fix(result): enforce durable consent reference integrity - #273
Conversation
|
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (3)
Included review availability: Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughPostgreSQL 마이그레이션에 Rust 호환 참조 검증 함수와 CHECK 제약조건을 추가했습니다. 기존 제약조건을 새 규칙으로 재생성하고, 결과 스냅샷 참조와 동의 참조 배열의 무효 값을 검증하는 통합 테스트를 추가했습니다. Changes결과 스냅샷 참조 검증
Estimated code review effort: 4 (Complex) | ~45 minutes Merge Risk: 🟡 Moderate · up to The migration strengthens consent-reference validation, but a non-transactional failure during reapplication could leave result data without the existing reference checks. Merge should wait for a rollback-preserving migration approach or explicit owner acceptance of this bounded data-integrity risk. Sequence Diagram(s)sequenceDiagram
participant RustTests
participant Migration_0007
participant PostgreSQL
RustTests->>Migration_0007: 스키마 마이그레이션 적용
Migration_0007->>PostgreSQL: 검증 함수와 CHECK 제약조건 생성
RustTests->>PostgreSQL: 참조 및 동의 배열 삽입
PostgreSQL->>PostgreSQL: Unicode 참조 규칙 검증
PostgreSQL-->>RustTests: 유효한 값 저장 또는 CHECK 위반 반환
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Preserve the #273 durable result consent-reference integrity constraint and PostgreSQL regression contract on top of current protected main. The #258 Rust toolchain-refresh paths are disjoint, so this reconciliation retains both change sets without force-pushing or changing result semantics beyond the existing PR delta.
|
Fixed and pushed current head |
Why
ResultSnapshot::newrejects missing, malformed, and duplicate consent-snapshot references before they become immutable product result evidence. Protected-main PostgreSQL persistence only checked thatconsent_snapshot_refswas non-empty, so direct SQL, recovery tooling, or a damaged writer could persist NULL, blank, numeric-like, or duplicate consent identities that the domain cannot produce.TDD lineage
29bc60d3de887a56989a256939a5bc62873bff37: real PostgreSQL tests require NULL, blank, numeric-like, and duplicate consent references to fail closed and require migration reapplication to repair a weakened same-named constraint.1ed1e6a1c8a0da8a723f70bd6a5228c39528b4f2: add an immutable SQL validator and an ownedresult_snapshot_consent_refs_integrity_check; reapplication drops/recreates that constraint so existing product schemas are strengthened rather than only fresh installs.Boundary
This is result-evidence persistence hardening only. It does not change consent purpose semantics, scoring/numeric psychometrics, result calculation, cross-service ownership, or the existing non-empty consent requirement. The validator preserves the current persisted opaque-reference syntax; broader Unicode reference-parity work remains separate.
Verification required before merge
Exact-current-head Runtime CI, PostgreSQL contract tests, rustfmt/Clippy/rustdoc, exact owned line/branch coverage, Security/SAST/SBOM/provenance, zero valid unresolved findings, and qualifying independent non-author last-push review are required. Never self-approve or transfer evidence from another head.
Summary by CodeRabbit
supersedes_ref가 자기 자신을 참조하는 경우를 방지합니다.