Resolve Current.organization from git-over-HTTP repository paths

What does this MR do and why?

Git-over-HTTP and Git LFS requests do not set Current.organization correctly. These requests endup in the unresolvable organization category, which will result in the Default Organization.

But if my_group belongs to my-org, a git clone https://gitlab.com/my_group/my_project.git should result in my-org assigned to Current.organization.

Root cause: these routes capture the whole repository path as a single *repository_path glob (for example /my-group/sub-group/my-project.git/git-upload-pack), so none of the existing resolver's parameter sources (namespace_id, group_id, organization_path) are present. In addition, Git clients do not send the X-GitLab-Organization-ID header, and Git HTTP authentication does not go through Warden, so current_user is nil at the point the organization is resolved.

With no source to use, resolution falls back to the default organization.

For ssh, something similar is now under test Derive Current.organization from repository in ... (!253231 - merged)

References

Resolves #606175

How to set up and validate locally

Setup

With a freash database, run this in a Rails console:

my_org = Organizations::Organization.find_or_create_by!(path: 'my-org') { |org| org.name = 'My Org' }
group = Group.find_by_path('twitter')
user = User.find_by_username('root')
Organizations::Transfer::GroupsService.new(group: group, new_organization: my_org, current_user: user).execute

Now, using http://gdk.test:3000/o/my-org/twitter/:

Test HTTP Clone

In one terminal, tail the log file:

tail -f log/development_json.log \
  | grep --line-buffered -v '^#' \
  | jq --unbuffered -c 'with_entries(select(.key | startswith("meta")))'

In another terminal, on master branch:

$ cd /tmp
$ git clone http://root:<password>@gdk.test:3000/twitter/my-sub-group/some-code.git

The log file will output "meta.organization_id": 1. This is the wrong organization

Now switch to 606175-fix-repositories-current-org branch

$ cd /tmp
$ rm -Rf some-code
$ git clone http://root:<password>@gdk.test:3000/twitter/my-sub-group/some-code.git

The log file will output "meta.organization_id": 1000. This is the correct organization id.

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Edited by Rutger Wessels

Merge request reports

Loading
Loading