Fix 500 error in resource access token API when bot has no membership

What does this MR do and why?

API::Entities::ResourceAccessToken read the access level with token.user.members.first.access_level. For inactive (revoked or expired) tokens, the bot user's membership may already be gone, so members.first is nil and the endpoint failed with a 500 error, for example on GET /groups/:id/manage/resource_access_tokens?state=inactive. This MR uses safe navigation so access_level is null in that case, and adds a request spec for it.

Closes #602579.

Screenshots or screen recordings

Not applicable — backend change.

How to set up and validate locally

  1. Run bundle exec rspec spec/lib/api/entities/resource_access_token_spec.rb.
  2. Run bundle exec rspec ee/spec/requests/api/manage/groups_spec.rb.

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist.

This contribution was prepared with the help of an AI assistant. I reviewed the changes and take responsibility for them.

Merge request reports

Loading
Loading