From 626e29659d0563184f459806e598792b2f16dbc9 Mon Sep 17 00:00:00 2001 From: Schalli Date: Thu, 6 Aug 2026 15:43:19 +0200 Subject: [PATCH] feat(16-01): apply Group.internalName/ldapObjectGuid migration to local DB MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - Migration 20260806133916_add_group_internal_name_and_object_guid applied against the local Postgres container (baselined 24 prior migrations first — _prisma_migrations was missing, unrelated to this task's DDL) - New describe block in migration-sql.spec.ts pins internalName, ldapObjectGuid, and the (tenantId, ldapObjectGuid) unique index - Full API test suite green (40 files, 526 tests) --- .../migration.sql | 16 +++++++++++++++ apps/api/src/groups/migration-sql.spec.ts | 20 +++++++++++++++++++ 2 files changed, 36 insertions(+) create mode 100644 apps/api/prisma/migrations/20260806133916_add_group_internal_name_and_object_guid/migration.sql diff --git a/apps/api/prisma/migrations/20260806133916_add_group_internal_name_and_object_guid/migration.sql b/apps/api/prisma/migrations/20260806133916_add_group_internal_name_and_object_guid/migration.sql new file mode 100644 index 0000000..88a19e1 --- /dev/null +++ b/apps/api/prisma/migrations/20260806133916_add_group_internal_name_and_object_guid/migration.sql @@ -0,0 +1,16 @@ +-- D-04: internalName (vom Sync nie berührt, überschreibt die Anzeige wenn +-- gesetzt) und ldapObjectGuid (hex-kodierter objectGUID, rename-stabiler +-- Sync-Match-Key; ldapDn bleibt Anzeige-/Debug-Feld) auf Group. Beide +-- Spalten sind nullable, kein Datenverlust beim Anlegen. Der Unique-Index +-- folgt demselben NULL-ist-distinct-Muster wie Group_tenantId_ldapDn_key. +-- +-- Keine eigene RLS-Anweisung: Group traegt die entsprechende Absicherung +-- bereits aus 20260804130918_groups_rls_policies; die Policy ist +-- spaltenunabhaengig und greift auf neue Spalten automatisch. + +-- AlterTable +ALTER TABLE "Group" ADD COLUMN "internalName" TEXT, +ADD COLUMN "ldapObjectGuid" TEXT; + +-- CreateIndex +CREATE UNIQUE INDEX "Group_tenantId_ldapObjectGuid_key" ON "Group"("tenantId", "ldapObjectGuid"); diff --git a/apps/api/src/groups/migration-sql.spec.ts b/apps/api/src/groups/migration-sql.spec.ts index 033554d..84443ff 100644 --- a/apps/api/src/groups/migration-sql.spec.ts +++ b/apps/api/src/groups/migration-sql.spec.ts @@ -94,3 +94,23 @@ describe('groups_rls_policies migration.sql (T-15-11)', () => { expect(directPolicyCount).toBe(2); }); }); + +describe('add_group_internal_name_and_object_guid migration.sql (D-04)', () => { + const sql = readMigrationSql('_add_group_internal_name_and_object_guid'); + + it('fügt die Spalte internalName hinzu (D-04, sync-immuner Anzeigename)', () => { + expect(sql).toContain('internalName'); + }); + + it('fügt die Spalte ldapObjectGuid hinzu (D-04, rename-stabiler Sync-Match-Key)', () => { + expect(sql).toContain('ldapObjectGuid'); + }); + + it('legt einen Unique-Index auf (tenantId, ldapObjectGuid) an', () => { + expect(sql).toContain('"tenantId", "ldapObjectGuid"'); + }); + + it('enthält keine eigene ENABLE/FORCE ROW LEVEL SECURITY-Anweisung (Group trägt sie bereits aus 20260804130918)', () => { + expect(sql).not.toMatch(/ALTER TABLE .* (ENABLE|FORCE) ROW LEVEL SECURITY/); + }); +});