Loading
Remove oauth_consents client_id foreign key for cross-cell compatibility
Closes #597595 (closed)
What does this MR do and why?
What?
- Removes the oauth_consents foreign key
fk_c5f142ff4b(oauth_consents.client_id→oauth_applications.uid) in a post-deploy migration, as agreed on the issue.
Why?
Before:
- DCR clients are created on the IAM service through
POST /oauth/registerand live only in IAM's database. - If a user consents to an application's authorization:
- GitLab creates a new
oauth_consentsrow - If
oauth_consents.client_iddoes not match anyoauth_applications.uid, it throws aPG::ForeignKeyViolation- This happens because the oauth application is in the IAM table (
oauth_clients)
- This happens because the oauth application is in the IAM table (
- GitLab creates a new
- If a user deletes an
oauth_application:- It automatically deletes its matching
oauth_consentsrows
- It automatically deletes its matching
After:
Found while testing the register endpoint: gitlab-org/auth/iam!560 (comment 3727417697)
- DCR clients are created on the IAM service through
POST /oauth/registerand live only in IAM's database. - If a user consents to an application's authorization:
- GitLab creates a new
oauth_consentsrow - If
oauth_consents.client_iddoes not match anyoauth_applications.uid, it allows the authz consent.
- GitLab creates a new
- If a user deletes an
oauth_application:- It does not delete its matching
oauth_consentsrows
- It does not delete its matching
Database Review
Steps to validate
-
On
master, inrails console, confirm a consent whose client_id has no local application row is rejected withActiveRecord::InvalidForeignKey:Authn::OauthConsent.create!( user: User.first, client_id: 'iam-only-client-uid', consent_challenge: SecureRandom.hex, requested_scopes: ['mcp'], granted_scopes: ['mcp'], status: :authorized ) -
Check out this branch and run
bin/rails db:migrate. -
Run the same console snippet from step 1 again and confirm the consent persists this time.
MR acceptance checklist
Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.
Edited by Hakeem Abdul-Razak