Reject cross-organization pipeline execution config project
What does this MR do?
Security::Policy#update_pipeline_execution_policy_config_link! resolved the pipeline execution CI config project by full path with no organization check (Project.find_by_full_path). A pipeline execution policy could link a config project from a different organization, letting it inject CI config from an unrelated organization's project.
This MR scopes the lookup to the policy's own organization: Project.in_organization(source.organization_id).find_by_full_path(...), where source is the policy's project or namespace. A config project in another organization is no longer found, so nothing links — the same no-op as a config project that doesn't exist.
The equivalent GraphQL-layer fix (ConstructSecurityPoliciesSharedAttributes#pipeline_execution_policy_content_project) already landed on master via a sibling MR, along with a same_organization validation on Security::PipelineExecutionPolicyConfigLink. That MR shipped without resolver spec coverage, so this MR now only adds the missing regression spec for that path, plus the model-level fix and its specs.
Specs added: a cross-organization case in ee/spec/models/security/policy_spec.rb, a namespace-scoped (group-level) same-organization case proving links still work, and a cross-organization case in ee/spec/graphql/resolvers/security_orchestration/pipeline_execution_policy_resolver_spec.rb.
Production impact today: none. GitLab.com is single-organization; this closes a gap that only becomes exploitable once multi-organization/Cells ships.
References
Relates to https://gitlab.com/gitlab-com/gl-infra/tenant-scale/organizations/organizations-feature-parity/-/work_items/102 (finding "Pipeline execution CI config can reference any organization")
How to test
bundle exec rspec ee/spec/models/security/policy_spec.rb -e "#update_pipeline_execution_policy_config_link!" ee/spec/graphql/resolvers/security_orchestration/pipeline_execution_policy_resolver_spec.rb9 examples pass in the model spec, 12 in the resolver spec. Both new cross-organization examples were mutation-tested: removing the organization guard makes them fail.