Remove oauth_consents client_id foreign key for cross-cell compatibility

Closes #597595 (closed)

What does this MR do and why?

What?

  • Removes the oauth_consents foreign key fk_c5f142ff4b (oauth_consents.client_id → oauth_applications.uid) in a post-deploy migration, as agreed on the issue.

Why?

Before:

  • DCR clients are created on the IAM service through POST /oauth/register and live only in IAM's database.
  • If a user consents to an application's authorization:
    • GitLab creates a new oauth_consents row
    • If oauth_consents.client_id does not match any oauth_applications.uid, it throws a PG::ForeignKeyViolation
      • This happens because the oauth application is in the IAM table (oauth_clients)
  • If a user deletes an oauth_application:
    • It automatically deletes its matching oauth_consents rows

After:

Found while testing the register endpoint: gitlab-org/auth/iam!560 (comment 3727417697)

  • DCR clients are created on the IAM service through POST /oauth/register and live only in IAM's database.
  • If a user consents to an application's authorization:
    • GitLab creates a new oauth_consents row
    • If oauth_consents.client_id does not match any oauth_applications.uid, it allows the authz consent.
  • If a user deletes an oauth_application:
    • It does not delete its matching oauth_consents rows

Database Review

Steps to validate

  1. On master, in rails console, confirm a consent whose client_id has no local application row is rejected with ActiveRecord::InvalidForeignKey:

    Authn::OauthConsent.create!(
      user: User.first, client_id: 'iam-only-client-uid',
      consent_challenge: SecureRandom.hex, requested_scopes: ['mcp'],
      granted_scopes: ['mcp'], status: :authorized
    )
  2. Check out this branch and run bin/rails db:migrate.

  3. Run the same console snippet from step 1 again and confirm the consent persists this time.

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Edited by Hakeem Abdul-Razak

Merge request reports

Loading
Loading