Skip to content

fix: a forbidden service fails alone and its error says where to look - #2

Merged
lesnik512 merged 2 commits into
mainfrom
fix/per-service-forbidden
Sep 28, 2026
Merged

lesnik512 merged 2 commits into
mainfrom
fix/per-service-forbidden

Conversation

@lesnik512

Copy link
Copy Markdown
Member

A real run failed with GitLab rejected the token (403) for /api/v4/projects/11736/deployments. It needs 'read_api' scope. and stopped the whole run. The token was fine. GitLab refuses read_deployment on a project whose Environments, CI/CD or repository is disabled, or when the user's role is too low. Group and project listing had already succeeded, which rules out a missing scope.

Changes

  • Projects with no deployments are skipped. When builds_access_level or environments_access_level is disabled, the service stays in the report with no rows and a warning naming the setting to enable, and no request is made for it. GitLab versions that don't return these fields are collected as before.

  • A forbidden service fails alone. A 403 inside one service becomes that service's error and the run continues (exit 1). A 401 still stops the run (exit 3). So does a 403 while resolving a --group or --project, because without it the tool can't know which services exist; that message now names the group or project.

  • Errors name the project and where to look. Per-service errors start with the project path instead of the numeric id. For a 403 they list the likely causes, each with a link:

    • deployments: Environments, CI/CD, role
    • pipelines and jobs: CI/CD, role
    • commits and tags: Repository, role
    • merge requests, including a commit's MR lookup: Merge requests, role

    The settings link is <project>/edit#js-shared-permissions, section "Visibility, project features, permissions", and the members link is <project>/-/project_members. Both were checked against GitLab's source and docs.

  • The API layer now sets the resource name on each error, so _messages.py no longer parses URLs.

  • The CLI prints Error: <error>, since errors now carry the project path.

The report schema is unchanged: schema_version 1, still warnings and error. The error text now starts with the project path and can span several lines.

Tests

The tests were written first. They cover:

  • a per-service 403 at use-case level and in the CLI (exit 1)
  • a 401 in the CLI (exit 3)
  • a 403 on --group and on --project resolution
  • per-resource cause lists
  • a forbidden MR lookup naming Merge requests
  • a network error naming the project
  • skips for disabled Environments or CI/CD
  • enabled and private values still being collected

All tests use respx only. 59 tests pass at 100% coverage.

@lesnik512
lesnik512 merged commit 1a1341d into main Sep 28, 2026
12 checks passed
@lesnik512
lesnik512 deleted the fix/per-service-forbidden branch September 28, 2026 21:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant