Permit mentioned param in project members autocomplete
What does this MR do and why?
Permit mentioned param in project members autocomplete
The mentioned array that the quick action autocomplete sends to /-/autocomplete_sources/members was dropped when the projects controller moved to strong params in 330528b8 and permitted only search. Without it, Projects::ParticipantsService#mentioned_users never receives the usernames, so a user already @-mentioned in a comment is no longer guaranteed a spot in the payload and can't be floated to the top of /request_review @ and the other member quick actions on issues and merge requests.
The groups controller has permitted mentioned: [] since 28ce2fdd. This brings the projects controller in line and adds the spec that would have caught it.
Feature introduced in !240117 (merged)
References
!240117 (merged) (merged)
Screenshots or screen recordings
| Before | After |
|---|---|
![]() |
![]() |
How to set up and validate locally
The bug only shows when the mentioned user is not already in the default suggestion payload. That payload is the noteable author, the noteable's participants (assignees, reviewers, commenters, and anyone mentioned in a posted note), and the first 10 authorized users of the project ordered by username. Anyone in that set gets floated by the frontend on its own, with or without this MR.
-
Pick a project with more than 10 authorized users. In the GDK seed data,
flightjs/Flighthas 26. -
Pick a member who sorts after the first 10 by username. In
flightjs/Flightthat isvickey,sherlyn,nila.hagenes, orjanuary. For another project, list the order inrails consoleand take anyone past position 10:Project.find_by_full_path('flightjs/Flight').authorized_users.order(:username, :id).pluck(:username) -
Create a fresh merge request (or issue) in that project so the user is not a participant yet. Do not post a comment that mentions them while testing. A posted mention makes them a participant, and they will be in the default payload from then on.
-
Open devtools, Network tab, and tick "Disable cache". Leave devtools open for the rest of the steps. The members endpoint sends a 3 minute
Cache-Control, so without this the browser replays the response from before you switched branches. -
On
master, in the comment box in rich text mode, type@vickey can you review?, press Enter, then type/request_review @(/assign @on an issue).vickeyis missing from the dropdown. In the Network tab, the request toautocomplete_sources/memberscarriesmentioned[]=vickeyand the response body does not containvickey. -
Check out this branch. No GDK restart; the controller reloads on the next request.
-
Reload the page and repeat step 5.
vickeyis now the first item, the rest of the list keeps its order, and the response body containsvickey. -
Switch to plain text editing and repeat steps 5 and 7. Both editors hit the same endpoint.
MR acceptance checklist
Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

