Permit mentioned param in project members autocomplete

What does this MR do and why?

Permit mentioned param in project members autocomplete

The mentioned array that the quick action autocomplete sends to /-/autocomplete_sources/members was dropped when the projects controller moved to strong params in 330528b8 and permitted only search. Without it, Projects::ParticipantsService#mentioned_users never receives the usernames, so a user already @-mentioned in a comment is no longer guaranteed a spot in the payload and can't be floated to the top of /request_review @ and the other member quick actions on issues and merge requests.

The groups controller has permitted mentioned: [] since 28ce2fdd. This brings the projects controller in line and adds the spec that would have caught it.

Feature introduced in !240117 (merged)

References

!240117 (merged) (merged)

Screenshots or screen recordings

Before After
Screenshot 2026-09-10 at 15.49.06.png Screenshot 2026-09-10 at 15.56.34.png

How to set up and validate locally

The bug only shows when the mentioned user is not already in the default suggestion payload. That payload is the noteable author, the noteable's participants (assignees, reviewers, commenters, and anyone mentioned in a posted note), and the first 10 authorized users of the project ordered by username. Anyone in that set gets floated by the frontend on its own, with or without this MR.

  1. Pick a project with more than 10 authorized users. In the GDK seed data, flightjs/Flight has 26.

  2. Pick a member who sorts after the first 10 by username. In flightjs/Flight that is vickey, sherlyn, nila.hagenes, or january. For another project, list the order in rails console and take anyone past position 10:

    Project.find_by_full_path('flightjs/Flight').authorized_users.order(:username, :id).pluck(:username)
  3. Create a fresh merge request (or issue) in that project so the user is not a participant yet. Do not post a comment that mentions them while testing. A posted mention makes them a participant, and they will be in the default payload from then on.

  4. Open devtools, Network tab, and tick "Disable cache". Leave devtools open for the rest of the steps. The members endpoint sends a 3 minute Cache-Control, so without this the browser replays the response from before you switched branches.

  5. On master, in the comment box in rich text mode, type @vickey can you review?, press Enter, then type /request_review @ (/assign @ on an issue). vickey is missing from the dropdown. In the Network tab, the request to autocomplete_sources/members carries mentioned[]=vickey and the response body does not contain vickey.

  6. Check out this branch. No GDK restart; the controller reloads on the next request.

  7. Reload the page and repeat step 5. vickey is now the first item, the rest of the list keeps its order, and the response body contains vickey.

  8. Switch to plain text editing and repeat steps 5 and 7. Both editors hit the same endpoint.

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Merge request reports

Loading
Loading