Commit e97a34dd authored by Max Woolf's avatar Max Woolf Committed by Thong Kuah

Fix issue where project maintainers can not assign compliance frameworks

https://gitlab.com/gitlab-org/gitlab/-/merge_requests/53370 introduced
a regression which stopped project maintainers from assigning compliance
frameworks to a project.

This is an upcoming feature change which was designed to be
behind a feature flag.

This commit puts that change back behind the feature flag.
parent 9612a1fc
......@@ -60,6 +60,10 @@ module EE
@subject.feature_available?(:project_merge_request_analytics)
end
condition(:custom_compliance_framework_available) do
::Feature.enabled?(:ff_custom_compliance_frameworks)
end
with_scope :subject
condition(:group_push_rules_enabled) do
@subject.group && @subject.group.feature_available?(:push_rules)
......@@ -402,6 +406,7 @@ module EE
rule { requirements_available & owner }.enable :destroy_requirement
rule { compliance_framework_available & can?(:owner_access) }.enable :admin_compliance_framework
rule { compliance_framework_available & can?(:maintainer_access) & ~custom_compliance_framework_available }.enable :admin_compliance_framework
rule { status_page_available & can?(:owner_access) }.enable :mark_issue_for_publication
rule { status_page_available & can?(:developer_access) }.enable :publish_status_page
......
---
title: Fix issue where maintainers could not set compliance framework for projects
merge_request: 54071
author:
type: fixed
......@@ -1537,27 +1537,29 @@ RSpec.describe ProjectPolicy do
let(:policy) { :admin_compliance_framework }
where(:role, :feature_enabled, :admin_mode, :allowed) do
:guest | false | nil | false
:guest | true | nil | false
:reporter | false | nil | false
:reporter | true | nil | false
:developer | false | nil | false
:developer | true | nil | false
:maintainer | false | nil | false
:maintainer | true | nil | false
:owner | false | nil | false
:owner | true | nil | true
:admin | false | false | false
:admin | false | true | false
:admin | true | false | false
:admin | true | true | true
where(:role, :feature_enabled, :admin_mode, :custom_framework_flag, :allowed) do
:guest | false | nil | false | false
:guest | true | nil | false | false
:reporter | false | nil | false | false
:reporter | true | nil | false | false
:developer | false | nil | false | false
:developer | true | nil | false | false
:maintainer | false | nil | false | false
:maintainer | true | nil | false | true
:maintainer | true | nil | true | false
:owner | false | nil | false | false
:owner | true | nil | false | true
:admin | false | false | false | false
:admin | false | true | false | false
:admin | true | false | false | false
:admin | true | true | false | true
end
with_them do
let(:current_user) { public_send(role) }
before do
stub_feature_flags(ff_custom_compliance_frameworks: custom_framework_flag)
stub_licensed_features(compliance_framework: feature_enabled)
enable_admin_mode!(current_user) if admin_mode
end
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment