Allow enabling secret detection token revocation without URLs

What does this MR do and why?

PUT /api/v4/application/settings rejected secret_detection_token_revocation_enabled=true unless both secret_detection_token_revocation_url and secret_detection_revocation_token_types_url were supplied in the same request.

Those two URLs configure the external Token Revocation API, which is only used for third-party secret types. Automatic revocation of GitLab personal access tokens is handled internally and never reads them. So an administrator who wants only GitLab PAT revocation — which the docs list as available by default on Self-Managed — could not enable it through the API.

The validation was also asymmetric: setting the flag to false returned 200, only true returned 400, and the Rails console sets the flag to true with both URLs nil without issue. The API parameter validation was stricter than the setting it guards.

This MR makes the two URL parameters optional instead of requires, so the setting can be enabled on its own. The URLs can still be set when third-party revocation is needed.

Closes #621994 (closed).

How to validate locally

bin/rspec ee/spec/requests/api/settings_spec.rb -e secret_detection_token_revocation

Or manually, with an admin token:

curl -i --request PUT --header "PRIVATE-TOKEN: $TOKEN" \
  --data "secret_detection_token_revocation_enabled=true" \
  --url "https://gitlab.example.com/api/v4/application/settings"

Before: 400 Bad Request (secret_detection_token_revocation_url is missing, ...). After: 200 OK with secret_detection_token_revocation_enabled: true.

Merge request reports

Loading
Loading