Skip to content

fix: secure tenant writes and schema migrations for v0.45.0 - #177

Merged
rrrodzilla merged 77 commits into
mainfrom
fix/all-outstanding-issues
Sep 25, 2026
Merged

rrrodzilla merged 77 commits into
mainfrom
fix/all-outstanding-issues

Conversation

@rrrodzilla

@rrrodzilla rrrodzilla commented Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

This change fixes all fifteen open issues covering tenant isolation, write authorization, migration safety, and CLI configuration. Tenant checks follow schema annotations, legacy tenant roots stay isolated, invitations validate tenant scope, and members cannot move records across tenants. Field authorization filters caller input before rules and hooks. Defaults, owner values, and audit values precede required validation; REST and GraphQL share the write pipeline. GraphQL reads use matching live definitions and policies after runtime schema changes. Canonical mutation handlers enforce concrete Cedar authorization independently of transport middleware and additional operator policies; nested GraphQL relations also honor operator visibility restrictions.

Schema administration supports declared data-preserving renames, validates hierarchy and the exact Cedar policy bundle before writes, and refuses destructive changes without explicit opt-in. Runtime schema updates commit DDL, metadata, and integrity checks atomically before publishing the matching registry and policy snapshot. PostgreSQL relation constraints are consistent across creation, alteration, and legacy repair, with typed integrity errors. Unsupported tenancy transitions include a tested manual migration procedure.

Upgrade behavior: serve --host controls the actual listener, defaulting to loopback; help conceals secret environment values. PUT clears omitted writable optional fields while preserving protected fields; PATCH remains partial, and SQL Server merges supplied fields atomically without losing omitted values. Empty access grants are documented and diagnosed. Custom backends must implement atomic runtime schema changes. SurrealDB uses the corrected 3.3 storage engine and requires remote servers at 3.3 or newer. Builds use Rust 1.97.1. Release versions and upgrade notes are prepared for v0.45.0.

Validation: all CI gates passed on efe2fed: complete runtime/schema and PostgreSQL storage suites, live PostgreSQL HTTP authorization/concurrency tests, both CLI suites, SQL Server 2019/2022 integration, native Windows build, site end-to-end tests, CEL proofs, and all-target Clippy. Focused regressions also verify 512 competing conditional-write races, migration rollback, metadata escaping/error propagation, and the manual tenancy migration procedure.

Fixes #162
Fixes #163
Fixes #164
Fixes #165
Fixes #166
Fixes #167
Fixes #168
Fixes #169
Fixes #170
Fixes #171
Fixes #172
Fixes #173
Fixes #174
Fixes #175
Fixes #176

@rrrodzilla rrrodzilla changed the title fix: close tenant, write, migration, and CLI safety gaps fix: secure tenant writes and schema migrations for v0.45.0 Sep 24, 2026
@rrrodzilla
rrrodzilla marked this pull request as ready for review September 25, 2026 00:58
@rrrodzilla
rrrodzilla merged commit 10ec403 into main Sep 25, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment