Skip to content

RC51.02C: Gate 1 auth/runtime parcial (PG16 Podman + MinhaCentral) - #385

Merged
devmnsoft merged 1 commit into
mainfrom
codex/rc51-02c-foundation-saas-industria-evolucao
Sep 10, 2026
Merged

devmnsoft merged 1 commit into
mainfrom
codex/rc51-02c-foundation-saas-industria-evolucao

Conversation

@devmnsoft

Copy link
Copy Markdown
Owner

Resumo

RC51.02C — Gate 1 auth/runtime parcial com evidência em PostgreSQL 16.15 via Podman/WSL e correções de baseline catalog-aware / shell autenticado.

Branch: codex/rc51-02c-foundation-saas-industria-evolucao (a partir de main dc7c1ac).
Commit: c6e74776 — fix(rc51): Gate 1 auth/runtime parcial e baseline catalog-aware.

PASS (Gate 1)

  • Apply vazio em PG16: 171 migrations
  • Reaplicação idempotente (“Já aplicada”): PASS
  • Swagger GET /swagger/v1/swagger.json: HTTP 200
  • Login e-mail / login / CPF / CNPJ → 302 /MinhaCentral
  • /MinhaCentral = 200
  • Logout (POST antiforgery) → 302 /Auth/Login; pós-logout /MinhaCentral → 302 login

Correções nesta RC

  • Baseline enterprise_tenant_mapping (includeInBaseline + scripts script_completo*)
  • Claims pontuais MatrizAcesso/Commercial → snapshot/serviço
  • Ícones sidebar (workflow etc.) + tamanhos 22/34; TagHelper com fallback
  • AtividadeRecenteViewModel materializável pelo Dapper

BLOCKED (Gate 1 incompleto)

  • Equivalência one-shot (script_completop.sql + compare-schema)
  • Isolamento de dois tenants
  • Upgrade legado formal

Não iniciado

  • Gates 2–5 (SaaS Admin, OP industrial, fatias Compras/Almoxarifado–Jurídico–Educação, backlog detalhado)
  • GED permanece por último

Próximo item

Fechar equivalência one-shot e isolamento de dois tenants em PG16; só então Gate 2.

Inclui enterprise_tenant_mapping no baseline, remove claims pontuais de
permissão, corrige ícones/MinhaCentral e registra evidência Podman PG16
com login HTTP; equivalência e dois tenants seguem BLOCKED.
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 10, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-10T20:16:23.610716Z c6e7477 PR opened
🔒 Security Review ✅ Completed 2026-09-10T20:17:26.789580Z c6e7477 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: c6e74776fc

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

throw new UnauthorizedAccessException("Usuário não resolvido.");
return new(tenantId, userId, User.HasClaim("permission", "comercial.clientes.dados_pessoais.visualizar"), HttpContext.TraceIdentifier);
var snapshot = HttpContext.RequestServices.GetRequiredService<IRequestAuthorizationSnapshot>();
var canViewPersonalData = snapshot.Current.HasPermission("comercial.clientes.dados_pessoais.visualizar");

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Honor cross-profile denies before exposing personal data

When one active profile grants this permission and another applicable profile denies it, RequestAuthorizationSnapshot still reports it as granted because AuthenticationRepository excludes only denies whose perfil_acesso_id equals the granting profile, whereas PersistentAuthorizationEvaluator gives every applicable deny precedence. Consequently, this flag becomes true and ObterClienteAsync returns unmasked personal data even though the authoritative policy denies access; use the evaluator here or make the snapshot preserve global deny precedence.

AGENTS.md reference: AGENTS.md:L14-L14

Useful? React with 👍 / 👎.

-- CHECKSUM_SHA256: 5de9eef9b5ef879f374093df3e78db27dd4528fb9e5badae9b5c59680642d0a7
-- ==================================================
create table if not exists sigov.enterprise_tenant_mapping (
id bigserial primary key,

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Correct the baseline PK to use identity

On a clean one-shot installation, the newly included baseline creates enterprise_tenant_mapping.id as bigserial, which is sequence-backed rather than the required bigint generated ... as identity. This now ships a nonconforming persistent schema in every synchronized baseline; introduce a corrective schema migration using the required identity form and regenerate the baselines.

AGENTS.md reference: AGENTS.md:L6-L6

Useful? React with 👍 / 👎.

@devmnsoft
devmnsoft merged commit 0644e69 into main Sep 10, 2026
35 of 42 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant