Drop read_namespace_via_membership ability from non-member roles
What does this MR do and why?
Drop read_namespace_via_membership ability from non-member roles
I originally introduced this ability in Address `read_namespace` semantic disjoint (#421150 - closed). It was never intended to be given to roles that aren't members.
The group permissions correctly exclude this ability on auditor and public_authenticated. On projects, the only impact I have found would be the fields on https://gitlab.com/gitlab-org/gitlab/-/blob/c740d663549ba5d99442a830b9dbbddfd82d3340/ee/app/graphql/ee/types/namespace_type.rb which include an explicit authorize: :read_namespace_via_membership when resolved against a project namespace. These fields had been marked this way explicitly to limit access to those fields to namespace members.
References
Screenshots or screen recordings
No UI changes
How to set up and validate locally
Execute the following query in the graphql explorer with a user that isn't a member of the project and group
query readNamespaceViaMembership {
namespace(fullPath: "<path>") {
totalRepositorySize
actualRepositorySizeLimit
storageSizeLimit
repositorySizeExcessProjectCount
totalRepositorySizeExcess
}
}Execute the query once for the project and for the group. On master you will see that you have access to these fields on projects, but not on groups.
On this branch, you will get null in both cases. If you execute the query as a user that is a member, you continue to have access.
MR acceptance checklist
Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.