Hide repository actions from unauthorized users

What does this MR do and why?

Closes #628479 (closed)

Problem

Repo-less custom templates can create projects without a repository. Developers get unusable actions and a bare 404 when clicked.

Solution

  • Gate repository creation and import actions on :admin_project.
  • Show a permission message when the actions are unavailable.
  • Cover Developer and Maintainer views with feature specs.
  • Add the new message to locale/gitlab.pot.

References

#628479 (closed)

Screenshots or screen recordings

No screenshots attached. Verify the rendered states locally instead:

Before After Role
Screenshot_2026-09-13_at_18.22.03 Screenshot_2026-09-13_at_18.35.19 Developer
Screenshot_2026-09-13_at_18.23.11 Screenshot_2026-09-13_at_18.19.17 Maintainer

How to set up and validate locally

  1. Open a repo-less project as a Developer. Confirm the repository action buttons are hidden and the permission message is shown.
  2. Open the same project as a Maintainer. Confirm both repository action buttons are shown and the permission message is hidden.
  3. Run: bin/rspec spec/features/projects/show/repository_actions_spec.rb

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist.

Edited by Vasilii Iakliushin

Merge request reports

Loading
Loading