Repository navigation
feat(projects): enforce Project membership and retire the connector - #8590
mzxchandra wants to merge 96 commits into
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub. |
…ty-enforcement # Conflicts: # apps/sim/lib/projects/__integration__/foundation.integration.ts
|
@greptile Please re-review the current head and the individual thread evidence. Downstream import adaptations are explicitly recorded as required follow-up outside these PRs; no downstream completion is claimed. |
|
@cubic-dev-ai review this PR |
@mzxchandra I have started the AI code review. It will take a few minutes to complete. |
There was a problem hiding this comment.
No issues found across 171 files
Confidence score: 5/5
- Automated review surfaced no issues in the provided summaries.
- No files require special attention.
Heads up: you’ve reached your flex budget. Increase your flex budget or wait for usage to reset.
You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.
Turn on auto-fix | Re-trigger cubic
…t-entity-enforcement # Conflicts: # apps/sim/lib/billing/organizations/lock-order.test.ts # apps/sim/lib/projects/__integration__/foundation.integration.ts # apps/sim/lib/projects/environment-source.ts
|
@cubic-dev-ai review this PR |
@mzxchandra I have started the AI code review. It will take a few minutes to complete. |
There was a problem hiding this comment.
All reported issues were addressed across 172 files
Heads up: you’ve reached your flex budget. Increase your flex budget or wait for usage to reset.
You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.
Turn on auto-fix | Re-trigger cubic
…t-entity-enforcement # Conflicts: # apps/sim/lib/workspaces/admin-move.test.ts
|
@greptile Please re-review head 204e5f1. Repair queries now select only pre-contraction fields, the inbox fixture supplies mandatory Project membership, DDL timeout scopes are explicit, and child stdout is flushed. All 14 affected application integration tests and three focused database tests pass locally. |
|
@cubic-dev-ai review this PR |
@mzxchandra I have started the AI code review. It will take a few minutes to complete. |
There was a problem hiding this comment.
No issues found across 173 files
Confidence score: 5/5
- Automated review surfaced no issues in the provided summaries.
- No files require special attention.
Heads up: you’ve reached your flex budget. Increase your flex budget or wait for usage to reset.
You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.
Turn on auto-fix | Re-trigger cubic
|
@cubic-dev-ai review this PR |
@mzxchandra I have started the AI code review. It will take a few minutes to complete. |
There was a problem hiding this comment.
No issues found across 173 files
Confidence score: 5/5
- Automated review surfaced no issues in the provided summaries.
- No files require special attention.
Heads up: you’ve reached your flex budget. Increase your flex budget or wait for usage to reset.
You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.
Turn on auto-fix | Re-trigger cubic
Summary
Complete the migration to
workspace.project_idafter #8830 is deployed and incompatible membership activity has drained. Release-2 migrations run before application promotion, while release 1 serves traffic.0031_project_membershiprunner switches the checked singleton to column authority under the workspace barrier, then performs bounded, resumable assignment and reconciliation. SQL 0407 remains a placeholder because SQL migrations precede script migrations.workspace.project_id NOT NULLand its restrictive FK, then atomically remove bothproject_workspaceandproject_membership_rollout. The authority-aware feat(projects): move Project membership to the workspace column #8830 runtime remains the supported rollback version after contraction.Permanent enforcement
Replace all custom Project integrity triggers, trigger-specific advisory locks, deferred row-version dispatch, and
UPDATE project SET updated_at = updated_atwith native constraints:personaland IDs asorganization:<id>. The expression always yields a value, cannot be overridden by writers, and supports a composite organization-consistency FK without the nullable-FK loophole.Project non-emptiness and archive lifecycle remain application-owned. Keep existing application Project/lineage/edge/workspace locks and transactional workflow admission. Backfill still validates legacy lifecycle state once; it does not install permanent lifecycle triggers. Keep
project.updated_atas ordinary metadata, and exclude the new internal scope key from Project presentation.Migration trade-off and rollback
On PostgreSQL 16/17, adding stored generated columns rewrites the Project/workspace tables. This phase refuses busy tables and bounds each statement to five seconds; a timeout rolls it back before connector removal. This is a bounded blocking operation, not a zero-interruption column addition. Assess table size/capacity before deployment; do not silently extend its lock budget. Interrupted concurrent unique-index builds are repaired on replay.
Use the existing all-at-once traffic cutover and verify the concrete old membership operations/workers have drained. No new maintenance mechanism, dual writes, synchronization triggers, extra compatibility release, or Project-specific PostgreSQL16 CI is introduced. Once authority switches, keep column authority on retries/rollback and never deploy pre-#8830 code. Updated #8830 recognizes the completed schema without the marker, so rollback requires no retained rollout table. Fresh schema push creates no marker; migration replay recognizes completed contraction even when recording its receipt previously failed.
Validation
Focused local checks only; full CI is delegated to GitHub Actions.
Current marker-removal revision: 17 real PostgreSQL checks passed for authority switching, missing-marker refusal, contraction cleanup, failed-receipt replay, and fresh push/replay. The application creation/disconnect/organization-deletion/archive integration case also passed against the migrated database without the marker. DB package type-check, SQL migration safety, schema mock generation, and schema drift checks passed.
Earlier validation for the native-constraint implementation (before marker removal):
Local HTTP proof does not establish production drain completion or external-provider cleanup. GitHub Actions results for the new heads are separate from these local results. Downstream #8609/#8610 still need synchronization; the shared decision document records superseded trigger/lifecycle/CI requirements.
Current hosted status
Head
204e5f1facfixes repair lookups that selected generated columns before contraction, updates the newly merged inbox fixture to create mandatory Project membership, bounds short DDL separately from longer scans/index builds, and flushes child stdout before exit. All 9 operator-repair integration cases, 5 inbox integration cases, and 3 focused database cases passed locally. The two previously failing detach-repair cases were reproduced before the fix. The generated-column ordering review finding did not reproduce with the unchanged fresh-push fixture; its thread includes the passing database evidence.Both PRs are mergeable. CI and both reviewers are running on this head; no clean hosted result is claimed: https://github.com/simstudioai/sim/actions/runs/38085328277.
Latest archive-result correction
Head
88977f3931restores Project name to the explicit lookup used by workspace archival. The existing concurrent archive integration case now checks the returned Project identity and name: it fails before the correction and passes afterward. Both pre-contraction reviewed-detach repair cases still pass (3 focused database-backed cases total). CI and both reviews have restarted; results are pending.