docs: BUG-1062 verified by gate run 2977; gender DB gap cleared
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017eEAG8HD3mm8gsKXgk8uU8
This commit is contained in:
co-authored by
Claude Opus 5.5
parent
9aa37197a4
commit
037cd1aa1d
+1
-1
@@ -2,7 +2,7 @@
|
||||
|
||||
## TASK-consult-gender-optional:真实 PostgreSQL 测试、登录态真机与模型输出待验(2026-09-27)
|
||||
|
||||
- 本机无 Docker:`npm run test:db` 未跑。本单新增 `frontend/tests/database-profile-gender.test.ts`(两条,本机 docker unavailable 跳过),覆盖新列、CHECK、RLS、授权与真实路由读写;BUG-1062 的补授权也由其中的账户 PATCH 用例在真实库上证实。结果以门禁 DB job 为准(run 号待推送后补记)。替代证据:迁移源文本合同(`profile-gender-20260927.test.ts`)与 service_role 授权静态合同(`profile-service-role-grants-20260927.test.ts`)已跑通。
|
||||
- ~~本机无 Docker:`npm run test:db` 未跑。本单新增 `frontend/tests/database-profile-gender.test.ts`(两条,本机 docker unavailable 跳过),覆盖新列、CHECK、RLS、授权与真实路由读写;BUG-1062 的补授权也由其中的账户 PATCH 用例在真实库上证实。结果以门禁 DB job 为准(run 号待推送后补记)。替代证据:迁移源文本合同(`profile-gender-20260927.test.ts`)与 service_role 授权静态合同(`profile-service-role-grants-20260927.test.ts`)已跑通。~~ → 已解除:门禁 run 2977 真实 PostgreSQL 通过(`gender migration is additive…`、`service_role can select every profiles column…`),全量 4204 / 0 fail / 0 skip。
|
||||
- 无受控登录账号与模型凭据:界面只在本地 `next start` + Chrome 无头、临时 harness 页与虚构人物上截图验过;真实账户保存与婚恋回答取法按 `docs/testing/consult-gender-optional-20260927.md` 待产品走。
|
||||
- 未部署。
|
||||
|
||||
|
||||
+2
-2
@@ -14326,7 +14326,7 @@
|
||||
|
||||
## BUG-1062 | 服务角色读不到「采用日期」三列:账户保存与本人报告 worker 在自托管 PostgreSQL 上会 42501
|
||||
|
||||
- 状态:investigating(静态证据确定;补授权迁移已随 `codex/consult-gender-optional-20260927` 提交,等门禁 DB job 与 staging 真实保存 smoke 后再改 resolved)
|
||||
- 状态:resolved(门禁 run 2977 真实 PostgreSQL 通过:`service_role can select every profiles column the account PATCH and the report worker read`、`account PATCH accepts gender alone…`;全量 4204 / 0 fail / 0 skip;migrate run 2978、deploy run 2979,`/api/health` gitCommit = `9aa37197`)
|
||||
- 首次发现 / 最近更新:2026-09-27 / 2026-09-27
|
||||
- 影响面:`PATCH /api/account`(并发保护读、写后 RETURNING 读)、报告 worker 的本人资料读取(`loadSubjectBirth` → `ACCOUNT_BIRTH_SELECT`),两者都经 `createAdminSupabaseClient()` → `set local role service_role`。
|
||||
- 现象(推断,未在真实库复现):新账户首次保存称呼 / 出生资料返回 `500 {"error":"暂时无法核对现有出生资料"}`;本人报告 worker 读资料失败按可重试处理。
|
||||
@@ -14337,7 +14337,7 @@
|
||||
- 防复发:静态合同把「服务角色读取的 profiles 列 ⊆ 迁移里授给 service_role 的 SELECT 列」锁住,以后加列漏授权会直接红,不再依赖人记得 BUG-600 的防复发句。
|
||||
- 相关记录:BUG-039、BUG-600(同类列级授权缺口第三次)、BUG-1031(worker 改走 `loadSubjectBirth`)
|
||||
- 复发自:BUG-600。当时的防复发只写成一句规则和针对 `ayanamsa` 的单列断言,没有通用合同,所以 `20260920020000` 加列时没有拦住。
|
||||
- 修复版本:`codex/consult-gender-optional-20260927`(未推送、未部署)
|
||||
- 修复版本:`3abae68f`(迁移 `20260927020000_profile_adopted_birth_service_role_select.sql`),随 `9aa37197` 部署 staging(run 2979)。
|
||||
|
||||
## BUG-1063 | 他人报告 worker 用服务角色读 `chart_profiles`,但服务角色对这张表没有任何权限
|
||||
|
||||
|
||||
Reference in New Issue
Block a user