Repository navigation
RC51.02C: Gate 1 auth/runtime parcial (PG16 Podman + MinhaCentral) - #385
Conversation
Inclui enterprise_tenant_mapping no baseline, remove claims pontuais de permissão, corrige ícones/MinhaCentral e registra evidência Podman PG16 com login HTTP; equivalência e dois tenants seguem BLOCKED.
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: c6e74776fc
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| throw new UnauthorizedAccessException("Usuário não resolvido."); | ||
| return new(tenantId, userId, User.HasClaim("permission", "comercial.clientes.dados_pessoais.visualizar"), HttpContext.TraceIdentifier); | ||
| var snapshot = HttpContext.RequestServices.GetRequiredService<IRequestAuthorizationSnapshot>(); | ||
| var canViewPersonalData = snapshot.Current.HasPermission("comercial.clientes.dados_pessoais.visualizar"); |
There was a problem hiding this comment.
Honor cross-profile denies before exposing personal data
When one active profile grants this permission and another applicable profile denies it, RequestAuthorizationSnapshot still reports it as granted because AuthenticationRepository excludes only denies whose perfil_acesso_id equals the granting profile, whereas PersistentAuthorizationEvaluator gives every applicable deny precedence. Consequently, this flag becomes true and ObterClienteAsync returns unmasked personal data even though the authoritative policy denies access; use the evaluator here or make the snapshot preserve global deny precedence.
AGENTS.md reference: AGENTS.md:L14-L14
Useful? React with 👍 / 👎.
| -- CHECKSUM_SHA256: 5de9eef9b5ef879f374093df3e78db27dd4528fb9e5badae9b5c59680642d0a7 | ||
| -- ================================================== | ||
| create table if not exists sigov.enterprise_tenant_mapping ( | ||
| id bigserial primary key, |
There was a problem hiding this comment.
Correct the baseline PK to use identity
On a clean one-shot installation, the newly included baseline creates enterprise_tenant_mapping.id as bigserial, which is sequence-backed rather than the required bigint generated ... as identity. This now ships a nonconforming persistent schema in every synchronized baseline; introduce a corrective schema migration using the required identity form and regenerate the baselines.
AGENTS.md reference: AGENTS.md:L6-L6
Useful? React with 👍 / 👎.
Resumo
RC51.02C — Gate 1 auth/runtime parcial com evidência em PostgreSQL 16.15 via Podman/WSL e correções de baseline catalog-aware / shell autenticado.
Branch:
codex/rc51-02c-foundation-saas-industria-evolucao(a partir demaindc7c1ac).Commit:
c6e74776—fix(rc51): Gate 1 auth/runtime parcial e baseline catalog-aware.PASS (Gate 1)
GET /swagger/v1/swagger.json: HTTP 200/MinhaCentral/MinhaCentral= 200/Auth/Login; pós-logout/MinhaCentral→ 302 loginCorreções nesta RC
enterprise_tenant_mapping(includeInBaseline+ scriptsscript_completo*)workflowetc.) + tamanhos 22/34; TagHelper com fallbackAtividadeRecenteViewModelmaterializável pelo DapperBLOCKED (Gate 1 incompleto)
script_completop.sql+ compare-schema)Não iniciado
Próximo item
Fechar equivalência one-shot e isolamento de dois tenants em PG16; só então Gate 2.