docs(09): record approved review decisions and close UAT
This commit is contained in:
@@ -177,11 +177,11 @@ Verification ran in the main checkout (`workflow.use_worktrees` is `false`), not
|
||||
**Files modified:** `modules/cabana/tx_context.go` (new), `modules/cabana/crud.go`, `modules/cabana/relation.go`, `modules/cabana/crud_lifecycle_test.go`, `modules/cabana/README.md`, `docs/backend/admin-controllers.md`; fonoteka.go `plugins/golem15/fonoteka/controllers/albums_admin_controller.go`, `plugins/golem15/fonoteka/controllers/collections_admin_controller.go`, `plugins/golem15/fonoteka/controllers/request_db.go` (new), `plugins/golem15/fonoteka/admin_albums_test.go`
|
||||
**Applied fix:** cabana puts the write's transaction on the context inside every `lagoon.Transaction` callback and exports `cabana.TxFromContext(ctx)`. The hook and scope signatures are unchanged, so no plugin contract breaks. The Fonoteka album and collection hooks read through it via a small `requestDB` helper and fall back to the pool outside a transaction (the list). The new Fonoteka test limits the pool to one connection and creates and updates an album; it hangs (and fails after 20 s) without the fix.
|
||||
|
||||
## Decisions needed
|
||||
## Decisions (resolved 2026-10-01, approved by the user)
|
||||
|
||||
- **WR-11, unique index on `lower(email)` (not applied).** The suggestion adds a migration to `modules/lagoon/backend_admin_migrations.go`. Winter's `backend_users` has plain unique `login` and `email`; a functional unique index could make the migration fail on a copied table that holds two emails differing only in case, which D-01 says must copy straight in. The login-time ambiguity check and the `admin:create` check already close the practical hole, and an index would only add race protection. Decide whether to add the index, and whether to dedupe copied rows first.
|
||||
- **WR-03, single-record delete.** It is allowed whenever a form exists, not only when the list toolbar has `delete`, because the SPA's form screen always shows its own delete button (as in Winter). If delete should follow the toolbar too, the form schema needs a new field so the SPA can hide that button; that changes the admin API shape and OpenAPI.
|
||||
- **WR-17, deny versus wildcard.** Winter's merge does not let an exact-code deny remove a wildcard grant. If SummerCMS should be stricter than Winter here, say so and `applyUserPermissions` plus its tests change.
|
||||
- **WR-11, unique index on `lower(email)`: added** in `2da8112` (summercms.go). The new migration `202610010001_backend_users_email_ci_unique` creates `backend_users_email_lower_unique`. Rows copied from Winter are not changed automatically: when emails differ only in case, the migration refuses to run and names the clashing logins, so the operator changes or removes one and runs `migrate` again. Picking an admin account to drop is not something a migration should do. Tests: `TestBackendAdminEmailCaseInsensitiveUnique` and `TestBackendAdminEmailIndexRefusesCaseDuplicates`. Documented in `modules/lagoon/README.md` and `docs/backend/users-and-permissions.md`.
|
||||
- **WR-03, single-record delete: kept as Winter.** It stays allowed whenever a form exists, because the form screen's delete button matches Winter, and the admin API shape stays unchanged.
|
||||
- **WR-17, deny versus wildcard: kept as Winter.** An exact-code deny does not remove a wildcard grant, matching Winter's `getMergedPermissions`.
|
||||
|
||||
## Test results
|
||||
|
||||
|
||||
Reference in New Issue
Block a user