Backport of 'Add application setting to block JWT for reclaimed project paths'
What does this MR do and why?
This backports !254058 (merged) to 19.3. GitLab 19.1 added a restriction that blocks CI/CD JWT/OIDC token generation for projects using a path that was previously assigned to a different project, protecting against a namespace-reclamation authentication bypass. Some GitLab Dedicated customers found their legitimate pipelines blocked when they reclaimed a project path, so this change adds an application setting called block_jwt_for_reclaimed_paths that lets admins disable the restriction if they accept the risk. The setting defaults to enabled everywhere, so the protection stays active on GitLab.com, GitLab Dedicated, and self-managed instances unless an admin turns it off.
Why this is a bug-fix backport, not a feature: the 19.1 restriction unintentionally blocked legitimate CI/CD pipelines for some customers, with no self-service way for them to resolve it other than an internal, manual workaround. This setting is the regression fix, since it is the only way to give affected admins self-service control without lowering the default security posture for everyone else.
References
- Original merge request: !254058 (merged)
- Work item: #623356 (closed)
- Related to: https://gitlab.com/gitlab-org/gitlab/-/issues/600358
MR acceptance checklist
This checklist encourages us to confirm any changes have been analyzed to reduce risks in quality, performance, reliability, security, and maintainability.
- This MR is backporting a bug fix, documentation update, or spec fix, previously merged in the default branch.
- The MR that fixed the bug on the default branch has been deployed to GitLab.com (not applicable for documentation or spec changes).
- The MR title is descriptive (e.g. "Backport of 'title of default branch MR'"). This is important, since the title will be copied to the patch blog post.
- Required labels have been applied to this merge request
- severity label and bug subtype labels (if applicable):
severity::2applied.bug::functionalis copied over from the original MR/work item. - If this MR fixes a bug that affects customers, the customer label has been applied: not set on the original MR or its work item, so not applied here.
- severity label and bug subtype labels (if applicable):
- This MR has been approved by a maintainer (only one approval is required).
- Ensure the
e2e:test-on-omnibus-eejob has succeeded, or if it has failed, investigate the failures. If you determine the failures are unrelated, you may proceed. If you need assistance investigating, request help in the #s_developer_experience Slack channel to confirm the failures are unrelated to the merge request.
Note to the merge request author and maintainer
If you have questions about the patch release process, please:
- Refer to the patch release runbook for engineers and maintainers for guidance.
- Ask questions on the
#releasesSlack channel (internal only). - Once the backport has been merged, the commit changes will be automatically deployed to a release environment that can be used for manual validation. See after merging runbook for details.