Repository navigation
Corrige trigger de compatibilidade e preserva suspensão SaaS - #406
Conversation
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 7eb309636b
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| "name": "função SaaS contrato estrutural de projeção", | ||
| "sql": "select case when not exists(select 1 from pg_proc p join pg_namespace n on n.oid=p.pronamespace where n.nspname='sigov' and p.proname='fn_tenant_modulo_compatibilizar' and p.pronargs=0 and p.prorettype='trigger'::regtype and p.prosecdef=false and array_to_string(p.proconfig,',') like '%search_path=pg_catalog, sigov%') then 'objeto=sigov.fn_tenant_modulo_compatibilizar esperado=security invoker com search_path fixo obtido=privilégio ou resolução de schema divergente' end" |
There was a problem hiding this comment.
Keep correction-only probes off the earlier migration
On a fresh database, apply-migrations-manifest.ps1 executes every pending migration's probes immediately after that migration. When it reaches 20260910120000, the function created there has no fixed search_path, so this newly added p.proconfig probe fails and rolls back the transaction before 20260914130000 can install the definition being tested. Preserve the historical probe for 20260910120000 and validate this stricter contract only on the new corrective migration.
AGENTS.md reference: AGENTS.md:L11-L11
Useful? React with 👍 / 👎.
| create trigger trg_tenant_modulo_compatibilizar | ||
| after insert or update on sigov.tenant_modulo_contratado | ||
| for each row | ||
| execute function sigov.fn_tenant_modulo_compatibilizar(); |
There was a problem hiding this comment.
Backfill legacy entitlements after replacing the trigger
For the installations this migration explicitly repairs because the old trigger was missing, disabled, or divergent, replacing the trigger does not process existing canonical rows. A contract already marked SUSPENSO/INADIMPLENTE, or with an elapsed scheduled cancellation, can therefore retain tenant_modulo.habilitado=true; legacy consumers such as TenantContextSwitchRepository and AgroModuleRepository continue granting access until an unrelated update fires the new trigger. Reproject the existing tenant_modulo_contratado rows as part of this migration.
AGENTS.md reference: AGENTS.md:L14-L14
Useful? React with 👍 / 👎.
Motivation
sigov.tenant_modulo) preserve suspensões, inadimplência, cancelamento, expiração e limites de vigência conforme a autoridade canônicasigov.tenant_modulo_contratado.Description
database/postgres/migrations/20260914130000_corr_saas_compatibilidade_suspensao.sqlque recria a funçãosigov.fn_tenant_modulo_compatibilizar()(comsecurity invokereset search_path = pg_catalog, sigov) e cria o triggertrg_tenant_modulo_compatibilizargarantindo que a projeção preserve suspensão e vigência.database/postgres/migrations/manifest.jsoncom a nova entrada e substitui a probe textual frágil por um conjunto de probes estruturais que verificam existência na tabela correta, habilitação, eventos/momento/granularidade, assinatura/retorno da função esearch_path/privilegio.database/postgres/script_completo.sql,database/postgres/script_completo_dev.sql,database/script_completo.sql,script_completo.sql,script_completo_dev.sql,script_completop.sql) para incorporar a migration e compatibilidades.docs/adr/ADR-SaaS-Catalogo-Entitlements.md, e estende asserções emtests/Sigov.IntegrationTests/DatabaseMigrationRegressionTests.cspara validar as probes e a nova migration sem adicionar nova classe de teste.Testing
python3 -m json.tool database/postgres/migrations/manifest.jsonexecuted and passed to validate JSON manifest structure.VALIDATE_ONLY=true bash scripts/apply-migrations-manifest.sh(manifest/static validation) executed successfully, andbash -n scripts/apply-migrations-manifest.shreported no syntax errors.cmpbetween consolidated outputs) passed and the tracked-artifacts gate (scripts/check-tracked-artifacts.sh) passed.git diff --check) and conflict markers scan showed no problems; integration test source was updated to assert new probes but runtime .NET/Postgres execution was blocked in this environment.Notes on blocked items: build, runtime and behavioral verification could not be executed here because the container lacks the required tools: the .NET SDK (
dotnet), PostgreSQL client/server (psql), Docker and PowerShell for the official generator/CI flows are not available; those steps must run in CI (PostgreSQL 16) to fully validate trigger behavior, idempotence, and the end-to-end SaaS admin journeys.Codex Task