diff --git a/alembic/versions/0135_fix_schema_drifts.py b/alembic/versions/0135_fix_schema_drifts.py index ae44a80..9f2e7e3 100644 --- a/alembic/versions/0135_fix_schema_drifts.py +++ b/alembic/versions/0135_fix_schema_drifts.py @@ -22,33 +22,33 @@ def upgrade() -> None: op.execute("ALTER TABLE notifications ALTER COLUMN type TYPE VARCHAR(100);") op.execute("ALTER TABLE notification_preferences ALTER COLUMN type_key TYPE VARCHAR(100);") - # 2. Create missing table: forgejo_reported_errors - # Model: ReportedError(Base) — NO TenantMixin, Integer id - op.create_table( - "forgejo_reported_errors", - sa.Column("id", sa.Integer, primary_key=True, autoincrement=True), - sa.Column("dedup_key", sa.String(64), nullable=False, unique=True, index=True), - sa.Column("message", sa.Text, nullable=False), - sa.Column("stack", sa.Text, nullable=True), - sa.Column("forgejo_issue_number", sa.Integer, nullable=True), - sa.Column("reported_at", sa.DateTime(timezone=True), nullable=False, server_default=sa.text("now()")), - sa.Column("status", sa.String(20), nullable=False, server_default=sa.text("'reported'")), - ) - # No RLS — model has no tenant_id + # 2. Create missing table: forgejo_reported_errors (only if not exists) + op.execute(""" + CREATE TABLE IF NOT EXISTS forgejo_reported_errors ( + id SERIAL PRIMARY KEY, + dedup_key VARCHAR(64) NOT NULL UNIQUE, + message TEXT NOT NULL, + stack TEXT, + forgejo_issue_number INTEGER, + reported_at TIMESTAMPTZ DEFAULT now() NOT NULL, + status VARCHAR(20) NOT NULL DEFAULT 'reported' + ) + """) - # 3. Create missing table: pgp_keys - # Model: PgpKey(Base, TenantMixin) — UUID id, user_id, key_id, encrypted_private_key, public_key_armored - op.create_table( - "pgp_keys", - sa.Column("id", UUID(as_uuid=True), primary_key=True, server_default=sa.text("gen_random_uuid()")), - sa.Column("tenant_id", UUID(as_uuid=True), sa.ForeignKey("tenants.id", ondelete="CASCADE"), nullable=False), - sa.Column("user_id", UUID(as_uuid=True), nullable=False), - sa.Column("key_id", sa.String(255), nullable=False), - sa.Column("encrypted_private_key", sa.Text, nullable=False), - sa.Column("public_key_armored", sa.Text, nullable=False), - ) - op.create_index("ix_pgp_keys_user", "pgp_keys", ["user_id"]) + # 3. Create missing table: pgp_keys (only if not exists) + op.execute(""" + CREATE TABLE IF NOT EXISTS pgp_keys ( + id UUID DEFAULT gen_random_uuid() NOT NULL PRIMARY KEY, + tenant_id UUID NOT NULL REFERENCES tenants(id) ON DELETE CASCADE, + user_id UUID NOT NULL, + key_id VARCHAR(255) NOT NULL, + encrypted_private_key TEXT NOT NULL, + public_key_armored TEXT NOT NULL + ) + """) + op.execute("CREATE INDEX IF NOT EXISTS ix_pgp_keys_user ON pgp_keys (user_id);") op.execute("ALTER TABLE pgp_keys ENABLE ROW LEVEL SECURITY;") + op.execute("DROP POLICY IF EXISTS pgp_keys_tenant_isolation ON pgp_keys;") op.execute("CREATE POLICY pgp_keys_tenant_isolation ON pgp_keys USING (tenant_id::text = current_setting('app.current_tenant_id', true));")