Skip to content

Remove admin ability not to use Hashed Storage

What does this MR do?

  • Modify the view and make Hashed Storage checkbox read-only when it is "enabled"
  • Add a validation rule in application_settings to prevent hashed_storage configuration to be false
  • Add a background migration to set hashed_storage setting to true
  • Prevent disabling hashed storage via API

Screenshots

Does this MR meet the acceptance criteria?

Conformity

Availability and Testing

Security

If this MR contains changes to processing or storing of credentials or tokens, authorization and authentication methods and other items described in the security review guidelines:

  • Label as security and @ mention @gitlab-com/gl-security/appsec
  • The MR includes necessary changes to maintain consistency between UI, API, email, or other methods
  • Security reports checked/validated by a reviewer from the AppSec team

Closes #210018 (closed)

Edited by Gabriel Mazetto

Merge request reports