Derive Current.organization from repository in git internal API

What does this MR do and why?

This is a follow-up to !253015 (merged), which fixed Current.organization resolution for the Rails git-over-HTTP controllers, including the SSH data transfer requests /ssh-upload-pack and /ssh-receive-pack. The remaining gap is the Grape internal API, which gitlab-shell, Gitaly, and Workhorse call around every git operation.

Before this MR, the organization was resolved as follows:

Endpoint Organization before this MR
POST /internal/shellhorse/git_audit_event default-organization fallback — number 2 in the fallback table of issue 606175 (12,016 events in a 1% sample)
GET /internal/lfs default-organization fallback

This MR resolves Current.organization from the repository (the gl_repository parameter) on these two endpoints, through a new set_current_organization_from_repository helper in API::Helpers::InternalHelpers. The helper follows the existing pattern of set_current_organization_from_job / set_current_organization_from_runner in lib/api/ci/helpers/runner.rb: it checks Current.organization_assigned first, resolves Organizations::Organization.find_by_id_with_isolation_record(project.organization_id), and then runs check_organization_maintenance_mode!.

References

Related to #606175 (this issue stays open; not resolved by this MR).

Follow-up to !253015 (merged).

How to set up and validate locally

Setup

With a freash database, run this in a Rails console:

my_org = Organizations::Organization.find_or_create_by!(path: 'my-org') { |org| org.name = 'My Org' }
group = Group.find_by_path('twitter')
user = User.find_by_username('root')
Organizations::Transfer::GroupsService.new(group: group, new_organization: my_org, current_user: user).execute

Now, using http://gdk.test:3000/o/my-org/twitter/:

Test SSH Clone

In one terminal, tail the log file:

tail -f log/api_json.log \
  | grep --line-buffered 'git_audit_event' \
  | jq --unbuffered -c 'with_entries(select(.key | startswith("meta")))'

In another terminal, on master branch:

$ cd /tmp
$ git clone ssh://git@gdk.test:2222/twitter/my-sub-group/some-code.git

The log file will output "meta.organization_id": 1 for the git_audit_event entry. This is the wrong organization.

(Note: the /internal/allowed entries also show organization 1 — that is the home organization of the root user, and this MR deliberately does not change that.)

Now switch to 606175-internal-api-repo-org branch

$ cd /tmp
$ rm -Rf some-code
$ git clone ssh://git@gdk.test:2222/twitter/my-sub-group/some-code.git

The log file will output "meta.organization_id": 1000 for the git_audit_event entry. This is the correct organization id.

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Edited by Rutger Wessels

Merge request reports

Loading
Loading