Guard repository page Apollo hooks against missing data

What does this MR do and why?

This MR adds defensive null/undefined guards to vue-apollo result() and update() hooks in repository-page frontend components. Two root causes combine to produce runtime crashes:

  1. vue-apollo re-invokes result() with undefined after a query error.
  2. GraphQL can legitimately return project: null — for example when the viewer lacks access — and destructuring defaults (= {}) only protect against undefined, not null, so nested destructure defaults are bypassed and the hook throws on first property access.

The first two rows below fix active crashes with measured Sentry volume. The remaining three are proactive guards found during the same audit.

File Crash cause Fix
app/assets/javascripts/repository/components/last_commit.vue Template accessed commit.pipeline.id; pipeline can be absent (~1,600 Sentry events/day) Changed to commit.pipeline?.id
app/assets/javascripts/badges/components/open_mr_badge/open_mr_badge.vue update() used fully-defaulted nested destructure that still crashed on project: null (~400 events/day) Changed body to data?.project?.mergeRequests?.count
app/assets/javascripts/repository/components/fork_info.vue Bare result({ loading }) parameter threw when hook was called with no argument Changed to result({ loading } = {})
app/assets/javascripts/repository/mixins/get_ref.js Bare result({ data, loading }) parameter; body already guarded access with if (data && !loading) Changed to result({ data, loading } = {})
ee/app/assets/javascripts/repository/components/lock_directory_button.vue update({ project }) and update({ currentUser }) lacked parameter defaults Added = {} to both hook signatures

Regression specs cover the two reactive fixes: last_commit renders commit info without pipeline status when the response carries project: null; the open MR badge does not render when the response carries project: null.

References

Audit: gitlab-org#23447 (comment 3764413057) Precedent: !252566 (merged)

Closes https://gitlab.com/gitlab-org/gitlab/-/issues/625057 Closes https://gitlab.com/gitlab-org/gitlab/-/issues/625061 Closes https://gitlab.com/gitlab-org/gitlab/-/issues/625062

Screenshots or screen recordings

No visible UI change. These are defensive guards only; the rendered output is identical under normal conditions.

Before After
(no change) (no change)

How to set up and validate locally

  1. Start GDK.
  2. Visit a repository tree page, for example http://gdk.test:3000/flightjs/Flight/-/tree/master, and open a file under it.
  3. Confirm the last commit widget, pipeline status icon, and open MR badge all render normally.
  4. Open the browser console and confirm no TypeErrors are thrown.
  5. Run the frontend specs:
yarn jest spec/frontend/repository/components/last_commit_spec.js spec/frontend/repository/components/fork_info_spec.js spec/frontend/vue_shared/components/badges/open_mr_badge_spec.js ee/spec/frontend/repository/components/lock_directory_button_spec.js

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Merge request reports

Loading
Loading