fix: secure tenant writes and schema migrations for v0.45.0 - #177
Merged
Merged
Conversation
rrrodzilla
marked this pull request as ready for review
September 25, 2026 00:58
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This change fixes all fifteen open issues covering tenant isolation, write authorization, migration safety, and CLI configuration. Tenant checks follow schema annotations, legacy tenant roots stay isolated, invitations validate tenant scope, and members cannot move records across tenants. Field authorization filters caller input before rules and hooks. Defaults, owner values, and audit values precede required validation; REST and GraphQL share the write pipeline. GraphQL reads use matching live definitions and policies after runtime schema changes. Canonical mutation handlers enforce concrete Cedar authorization independently of transport middleware and additional operator policies; nested GraphQL relations also honor operator visibility restrictions.
Schema administration supports declared data-preserving renames, validates hierarchy and the exact Cedar policy bundle before writes, and refuses destructive changes without explicit opt-in. Runtime schema updates commit DDL, metadata, and integrity checks atomically before publishing the matching registry and policy snapshot. PostgreSQL relation constraints are consistent across creation, alteration, and legacy repair, with typed integrity errors. Unsupported tenancy transitions include a tested manual migration procedure.
Upgrade behavior:
serve --hostcontrols the actual listener, defaulting to loopback; help conceals secret environment values. PUT clears omitted writable optional fields while preserving protected fields; PATCH remains partial, and SQL Server merges supplied fields atomically without losing omitted values. Empty access grants are documented and diagnosed. Custom backends must implement atomic runtime schema changes. SurrealDB uses the corrected 3.3 storage engine and requires remote servers at 3.3 or newer. Builds use Rust 1.97.1. Release versions and upgrade notes are prepared for v0.45.0.Validation: all CI gates passed on
efe2fed: complete runtime/schema and PostgreSQL storage suites, live PostgreSQL HTTP authorization/concurrency tests, both CLI suites, SQL Server 2019/2022 integration, native Windows build, site end-to-end tests, CEL proofs, and all-target Clippy. Focused regressions also verify 512 competing conditional-write races, migration rollback, metadata escaping/error propagation, and the manual tenancy migration procedure.Fixes #162
Fixes #163
Fixes #164
Fixes #165
Fixes #166
Fixes #167
Fixes #168
Fixes #169
Fixes #170
Fixes #171
Fixes #172
Fixes #173
Fixes #174
Fixes #175
Fixes #176