fields are unordered in GraphQL, so the create mutation is semantically unchanged.
  • policyId is a plain Int, not a GlobalID, matching the GovernPolicy.id field — see the linked decision MR for the rationale and the Int32-widening caveat tracked for experiment graduation.

References

Screenshots or screen recordings

No UI changes.

How to set up and validate locally

  1. Enable the experiment in a rails console:

    Feature.enable(:security_policies_v2)
    ApplicationSetting.current.update!(policy_store_experiment_enabled: true)
  2. Create a policy first (as an organization owner) via the governPolicyCreate mutation or the REST endpoint, and note its id.

  3. Run this mutation in GraphiQL (http://gdk.test:3000/-/graphql-explorer), as an owner of the organization:

    mutation {
      governPolicyUpdate(input: {
        organizationId: "gid://gitlab/Organizations::Organization/1",
        policyId: 1,
        name: "Renamed policy",
        mode: "warn"
      }) {
        policy { id name mode description triggerType }
        errors
      }
    }
  4. Expected: name and mode change; description and triggerType keep their previous values (partial update). A nonexistent policyId returns a top-level "resource not available" error.

Verification

  • Request spec: ee/spec/requests/api/graphql/mutations/govern/policy_update_spec.rb — 20 examples, 0 failures, 1 pending (pending example is inside the shared granular-token example, same as the create mutation spec).
  • Unit spec: ee/spec/graphql/mutations/govern/policy_update_spec.rb — 5 examples, 0 failures.
  • bundle exec rake gitlab:graphql:update_all, gitlab:permissions:validate, and gitlab:permissions:graphql:compile_docs all run clean; artifacts committed.
  • Adversarial pre-review verdict: pass with findings. All pre-MR findings addressed (full-update spec coverage added, commit restructured so schema artifacts land with the change, changelog omission aligned with the sibling create MR). Remaining low-severity findings deferred as follow-ups: extracting the duplicated error-mapping block into a shared concern, a MAX_ARRAY_SIZE parity example, and explicit-null/no-op update coverage.

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist.

🤖 Generated with Claude Code

Merge request reports

Loading
Loading