Skip to content

Create project protected branch rules with explicit push and merge roles #515

Description

@sjungwon03

Goal

Create a project protected branch rule from the existing protected-branches screen, independently of the in-review protected-tag work.

Acceptance

  • Support an exact branch name or wildcard pattern, with explicit push and merge role choices: No one (0), Developers and Maintainers (30), Maintainers (40). Default to no direct pushes and Maintainers for merge. Keep force push disabled and default unprotect permissions.
  • Explain that the rule can affect current and future matching branches, merge requests, protected CI variables, and jobs. Require acknowledgement of the exact pattern and both roles before writing.
  • Scan the complete protected-branch rule inventory before POST, reject duplicate/ambiguous or malformed pagination, block concurrent requests and OAuth replay, and confirm the exact 201 response before refreshing cached lists/details.
  • Keep uncertain results blocked until a new full inventory scan; distinguish permission/session/rate-limit errors, and isolate account changes and stale page responses.
  • Localize English source and supported locales. Cover API, controller, and widget paths test-first, including small/wide layouts and themes.

Boundary

Role-only project rules in this slice. User/group/deploy-key grants, code-owner approval, force-push controls, unprotect restrictions, inherited rule editing, and removal need separate issues. There is no atomic create-if-absent API guarantee, so duplicate detection is best effort.

Reference: https://docs.gitlab.com/api/protected_branches/#protect-repository-branches

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions