feat(260805-fok): beide Mandanten-Entstehungspfade verdrahten + Startup-Reparatur
- TenantService.create ruft nach prisma.tenant.create ensureDefaultGroup auf; Fehler werden protokolliert, nicht propagiert (Muster aus UserService.create) - tenant.module.ts importiert GroupsModule (keine Zirkularitaet, wie UserModule bereits vormacht) - AdminSeedService.onApplicationBootstrap besteht jetzt aus zwei sequenziellen await-Schritten: seedAdmin() (bisheriger Rumpf, plus ensureDefaultGroup nach dem Tenant-Upsert und VOR user.create), dann ensureDefaultGroupsForAllTenants() als abschliessende Reparatur ueber ALLE Mandanten — laeuft unabhaengig von seedAdmin()s fruehen Rueckkehrpfaden (fehlende ENV / Admin existiert bereits) und ist je Mandant sowie insgesamt try/catch-gekapselt, blockiert den API-Start nie - Reparatur sitzt bewusst NICHT als eigener onApplicationBootstrap-Hook in GroupsModule (Ordering-Falle aus tender-scheduler.service.ts) - tenant.service.spec.ts, admin-seed.service.spec.ts (neu): Reihenfolge, beide fruehen Rueckkehrpfade, Fehlerisolation je Mandant, Idempotenz ueber zwei Bootstrap-Laeufe
This commit is contained in:
@@ -1,11 +1,27 @@
|
||||
import { Injectable, Logger, OnApplicationBootstrap } from '@nestjs/common';
|
||||
import { ConfigService } from '@nestjs/config';
|
||||
import * as argon2 from 'argon2';
|
||||
import { GroupsService } from '../groups/groups.service';
|
||||
import { PrismaService } from '../prisma/prisma.service';
|
||||
|
||||
/**
|
||||
* Creates the initial Super-Admin account from Docker ENV variables on first boot.
|
||||
* Per D-05, D-07, D-13.
|
||||
*
|
||||
* onApplicationBootstrap läuft in genau zwei sequenziellen await-Schritten:
|
||||
* erst seedAdmin(), danach ensureDefaultGroupsForAllTenants(). Diese
|
||||
* sequenzielle Reihenfolge — nicht Nests Hook-Reihenfolge über Module
|
||||
* hinweg — ist der Ordering-Garant. Die Reparatur sitzt bewusst NICHT als
|
||||
* eigener onApplicationBootstrap-Hook in GroupsModule: GroupsModule ist
|
||||
* eine Dependency von UserModule, seine eigenen Hooks liefen deshalb VOR
|
||||
* dem Admin-Seed und würden auf einer frischen Installation den noch gar
|
||||
* nicht existierenden Default-Mandanten übergehen — dieselbe Falle, die
|
||||
* tenders/tender-scheduler.service.ts für den DÖE-Poll-Config-Seed
|
||||
* ausführlich dokumentiert (onModuleInit-Reihenfolge zwischen Modulen ist
|
||||
* unspezifiziert, onApplicationBootstrap läuft garantiert nach jedem
|
||||
* onModuleInit). seedAdmin() bleibt bewusst UNgekapselt: schlägt der
|
||||
* Admin-Seed fehl, soll der Start weiterhin laut scheitern — bestehendes
|
||||
* Verhalten, hier nicht aufgeweicht.
|
||||
*/
|
||||
@Injectable()
|
||||
export class AdminSeedService implements OnApplicationBootstrap {
|
||||
@@ -14,9 +30,15 @@ export class AdminSeedService implements OnApplicationBootstrap {
|
||||
constructor(
|
||||
private prisma: PrismaService,
|
||||
private configService: ConfigService,
|
||||
private readonly groupsService: GroupsService,
|
||||
) {}
|
||||
|
||||
async onApplicationBootstrap() {
|
||||
await this.seedAdmin();
|
||||
await this.ensureDefaultGroupsForAllTenants();
|
||||
}
|
||||
|
||||
private async seedAdmin() {
|
||||
const username = this.configService
|
||||
.get<string>('TESSERA_ADMIN_USER')
|
||||
?.toLowerCase();
|
||||
@@ -49,6 +71,12 @@ export class AdminSeedService implements OnApplicationBootstrap {
|
||||
create: { name: 'Default', slug: 'default' },
|
||||
});
|
||||
|
||||
// Ensure the default group exists BEFORE the Super-Admin user is
|
||||
// created, so user.create's addUserToDefaultGroup path (D-11/D-12)
|
||||
// finds a marked default group to join instead of relying on the
|
||||
// repair below to backfill the membership afterwards.
|
||||
await this.groupsService.ensureDefaultGroup(tenant.id);
|
||||
|
||||
// Create Super-Admin user
|
||||
const passwordHash = await argon2.hash(password);
|
||||
await this.prisma.user.create({
|
||||
@@ -67,4 +95,50 @@ export class AdminSeedService implements OnApplicationBootstrap {
|
||||
`Admin user "${username}" seeded as SUPER_ADMIN in tenant "${tenant.slug}"`,
|
||||
);
|
||||
}
|
||||
|
||||
/**
|
||||
* One-time startup repair for installations that already exist without a
|
||||
* default group — e.g. a fresh database where migration
|
||||
* 20260804130130_add_groups_and_module_grants' backfill ran before any
|
||||
* tenant existed, or an install whose admin already exists so seedAdmin()
|
||||
* returned early without ever touching a tenant. Runs per-tenant in its
|
||||
* own try/catch and is additionally wrapped as a whole, so a failing
|
||||
* tenant.findMany or a single tenant's ensureDefaultGroup call can never
|
||||
* block the API from starting.
|
||||
*/
|
||||
private async ensureDefaultGroupsForAllTenants() {
|
||||
try {
|
||||
const tenants = await this.prisma.tenant.findMany({
|
||||
select: { id: true, slug: true },
|
||||
});
|
||||
|
||||
let repaired = 0;
|
||||
for (const tenant of tenants) {
|
||||
try {
|
||||
const group = await this.groupsService.ensureDefaultGroup(tenant.id);
|
||||
if (group !== null) {
|
||||
repaired += 1;
|
||||
}
|
||||
} catch (err) {
|
||||
this.logger.error(
|
||||
`Default-group repair failed for tenant "${tenant.slug}": ${
|
||||
err instanceof Error ? err.message : String(err)
|
||||
}`,
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
if (repaired > 0) {
|
||||
this.logger.warn(
|
||||
`Default-group repair created a default group for ${repaired} tenant(s) that had none`,
|
||||
);
|
||||
}
|
||||
} catch (err) {
|
||||
this.logger.error(
|
||||
`Default-group repair could not load tenants: ${
|
||||
err instanceof Error ? err.message : String(err)
|
||||
}`,
|
||||
);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user