Migrate policy store list view to GraphQL policies query
What does this MR do and why?
Migrates the Policy Store list view from REST to GraphQL, replacing the fetchPolicies wrapper with the policies query added in !250240 (merged). The Apollo provider is wired into the list page entrypoint for the first time (the editor page already used it), and a single GraphQL request now fetches both the policies and the triggers catalog. The now-unused fetchPolicies wrapper and the dead Api.getPolicyStorePolicies method are removed — the list app was their sole consumer (verified by repo-wide grep). fetchPolicy, createPolicy, updatePolicy and deletePolicy still use REST; a later issue migrates them. Related to #617789.
Two deliberate behavior changes:
- Permission detection: the resolver returns a null payload instead of HTTP 401/403/404 when the viewer lacks
read_govern_policyor thesecurity_policies_v2experiment is off, so the permission alert now fires on a successful response with a nullorganization/policyStore/policies. Network/execution errors show the generic alert with a Retry button and report to Sentry. - Catalog failure mode: the triggers catalog rides the same query, so a full query failure shows the list error (under REST a catalog failure only degraded trigger labels).
The mapping in app.vue preserves the exact row shape the list components consume today: derived type, status and scopedProjectsCount, plus the snake_case trigger_type, rules, actions and updated_at fields the expandable row details deserialize.
References
- Issue #617789 (confidential) · Epic &22542
- !250240 (merged) — the
policiesGraphQL query this MR consumes - Approved plan and progress record: https://gitlab.com/gitlab-org/gitlab/-/work_items/617789#note_3747167302
- GovernPolicy IDs are plain
Intby design (established in !250240 (merged)), so the frontend does not convert policy IDs to GlobalIDs.
Screenshots or screen recordings
| Description | UI |
|---|---|
| Policies loaded via Graphql |
How to set up and validate locally
- In a GDK with the policy store experiment enabled (
security_policies_v2feature flag plus the group opt-in in policy settings), visit the group's Policy Store list page (Secure > Policies area for the group). The policy list renders with Type/Mode/Status/Scope/Last updated columns as before, and the network tab shows onegetPolicyStorePoliciesGraphQL call instead of the REST/api/v4/organizations/:id/security/policy_storecall. - Expand a row — the configuration details still show the policy's rules and actions.
- As a user without the
read_govern_policypermission (or with the experiment disabled), the permission alert "You do not have permission to view the policies of this organization." shows without a Retry button. - Run
yarn jest ee/spec/frontend/policy_store ee/spec/frontend/api_spec.js— 30 suites / 495 tests pass.
Verification and review
- Jest:
ee/spec/frontend/policy_store+ee/spec/frontend/api_spec.js→ 30 suites / 495 tests green locally; eslint and prettier clean. - The query document was validated against the live gitlab.com schema (
glab api graphql) — no validation errors. - Adversarial review verdict: pass with findings — all actionable findings were addressed before this commit (details in the plan comment linked above).
MR acceptance checklist
Evaluate this MR against the MR acceptance checklist.