Skip to content

Corrige trigger de compatibilidade e preserva suspensão SaaS - #406

Merged
devmnsoft merged 1 commit into
mainfrom
codex/corrigir-falha-de-validacao-do-trigger-saas
Sep 14, 2026
Merged

devmnsoft merged 1 commit into
mainfrom
codex/corrigir-falha-de-validacao-do-trigger-saas

Conversation

@devmnsoft

Copy link
Copy Markdown
Owner

Motivation

  • Corrigir a falha de validação que reportava o trigger de compatibilidade SaaS como ausente/divergente devido a uma probe textual frágil.
  • Garantir que a projeção legada (sigov.tenant_modulo) preserve suspensões, inadimplência, cancelamento, expiração e limites de vigência conforme a autoridade canônica sigov.tenant_modulo_contratado.
  • Aplicar correção forward-only e idempotente que repara instalações em que o trigger/função estejam ausentes, desabilitados ou instalados de forma divergente.
  • Tornar as post-conditions/probes estruturais e robustas para evitar falso-positivos/falsos-negativos na validação de ledger.

Description

  • Adiciona a migration forward-only database/postgres/migrations/20260914130000_corr_saas_compatibilidade_suspensao.sql que recria a função sigov.fn_tenant_modulo_compatibilizar() (com security invoker e set search_path = pg_catalog, sigov) e cria o trigger trg_tenant_modulo_compatibilizar garantindo que a projeção preserve suspensão e vigência.
  • Atualiza o manifesto database/postgres/migrations/manifest.json com a nova entrada e substitui a probe textual frágil por um conjunto de probes estruturais que verificam existência na tabela correta, habilitação, eventos/momento/granularidade, assinatura/retorno da função e search_path/privilegio.
  • Regenera e sincroniza os consolidados obrigatórios (database/postgres/script_completo.sql, database/postgres/script_completo_dev.sql, database/script_completo.sql, script_completo.sql, script_completo_dev.sql, script_completop.sql) para incorporar a migration e compatibilidades.
  • Documenta a causa raiz, contrato canônico e fornece uma consulta somente-leitura recomendada para diagnóstico em docs/adr/ADR-SaaS-Catalogo-Entitlements.md, e estende asserções em tests/Sigov.IntegrationTests/DatabaseMigrationRegressionTests.cs para validar as probes e a nova migration sem adicionar nova classe de teste.

Testing

  • python3 -m json.tool database/postgres/migrations/manifest.json executed and passed to validate JSON manifest structure.
  • VALIDATE_ONLY=true bash scripts/apply-migrations-manifest.sh (manifest/static validation) executed successfully, and bash -n scripts/apply-migrations-manifest.sh reported no syntax errors.
  • Consolidation equivalence and byte-level checks for generated scripts (cmp between consolidated outputs) passed and the tracked-artifacts gate (scripts/check-tracked-artifacts.sh) passed.
  • Repository/static checks (git diff --check) and conflict markers scan showed no problems; integration test source was updated to assert new probes but runtime .NET/Postgres execution was blocked in this environment.

Notes on blocked items: build, runtime and behavioral verification could not be executed here because the container lacks the required tools: the .NET SDK (dotnet), PostgreSQL client/server (psql), Docker and PowerShell for the official generator/CI flows are not available; those steps must run in CI (PostgreSQL 16) to fully validate trigger behavior, idempotence, and the end-to-end SaaS admin journeys.


Codex Task

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-14T20:23:14.163475Z 7eb3096 PR opened
🔒 Security Review ✅ Completed 2026-09-14T20:23:07.656025Z 7eb3096 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@devmnsoft
devmnsoft merged commit 268dc59 into main Sep 14, 2026
9 of 14 checks passed

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 7eb309636b

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment on lines +2332 to +2333
"name": "função SaaS contrato estrutural de projeção",
"sql": "select case when not exists(select 1 from pg_proc p join pg_namespace n on n.oid=p.pronamespace where n.nspname='sigov' and p.proname='fn_tenant_modulo_compatibilizar' and p.pronargs=0 and p.prorettype='trigger'::regtype and p.prosecdef=false and array_to_string(p.proconfig,',') like '%search_path=pg_catalog, sigov%') then 'objeto=sigov.fn_tenant_modulo_compatibilizar esperado=security invoker com search_path fixo obtido=privilégio ou resolução de schema divergente' end"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Keep correction-only probes off the earlier migration

On a fresh database, apply-migrations-manifest.ps1 executes every pending migration's probes immediately after that migration. When it reaches 20260910120000, the function created there has no fixed search_path, so this newly added p.proconfig probe fails and rolls back the transaction before 20260914130000 can install the definition being tested. Preserve the historical probe for 20260910120000 and validate this stricter contract only on the new corrective migration.

AGENTS.md reference: AGENTS.md:L11-L11

Useful? React with 👍 / 👎.

Comment on lines +60 to +63
create trigger trg_tenant_modulo_compatibilizar
after insert or update on sigov.tenant_modulo_contratado
for each row
execute function sigov.fn_tenant_modulo_compatibilizar();

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Backfill legacy entitlements after replacing the trigger

For the installations this migration explicitly repairs because the old trigger was missing, disabled, or divergent, replacing the trigger does not process existing canonical rows. A contract already marked SUSPENSO/INADIMPLENTE, or with an elapsed scheduled cancellation, can therefore retain tenant_modulo.habilitado=true; legacy consumers such as TenantContextSwitchRepository and AgroModuleRepository continue granting access until an unrelated update fires the new trigger. Reproject the existing tenant_modulo_contratado rows as part of this migration.

AGENTS.md reference: AGENTS.md:L14-L14

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant