feat(16-01): apply Group.internalName/ldapObjectGuid migration to local DB

- Migration 20260806133916_add_group_internal_name_and_object_guid applied
  against the local Postgres container (baselined 24 prior migrations first
  — _prisma_migrations was missing, unrelated to this task's DDL)
- New describe block in migration-sql.spec.ts pins internalName,
  ldapObjectGuid, and the (tenantId, ldapObjectGuid) unique index
- Full API test suite green (40 files, 526 tests)
This commit is contained in:
2026-08-06 15:43:19 +02:00
parent 3523e43a13
commit 626e29659d
2 changed files with 36 additions and 0 deletions
@@ -0,0 +1,16 @@
-- D-04: internalName (vom Sync nie berührt, überschreibt die Anzeige wenn
-- gesetzt) und ldapObjectGuid (hex-kodierter objectGUID, rename-stabiler
-- Sync-Match-Key; ldapDn bleibt Anzeige-/Debug-Feld) auf Group. Beide
-- Spalten sind nullable, kein Datenverlust beim Anlegen. Der Unique-Index
-- folgt demselben NULL-ist-distinct-Muster wie Group_tenantId_ldapDn_key.
--
-- Keine eigene RLS-Anweisung: Group traegt die entsprechende Absicherung
-- bereits aus 20260804130918_groups_rls_policies; die Policy ist
-- spaltenunabhaengig und greift auf neue Spalten automatisch.
-- AlterTable
ALTER TABLE "Group" ADD COLUMN "internalName" TEXT,
ADD COLUMN "ldapObjectGuid" TEXT;
-- CreateIndex
CREATE UNIQUE INDEX "Group_tenantId_ldapObjectGuid_key" ON "Group"("tenantId", "ldapObjectGuid");
+20
View File
@@ -94,3 +94,23 @@ describe('groups_rls_policies migration.sql (T-15-11)', () => {
expect(directPolicyCount).toBe(2);
});
});
describe('add_group_internal_name_and_object_guid migration.sql (D-04)', () => {
const sql = readMigrationSql('_add_group_internal_name_and_object_guid');
it('fügt die Spalte internalName hinzu (D-04, sync-immuner Anzeigename)', () => {
expect(sql).toContain('internalName');
});
it('fügt die Spalte ldapObjectGuid hinzu (D-04, rename-stabiler Sync-Match-Key)', () => {
expect(sql).toContain('ldapObjectGuid');
});
it('legt einen Unique-Index auf (tenantId, ldapObjectGuid) an', () => {
expect(sql).toContain('"tenantId", "ldapObjectGuid"');
});
it('enthält keine eigene ENABLE/FORCE ROW LEVEL SECURITY-Anweisung (Group trägt sie bereits aus 20260804130918)', () => {
expect(sql).not.toMatch(/ALTER TABLE .* (ENABLE|FORCE) ROW LEVEL SECURITY/);
});
});