diff --git a/apps/api/prisma/migrations/20260806133916_add_group_internal_name_and_object_guid/migration.sql b/apps/api/prisma/migrations/20260806133916_add_group_internal_name_and_object_guid/migration.sql new file mode 100644 index 0000000..88a19e1 --- /dev/null +++ b/apps/api/prisma/migrations/20260806133916_add_group_internal_name_and_object_guid/migration.sql @@ -0,0 +1,16 @@ +-- D-04: internalName (vom Sync nie berührt, überschreibt die Anzeige wenn +-- gesetzt) und ldapObjectGuid (hex-kodierter objectGUID, rename-stabiler +-- Sync-Match-Key; ldapDn bleibt Anzeige-/Debug-Feld) auf Group. Beide +-- Spalten sind nullable, kein Datenverlust beim Anlegen. Der Unique-Index +-- folgt demselben NULL-ist-distinct-Muster wie Group_tenantId_ldapDn_key. +-- +-- Keine eigene RLS-Anweisung: Group traegt die entsprechende Absicherung +-- bereits aus 20260804130918_groups_rls_policies; die Policy ist +-- spaltenunabhaengig und greift auf neue Spalten automatisch. + +-- AlterTable +ALTER TABLE "Group" ADD COLUMN "internalName" TEXT, +ADD COLUMN "ldapObjectGuid" TEXT; + +-- CreateIndex +CREATE UNIQUE INDEX "Group_tenantId_ldapObjectGuid_key" ON "Group"("tenantId", "ldapObjectGuid"); diff --git a/apps/api/src/groups/migration-sql.spec.ts b/apps/api/src/groups/migration-sql.spec.ts index 033554d..84443ff 100644 --- a/apps/api/src/groups/migration-sql.spec.ts +++ b/apps/api/src/groups/migration-sql.spec.ts @@ -94,3 +94,23 @@ describe('groups_rls_policies migration.sql (T-15-11)', () => { expect(directPolicyCount).toBe(2); }); }); + +describe('add_group_internal_name_and_object_guid migration.sql (D-04)', () => { + const sql = readMigrationSql('_add_group_internal_name_and_object_guid'); + + it('fügt die Spalte internalName hinzu (D-04, sync-immuner Anzeigename)', () => { + expect(sql).toContain('internalName'); + }); + + it('fügt die Spalte ldapObjectGuid hinzu (D-04, rename-stabiler Sync-Match-Key)', () => { + expect(sql).toContain('ldapObjectGuid'); + }); + + it('legt einen Unique-Index auf (tenantId, ldapObjectGuid) an', () => { + expect(sql).toContain('"tenantId", "ldapObjectGuid"'); + }); + + it('enthält keine eigene ENABLE/FORCE ROW LEVEL SECURITY-Anweisung (Group trägt sie bereits aus 20260804130918)', () => { + expect(sql).not.toMatch(/ALTER TABLE .* (ENABLE|FORCE) ROW LEVEL SECURITY/); + }); +});