Repository navigation
fix(server): backport role backfill migrations to the apps/server tree - #2814
Merged
Merged
Conversation
The three role backfills (20260907170000_backfill_project_roles, 20260908155700_add_security_role, 20260929130657_add_security_admin_role) only existed in apps/server-nestjs, but the production prestart deploys from apps/server/src/prisma/migrations, so existing instances never received them. Port the three migrations verbatim under the same names: identical SQL means a database already backfilled via the nestjs tree is untouched (anti-joins are no-ops) and both trees converge on the same AdminRole id. Closes #2812 Co-authored-by: Automata <automata@shikanime.studio> Signed-off-by: William Phetsinorath <william.phetsinorath-open@interieur.gouv.fr> Change-Id: I05da2a441ea12222afc741a48e0772aa6a6a6964
shikanime
marked this pull request as draft
October 5, 2026 09:56
shikanime
marked this pull request as ready for review
October 5, 2026 09:57
shikanime
enabled auto-merge
October 5, 2026 10:06
|
iliesmrf
approved these changes
Oct 5, 2026
StephaneTrebel
requested changes
Oct 5, 2026
Collaborator
There was a problem hiding this comment.
Le report est strictement identique aux migrations NestJS et la CI actuellement exécutée est verte. Je demande néanmoins des modifications : le test de déploiement complet explicitement requis par l’issue est absent, et la branche diverge de main de deux commits ; elle doit être rebasée puis revalidée sur la tête actuelle
StephaneTrebel
self-requested a review
October 5, 2026 11:54
StephaneTrebel
approved these changes
Oct 5, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

0 New Issues
0 Fixed Issues
0 Accepted Issues
No data about coverage (55.60% Estimated after merge)
Pourquoi
Le chemin de déploiement en production exécute
prestart→db:deploy→prisma migrate deploydepuisapps/server/src/prisma/migrations. Les trois backfills de rôles n'existaient que dans l'arbreapps/server-nestjs: les instances montées de version depuis une base antérieure à v9.26 n'ont jamais reçu le rôle Sécurité ni le rôle admin Sécurité Plateforme.Quoi
Report verbatim des trois migrations depuis
apps/server-nestjs, sous les mêmes noms horodatés :20260907170000_backfill_project_roles(🐛 [BUG] - Des projets existants n'ont aucun rôle projet (backfill des rôles système) #2684)20260908155700_add_security_role(💡 [REQUEST] - Ajout du rôle Sécurité au système de rôles projet #2676)20260929130657_add_security_admin_role(💡 [REQUEST] - Ajout du rôle Sécurité au système de rôles admin #2792)Le SQL identique dans les deux arbres est délibéré : les anti-joins rendent toute double application no-op, et les deux arbres convergent sur le même id
AdminRole. Une base déjà backfillée via l'arbre nestjs reste intacte.Validation sur un PostgreSQL 16 jetable, chaîne complète
prisma migrate deploydepuisapps/server(70 migrations dont les trois reports) : base vierge OK ; simulation de montée de version (les trois migrations retirées de_prisma_migrations, deux projets sans rôles seedés) → chaque projet reçoit les 5 rôlessystem:managedavec les permissions attendues (2 / 984 / 784 / 768 / 832) et le rôle adminSécurité Plateformeavec l'id487450e6-3265-4df2-8581-8e39b0cecc5d; second déploiement :No pending migrations to apply, aucun doublon.Références
Closes #2812