Extend MW-02 with project-only removal of one role-based deploy grant by its GitLab grant ID. Show the exact environment, selected role, and other deploy/approval entries; require an exact-name acknowledgement. Before one non-retrying PUT with only deploy_access_levels [{id, _destroy: true}], inspect every list page and the complete rule, reject stale or ambiguous matches, and verify after the write that exactly the selected grant is gone while all other grants and approval rules remain. An uncertain response requires reinspection. Keep group rules read-only. Cover 200/error/OAuth behavior, stale and session handling, five locales, and narrow/wide layouts.
Extend MW-02 with project-only removal of one role-based deploy grant by its GitLab grant ID. Show the exact environment, selected role, and other deploy/approval entries; require an exact-name acknowledgement. Before one non-retrying PUT with only deploy_access_levels [{id, _destroy: true}], inspect every list page and the complete rule, reject stale or ambiguous matches, and verify after the write that exactly the selected grant is gone while all other grants and approval rules remain. An uncertain response requires reinspection. Keep group rules read-only. Cover 200/error/OAuth behavior, stale and session handling, five locales, and narrow/wide layouts.