Stop auto-expanding Duo for disabled access
What does this MR do and why?
The Duo panel no longer opens on its own for people who cannot use Duo, so they stop landing on an "Access required" message they can do nothing about. Users who do have access still get the panel opening on their first visit.
References
Closes #611497 (closed)
Screenshots or screen recordings
| Before | After |
|---|---|
How to set up and validate locally
Requires a self-managed GDK:
gdk config set gdk.simulate_saas false
gdk reconfigure
gdk restart
GITLAB_SIMULATE_SAAS=0 bundle exec rails console1. User without Duo access
Disable Duo and Duo Core:
ApplicationSetting.current.update!(duo_availability: 'default_off')
org = Organizations::Organization.default_organization
Ai::Setting.find_or_create_by!(organization: org)
.update!(duo_core_features_enabled: false)Restart the Rails console, then create a non-admin user:
u = Users::CreateService.new(nil,
username: 'nonpilot_user',
name: 'Duo Nonpilot',
email: 'nonpilot_user@example.com',
password: 'Password123!!',
password_confirmation: 'Password123!!',
skip_confirmation: true,
organization_id: org.id
).execute.payload[:user]Sign in as nonpilot_user and open /dashboard/projects in a new tab.
Expected: Duo panel stays closed. Clicking the Duo icon shows "Access required".
2. Duo disabled for a group
g = Group.find_by_full_path('flightjs')
g.namespace_settings.update!(duo_features_enabled: false)
g.add_developer(u)
Users::Callout.where(user: u, feature_name: :duo_panel_auto_expanded).destroy_allOpen /groups/flightjs in a new tab.
Expected: Panel stays closed. Clicking the icon shows "GitLab Duo Agent Platform is turned off".
Note: Use a new tab (Cmd+T + URL). Duplicating a tab or using Cmd+click copies sessionStorage and can mask the result.
MR acceptance checklist
Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.