Load runner tags in the job assistant from the project

What does this MR do and why?

The job assistant drawer in the pipeline editor fetches runner tags on every page load. The runner tags query used the root runners GraphQL field, which requires instance admin privileges. This caused every non-admin user to see a GraphQL permission error in the browser console on every pipeline editor visit.

This MR fixes the issue by two changes:

  • The backend passes a new flag can-read-runners to the frontend. This flag is true when the user can read runners for the project, usually maintainers and owners.
  • The frontend queries project-scoped runners instead of root runners. The drawer skips the query when closed or when the user lacks the required permission. Users without permission see an empty tag list without a failed request.

The result is that non-admin users see no console error. Maintainers continue to see runner tags as before.

References

Screenshots or screen recordings

Not applicable. The tag options look the same for maintainers. Developers saw no tags before and see no tags now, without the console error.

How to set up and validate locally

  1. Run yarn jest spec/frontend/ci/pipeline_editor and bundle exec rspec spec/helpers/ci/pipeline_editor_helper_spec.rb.
  2. Sign in as a developer of a project and open CI/CD > Pipeline editor with the browser console open.
  3. On master the console shows GraphQL execution errors for query 'runners'. On this branch it shows nothing and no runners request is sent.
  4. Sign in as a maintainer, open the pipeline editor, click "Job assistant", and confirm the Tags dropdown lists the project runner tags.
  5. Confirm the runners request is sent only after the drawer opens.

MR acceptance checklist

This MR was evaluated against the acceptance checklist.

Merge request reports

Loading
Loading