diff --git a/BLOCKED.md b/BLOCKED.md index 295bee42..2e5eefb5 100644 --- a/BLOCKED.md +++ b/BLOCKED.md @@ -2,7 +2,7 @@ ## TASK-consult-gender-optional:真实 PostgreSQL 测试、登录态真机与模型输出待验(2026-09-27) -- 本机无 Docker:`npm run test:db` 未跑。本单新增 `frontend/tests/database-profile-gender.test.ts`(两条,本机 docker unavailable 跳过),覆盖新列、CHECK、RLS、授权与真实路由读写;BUG-1062 的补授权也由其中的账户 PATCH 用例在真实库上证实。结果以门禁 DB job 为准(run 号待推送后补记)。替代证据:迁移源文本合同(`profile-gender-20260927.test.ts`)与 service_role 授权静态合同(`profile-service-role-grants-20260927.test.ts`)已跑通。 +- ~~本机无 Docker:`npm run test:db` 未跑。本单新增 `frontend/tests/database-profile-gender.test.ts`(两条,本机 docker unavailable 跳过),覆盖新列、CHECK、RLS、授权与真实路由读写;BUG-1062 的补授权也由其中的账户 PATCH 用例在真实库上证实。结果以门禁 DB job 为准(run 号待推送后补记)。替代证据:迁移源文本合同(`profile-gender-20260927.test.ts`)与 service_role 授权静态合同(`profile-service-role-grants-20260927.test.ts`)已跑通。~~ → 已解除:门禁 run 2977 真实 PostgreSQL 通过(`gender migration is additive…`、`service_role can select every profiles column…`),全量 4204 / 0 fail / 0 skip。 - 无受控登录账号与模型凭据:界面只在本地 `next start` + Chrome 无头、临时 harness 页与虚构人物上截图验过;真实账户保存与婚恋回答取法按 `docs/testing/consult-gender-optional-20260927.md` 待产品走。 - 未部署。 diff --git a/docs/BUG_HISTORY.md b/docs/BUG_HISTORY.md index 48591c13..1d82d1de 100644 --- a/docs/BUG_HISTORY.md +++ b/docs/BUG_HISTORY.md @@ -14326,7 +14326,7 @@ ## BUG-1062 | 服务角色读不到「采用日期」三列:账户保存与本人报告 worker 在自托管 PostgreSQL 上会 42501 -- 状态:investigating(静态证据确定;补授权迁移已随 `codex/consult-gender-optional-20260927` 提交,等门禁 DB job 与 staging 真实保存 smoke 后再改 resolved) +- 状态:resolved(门禁 run 2977 真实 PostgreSQL 通过:`service_role can select every profiles column the account PATCH and the report worker read`、`account PATCH accepts gender alone…`;全量 4204 / 0 fail / 0 skip;migrate run 2978、deploy run 2979,`/api/health` gitCommit = `9aa37197`) - 首次发现 / 最近更新:2026-09-27 / 2026-09-27 - 影响面:`PATCH /api/account`(并发保护读、写后 RETURNING 读)、报告 worker 的本人资料读取(`loadSubjectBirth` → `ACCOUNT_BIRTH_SELECT`),两者都经 `createAdminSupabaseClient()` → `set local role service_role`。 - 现象(推断,未在真实库复现):新账户首次保存称呼 / 出生资料返回 `500 {"error":"暂时无法核对现有出生资料"}`;本人报告 worker 读资料失败按可重试处理。 @@ -14337,7 +14337,7 @@ - 防复发:静态合同把「服务角色读取的 profiles 列 ⊆ 迁移里授给 service_role 的 SELECT 列」锁住,以后加列漏授权会直接红,不再依赖人记得 BUG-600 的防复发句。 - 相关记录:BUG-039、BUG-600(同类列级授权缺口第三次)、BUG-1031(worker 改走 `loadSubjectBirth`) - 复发自:BUG-600。当时的防复发只写成一句规则和针对 `ayanamsa` 的单列断言,没有通用合同,所以 `20260920020000` 加列时没有拦住。 -- 修复版本:`codex/consult-gender-optional-20260927`(未推送、未部署) +- 修复版本:`3abae68f`(迁移 `20260927020000_profile_adopted_birth_service_role_select.sql`),随 `9aa37197` 部署 staging(run 2979)。 ## BUG-1063 | 他人报告 worker 用服务角色读 `chart_profiles`,但服务角色对这张表没有任何权限