docs: BUG-1062 verified by gate run 2977; gender DB gap cleared

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_017eEAG8HD3mm8gsKXgk8uU8
This commit is contained in:
Jesse_Chen
2026-09-27 19:00:51 +08:00
co-authored by Claude Opus 5.5
parent 9aa37197a4
commit 037cd1aa1d
2 changed files with 3 additions and 3 deletions
+2 -2
View File
@@ -14326,7 +14326,7 @@
## BUG-1062 | 服务角色读不到「采用日期」三列:账户保存与本人报告 worker 在自托管 PostgreSQL 上会 42501
- 状态:investigating(静态证据确定;补授权迁移已随 `codex/consult-gender-optional-20260927` 提交,等门禁 DB job 与 staging 真实保存 smoke 后再改 resolved)
- 状态:resolved(门禁 run 2977 真实 PostgreSQL 通过:`service_role can select every profiles column the account PATCH and the report worker read`、`account PATCH accepts gender alone…`;全量 4204 / 0 fail / 0 skip;migrate run 2978、deploy run 2979,`/api/health` gitCommit = `9aa37197`)
- 首次发现 / 最近更新:2026-09-27 / 2026-09-27
- 影响面:`PATCH /api/account`(并发保护读、写后 RETURNING 读)、报告 worker 的本人资料读取(`loadSubjectBirth` → `ACCOUNT_BIRTH_SELECT`),两者都经 `createAdminSupabaseClient()` → `set local role service_role`。
- 现象(推断,未在真实库复现):新账户首次保存称呼 / 出生资料返回 `500 {"error":"暂时无法核对现有出生资料"}`;本人报告 worker 读资料失败按可重试处理。
@@ -14337,7 +14337,7 @@
- 防复发:静态合同把「服务角色读取的 profiles 列 ⊆ 迁移里授给 service_role 的 SELECT 列」锁住,以后加列漏授权会直接红,不再依赖人记得 BUG-600 的防复发句。
- 相关记录:BUG-039、BUG-600(同类列级授权缺口第三次)、BUG-1031(worker 改走 `loadSubjectBirth`)
- 复发自:BUG-600。当时的防复发只写成一句规则和针对 `ayanamsa` 的单列断言,没有通用合同,所以 `20260920020000` 加列时没有拦住。
- 修复版本:`codex/consult-gender-optional-20260927`(未推送、未部署)
- 修复版本:`3abae68f`(迁移 `20260927020000_profile_adopted_birth_service_role_select.sql`),随 `9aa37197` 部署 staging(run 2979)。
## BUG-1063 | 他人报告 worker 用服务角色读 `chart_profiles`,但服务角色对这张表没有任何权限