Authorize labels in GraphQL for ai_workflows scope

What does this MR do and why?

Allow access to the ai_workflows OAuth scope for the Project.labels and Group.labels GraphQL fields.

Previously these fields weren't accessible to tokens with the ai_workflows scope, making it impossible for the agent to look up labels before setting them on a work item. This MR permits access for ai_workflows tokens.

References

Related to #604527 (closed)

AI Gateway MR: gitlab-org/modelops/applied-ml/code-suggestions/ai-assist!6723 (merged)

Screenshots or screen recordings

Before After

How to set up and validate locally

  1. In the rails console of the GDK, create a new OAuth access token with ai_workflows scope.
organization = Organizations::Organization.first

application = Authn::OauthApplication.create!(
  name: "AI Workflows App",
  redirect_uri: "urn:ietf:wg:oauth:2.0:oob",
  scopes: "ai_workflows",
  owner: User.find_by_username("root"),
  organization: organization
)

OauthAccessToken.create!(
  application: application,
  resource_owner_id: application.owner_id,
  scopes: "ai_workflows",
  expires_in: 1.year.to_i,
  organization: organization
).plaintext_token
  1. Send a request with the new token to query the project labels.
curl -X POST http://gdk.test:3000/api/graphql \
  -H "Authorization: Bearer <your-token>" \
  -H "Content-Type: application/json" \
  --data '{"query": "query { project(fullPath: \"<project_full_path>\") { labels { nodes { id title } } } }"}' | jq
  1. You should see a response containing the project labels.
  2. Do the same for the group labels.
curl -X POST http://gdk.test:3000/api/graphql \
  -H "Authorization: Bearer <your-token>" \
  -H "Content-Type: application/json" \
  --data '{"query": "query { group(fullPath: \"<group_full_path>\") { labels { nodes { id title } } } }"}' | jq
  1. You should see a response containing the group labels. On master both requests return null with an authorization error.
Example response:
{
  "data": {
    "project": {
      "labels": {
        "nodes": [
          {
            "id": "gid://gitlab/ProjectLabel/109",
            "title": "testing"
          }
        ]
      }
    }
  }
}

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Edited by Eva Kadlecová

Merge request reports

Loading
Loading