Drop read_namespace_via_membership ability from non-member roles

What does this MR do and why?

Drop read_namespace_via_membership ability from non-member roles

I originally introduced this ability in Address `read_namespace` semantic disjoint (#421150 - closed). It was never intended to be given to roles that aren't members.

The group permissions correctly exclude this ability on auditor and public_authenticated. On projects, the only impact I have found would be the fields on https://gitlab.com/gitlab-org/gitlab/-/blob/c740d663549ba5d99442a830b9dbbddfd82d3340/ee/app/graphql/ee/types/namespace_type.rb which include an explicit authorize: :read_namespace_via_membership when resolved against a project namespace. These fields had been marked this way explicitly to limit access to those fields to namespace members.

References

Screenshots or screen recordings

No UI changes

How to set up and validate locally

Execute the following query in the graphql explorer with a user that isn't a member of the project and group

query readNamespaceViaMembership {
  namespace(fullPath: "<path>") {
    totalRepositorySize
    actualRepositorySizeLimit
    storageSizeLimit
    repositorySizeExcessProjectCount
    totalRepositorySizeExcess
  }
}

Execute the query once for the project and for the group. On master you will see that you have access to these fields on projects, but not on groups.

On this branch, you will get null in both cases. If you execute the query as a user that is a member, you continue to have access.

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Edited by Niklas van Schrick

Merge request reports

Loading
Loading