Scope CSP project batches to the namespace's organization

What does this MR do?

Namespace#all_projects_with_csp_in_batches and #all_project_ids_with_csp_in_batches used ::Project.all for a CSP-designated namespace, returning every project on the instance regardless of organization. Scope both to the namespace's own organization via Project.in_organization.

designated_as_csp? already returns false on GitLab.com (csp_enabled? checks gitlab_com_subscription?), so this branch never runs there today — no production impact on GitLab.com. This closes a real gap for self-managed/Dedicated once multi-organization ships broadly: without this fix, a namespace designated as CSP for one organization would pull in every project across every organization on the instance when fanning out policy enforcement.

References

Relates to https://gitlab.com/gitlab-com/gl-infra/tenant-scale/organizations/organizations-feature-parity/-/work_items/102 (finding "CSP project scoping returns ALL projects across ALL organizations")

How to test

bundle exec rspec ee/spec/models/ee/namespace_spec.rb -e "#all_projects_with_csp_in_batches" -e "#all_project_ids_with_csp_in_batches"

Merge request reports

Loading
Loading