Loading
Hide repository actions from unauthorized users
What does this MR do and why?
Closes #628479 (closed)
Problem
Repo-less custom templates can create projects without a repository. Developers get unusable actions and a bare 404 when clicked.
Solution
- Gate repository creation and import actions on
:admin_project. - Show a permission message when the actions are unavailable.
- Cover Developer and Maintainer views with feature specs.
- Add the new message to
locale/gitlab.pot.
References
Screenshots or screen recordings
No screenshots attached. Verify the rendered states locally instead:
| Before | After | Role |
|---|---|---|
![]() |
![]() |
Developer |
![]() |
![]() |
Maintainer |
How to set up and validate locally
- Open a repo-less project as a Developer. Confirm the repository action buttons are hidden and the permission message is shown.
- Open the same project as a Maintainer. Confirm both repository action buttons are shown and the permission message is hidden.
- Run:
bin/rspec spec/features/projects/show/repository_actions_spec.rb
MR acceptance checklist
Evaluate this MR against the MR acceptance checklist.
Edited by Vasilii Iakliushin



