Additive migration: nullable profiles.gender / chart_profiles.gender with a female/male CHECK, owner-only via existing table RLS, column grants mirroring the neighbouring birth columns (service_role for the account PATCH, no admin_runtime). Account PATCH/GET, people POST/PUT/GET, subject resolution and the consult route carry each person's own value; a people write only touches gender when the key is sent. DB test runs in the gate's DB job. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_017eEAG8HD3mm8gsKXgk8uU8
49 lines
2.1 KiB
PL/PgSQL
49 lines
2.1 KiB
PL/PgSQL
-- Optional gender for the household profile and every saved person
|
|
-- (TASK-consult-gender-optional-20260927). Consultation reads it to pick the
|
|
-- spouse significator on the marriage evidence card; empty means "not filled".
|
|
--
|
|
-- Additive only (AGENTS §7.6): two nullable columns with no default and no
|
|
-- backfill, a CHECK that only constrains the new column, and column grants
|
|
-- that mirror the neighbouring birth columns. The code deployed before this
|
|
-- migration never selects or writes `gender`, so the migrate-then-deploy
|
|
-- window is safe; rolling the application back leaves the column unused.
|
|
--
|
|
-- Privacy: same level as birth data. RLS stays table-level (owner only);
|
|
-- admin_runtime gets no grant, like birth_date.
|
|
begin;
|
|
|
|
alter table public.profiles
|
|
add column if not exists gender text;
|
|
|
|
alter table public.profiles
|
|
drop constraint if exists profiles_gender_check;
|
|
|
|
alter table public.profiles
|
|
add constraint profiles_gender_check
|
|
check (gender is null or gender in ('female', 'male'));
|
|
|
|
-- authenticated already has table-level SELECT on profiles (owner-only RLS).
|
|
grant update (gender) on table public.profiles to authenticated;
|
|
-- The account PATCH writes through service_role (BUG-600: a column without an
|
|
-- explicit service_role grant fails with "permission denied").
|
|
grant select (gender) on table public.profiles to service_role;
|
|
grant insert (gender) on table public.profiles to service_role;
|
|
grant update (gender) on table public.profiles to service_role;
|
|
|
|
alter table public.chart_profiles
|
|
add column if not exists gender text;
|
|
|
|
alter table public.chart_profiles
|
|
drop constraint if exists chart_profiles_gender_check;
|
|
|
|
alter table public.chart_profiles
|
|
add constraint chart_profiles_gender_check
|
|
check (gender is null or gender in ('female', 'male'));
|
|
|
|
-- authenticated already has table-level SELECT on chart_profiles (owner-only RLS);
|
|
-- insert / update are column grants, so the new column is listed explicitly.
|
|
grant insert (gender) on table public.chart_profiles to authenticated;
|
|
grant update (gender) on table public.chart_profiles to authenticated;
|
|
|
|
commit;
|