Repository navigation
fix(server-nestjs): resolve multi-path auditor groups in GitLab mapping - #2795
Merged
Merged
Conversation
The GitLab module compared the raw auditor group config against each admin role's oidcGroup in a single equality, so the default '/console/readonly,/console/security' resolved no role id: members of the platform security and read-only groups were not flagged as GitLab auditors. Split the admin and auditor configs like the other modules parse their platform group lists, so the configured groups — including /console/security — map to the admin and auditor flags. Refs #2792 Co-authored-by: Automata <automata@shikanime.studio> Signed-off-by: William Phetsinorath <william.phetsinorath-open@interieur.gouv.fr> Change-Id: Ia51fbbc90fb006d14891fe0955d83d306a6a6964
This was referenced Sep 29, 2026
shikanime
marked this pull request as ready for review
September 29, 2026 14:19
|
StephaneTrebel
approved these changes
Sep 30, 2026
github-merge-queue
Bot
removed this pull request from the merge queue due to failed status checks
Sep 30, 2026
5 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

0 New Issues
0 Fixed Issues
0 Accepted Issues
Issues liées
Refs #2792
Quel est le comportement actuel ?
getAdminRoleIdscomparait la valeur brute deauditorGroupPathà l'oidcGroupde chaque rôle admin par une égalité simple. La valeur par défaut'/console/readonly,/console/security'ne résolvait donc aucun rôle : les membres des groupes plateforme « sécurité » et « lecture seule » n'étaient pas marqués « auditor » dans GitLab (le bug affectait déjà/console/readonly).Quel est le nouveau comportement ?
adminGroupPathetauditorGroupPathsont découpés en liste — comme les autres modules le font pour leurs groupes plateforme — et chaque chemin résolu fournit les ids de rôles correspondants. Les marqueursadmin/auditorsont posés dès que l'utilisateur porte l'un de ces rôles ;/console/securityest désormais projeté comme/console/adminet/console/readonly.Cette PR introduit-elle un breaking change ?
Non.
Autres informations
Tests : 106 tests du module gitlab passent,
nest buildet lint OK.Note :
gitlab.service.tsetgitlab.service.spec.tssont partagés avec #2749 et #2654 — à coordonner au merge.Issue : #2792