Scope global group approvers to policy's organization
What does this MR do?
Security::ApprovalGroupsFinder searches all groups instance-wide when resolving a security policy's group approvers and security_policy_global_group_approvers_enabled is true (the default, no feature flag). That means a policy in one organization could reference an approver group belonging to a different organization.
This scopes the global search to the policy container's organization, using the existing Namespace#in_organization pattern. When there's no container (instance-level policy, not tied to any organization), behavior is unchanged.
Production impact today: none. GitLab.com is currently single-organization, so container.root_ancestor.organization always equals the target group's organization right now — this closes a gap that only becomes exploitable once multi-organization/Cells ships, per the finding below.
References
Relates to https://gitlab.com/gitlab-com/gl-infra/tenant-scale/organizations/organizations-feature-parity/-/work_items/102 (finding "Global group approvers search across all organizations")
How to test
bundle exec rspec ee/spec/finders/security/approval_groups_finder_spec.rb ee/spec/services/security/security_orchestration_policies/fetch_policy_approvers_service_spec.rb ee/spec/lib/security/scan_result_policies/approval_rule_params_builder_spec.rb
Query
explain SELECT "member_roles".* FROM "member_roles" WHERE "member_roles"."organization_id" = 1; Index Scan using index_member_roles_on_organization_id on public.member_roles (cost=0.28..3.30 rows=1 width=341) (actual time=2.198..2.199 rows=0 loops=1)
Index Cond: (member_roles.organization_id = 1)
Buffers: shared hit=3 read=2
I/O Timings: read=1.920 write=0.000
Settings: effective_cache_size = '472585MB', jit = 'off', random_page_cost = '1.5', work_mem = '230MB', seq_page_cost = '4'
Query ID: 2118778367707632724https://postgres.ai/console/gitlab/gitlab-production-main/sessions/55555/commands/159379