Gate pipeline list cancel and retry buttons on permissions
What does this MR do and why?
On the GraphQL-backed pipelines lists (project pipelines page, MR pipelines tab, commit pipelines tab), users below the cancel/retry permission threshold see Cancel and Retry buttons that fail with an authorization error when clicked. Reported in Pipelines list: Guest role sees "Can't find HEA... (#627161).
The old REST list combined pipeline state with a permission check server-side in flags.cancelable / flags.retryable. The GraphQL cancelable and retryable fields reflect pipeline state only, and pipeline_operations.vue rendered the buttons from them directly, so the permission gate was lost in the migration.
I added userPermissions { cancelPipeline updatePipeline } to the shared PipelineListItemBase fragment and now gate each button on state and permission together, the same way the pipeline details header does. All three list consumers import this fragment, so they all pick up the fix.
Visual Changes
| Before (As Reporter) | After (As Reporter) |
|---|---|
![]() |
![]() |
How to verify
- Create a project with a running pipeline and a failed pipeline (with at least one job each).
- As a Reporter, open Build > Pipelines: no Cancel or Retry buttons render.
- As a Developer or above, both buttons render and work.
Related to #627161

