Files
leocrm/alembic/versions/0136_fix_rls_tenant_id.py
T
Agent Zero a614ab337b
Check Cross-Plugin Imports / check (push) Has been cancelled
fix: schema drifts, RLS policies, wiki plugin, agent_loop syntax, test imports, frontend error handling
- Migration 0135: Fix 3 VARCHAR length drifts + 2 missing tables (forgejo_reported_errors, pgp_keys)
- Migration 0136: Fix 8 RLS policies referencing app.tenant_id instead of app.current_tenant_id
- wiki/__init__.py: Import WikiPlugin for discover_builtins()
- wiki/plugin.py: Fix SyntaxError (unterminated triple-quoted string)
- agent_loop.py: Fix SyntaxError (stray n character in dict)
- test_p1_6_dms_streaming.py: Fix import (CHUNK_SIZE removed, use _sanitize_filename only)
- conftest.py: Use create_all only (alembic conflicts with create_all in tests)
- frontend errorTypes.ts: asError() now handles nested detail objects
- AGENTS.md: Sub-agents forbidden in this project
- DAMAGE_REPORT.md + SCHEMA_DRIFTS.md: Complete damage assessment
- scripts/schema_drift_check.py: Schema drift checker tool

Tests: 24/24 Phase J + 12/12 Phase K = 36/36 passed
tsc: 0 errors
Frontend build: successful
2026-08-21 10:02:50 +02:00

50 lines
1.5 KiB
Python

"""Fix RLS policies — app.tenant_id → app.current_tenant_id.
8 RLS policies in production reference 'app.tenant_id' which doesn't exist
as a PostgreSQL parameter. The code uses 'app.current_tenant_id'.
This causes 500 errors on roles, sequences, wiki, approval_requests,
ai_decision_records, and automation_agent_run_steps.
Revision ID: 0136
Revises: 0135
Create Date: 2026-08-21
"""
from alembic import op
revision = "0136"
down_revision = "0135"
branch_labels = None
depends_on = None
# All 8 tables with broken RLS policies referencing app.tenant_id
TABLES_WITH_BAD_RLS = [
"ai_decision_records",
"approval_requests",
"automation_agent_run_steps",
"roles",
"sequences",
"wiki_articles",
"wiki_article_versions",
"wiki_categories",
]
def upgrade() -> None:
for table in TABLES_WITH_BAD_RLS:
# Drop old policy with app.tenant_id
op.execute(f"DROP POLICY IF EXISTS tenant_isolation ON {table};")
# Create new policy with app.current_tenant_id
op.execute(
f"CREATE POLICY tenant_isolation ON {table} "
f"USING (tenant_id::text = current_setting('app.current_tenant_id', true));"
)
def downgrade() -> None:
for table in TABLES_WITH_BAD_RLS:
op.execute(f"DROP POLICY IF EXISTS tenant_isolation ON {table};")
op.execute(
f"CREATE POLICY tenant_isolation ON {table} "
f"USING (tenant_id::text = current_setting('app.tenant_id', true));"
)