forked from bai/curriculum-project-hub
feat: redesign Feishu project console
This commit is contained in:
@@ -0,0 +1,65 @@
|
||||
-- ADR-0017: roles are selected through the project-group control plane, not
|
||||
-- through slash-command names. Existing alpha Organizations keep draft as
|
||||
-- their configured default during migration; runtime code no longer hard-codes it.
|
||||
ALTER TABLE "OrganizationAgentRole"
|
||||
ADD COLUMN "isDefault" BOOLEAN NOT NULL DEFAULT false;
|
||||
|
||||
-- An Organization without any role was valid in the previous schema (the
|
||||
-- runtime failed closed later). Preserve the old alpha baseline so every
|
||||
-- existing binding can acquire a selected role during this migration.
|
||||
INSERT INTO "OrganizationAgentRole" (
|
||||
"id", "organizationId", "roleId", "label", "sortOrder", "isDefault", "updatedAt"
|
||||
)
|
||||
SELECT organization."id" || ':agent-role:draft', organization."id", 'draft', '草稿', 10, true, CURRENT_TIMESTAMP
|
||||
FROM "Organization" organization
|
||||
WHERE NOT EXISTS (
|
||||
SELECT 1 FROM "OrganizationAgentRole" role
|
||||
WHERE role."organizationId" = organization."id" AND role."disabledAt" IS NULL
|
||||
);
|
||||
|
||||
WITH ranked AS (
|
||||
SELECT "id", row_number() OVER (
|
||||
PARTITION BY "organizationId"
|
||||
ORDER BY CASE WHEN "roleId" = 'draft' THEN 0 ELSE 1 END, "sortOrder", "roleId", "id"
|
||||
) AS position
|
||||
FROM "OrganizationAgentRole"
|
||||
WHERE "disabledAt" IS NULL
|
||||
)
|
||||
UPDATE "OrganizationAgentRole" role
|
||||
SET "isDefault" = (ranked.position = 1)
|
||||
FROM ranked
|
||||
WHERE role."id" = ranked."id";
|
||||
|
||||
CREATE UNIQUE INDEX "OrganizationAgentRole_one_active_default_per_org"
|
||||
ON "OrganizationAgentRole"("organizationId")
|
||||
WHERE "isDefault" = true AND "disabledAt" IS NULL;
|
||||
|
||||
ALTER TABLE "ProjectGroupBinding"
|
||||
ADD COLUMN "selectedAgentRoleId" TEXT;
|
||||
|
||||
UPDATE "ProjectGroupBinding" binding
|
||||
SET "selectedAgentRoleId" = role."id"
|
||||
FROM "Project" project
|
||||
JOIN "OrganizationAgentRole" role
|
||||
ON role."organizationId" = project."organizationId"
|
||||
AND role."isDefault" = true
|
||||
AND role."disabledAt" IS NULL
|
||||
WHERE binding."projectId" = project."id";
|
||||
|
||||
DO $$
|
||||
BEGIN
|
||||
IF EXISTS (SELECT 1 FROM "ProjectGroupBinding" WHERE "selectedAgentRoleId" IS NULL) THEN
|
||||
RAISE EXCEPTION 'cannot migrate project-group bindings without an active default Agent role';
|
||||
END IF;
|
||||
END $$;
|
||||
|
||||
ALTER TABLE "ProjectGroupBinding"
|
||||
ALTER COLUMN "selectedAgentRoleId" SET NOT NULL;
|
||||
|
||||
CREATE INDEX "ProjectGroupBinding_selectedAgentRoleId_idx"
|
||||
ON "ProjectGroupBinding"("selectedAgentRoleId");
|
||||
|
||||
ALTER TABLE "ProjectGroupBinding"
|
||||
ADD CONSTRAINT "ProjectGroupBinding_selectedAgentRoleId_fkey"
|
||||
FOREIGN KEY ("selectedAgentRoleId") REFERENCES "OrganizationAgentRole"("id")
|
||||
ON DELETE RESTRICT ON UPDATE CASCADE;
|
||||
@@ -0,0 +1,41 @@
|
||||
-- ADR-0017 / ADR-0020: enforce the selected role's Organization at the
|
||||
-- database boundary. A role primary key alone cannot prove tenant scope.
|
||||
ALTER TABLE "ProjectGroupBinding"
|
||||
ADD COLUMN "organizationId" TEXT;
|
||||
|
||||
UPDATE "ProjectGroupBinding" binding
|
||||
SET "organizationId" = project."organizationId"
|
||||
FROM "Project" project
|
||||
WHERE project."id" = binding."projectId";
|
||||
|
||||
DO $$
|
||||
BEGIN
|
||||
IF EXISTS (SELECT 1 FROM "ProjectGroupBinding" WHERE "organizationId" IS NULL) THEN
|
||||
RAISE EXCEPTION 'cannot tenant-scope project-group binding without a project Organization';
|
||||
END IF;
|
||||
END $$;
|
||||
|
||||
ALTER TABLE "ProjectGroupBinding"
|
||||
ALTER COLUMN "organizationId" SET NOT NULL;
|
||||
|
||||
CREATE UNIQUE INDEX "Project_organizationId_id_key"
|
||||
ON "Project"("organizationId", "id");
|
||||
|
||||
ALTER TABLE "ProjectGroupBinding"
|
||||
DROP CONSTRAINT "ProjectGroupBinding_projectId_fkey",
|
||||
DROP CONSTRAINT "ProjectGroupBinding_selectedAgentRoleId_fkey";
|
||||
|
||||
ALTER TABLE "ProjectGroupBinding"
|
||||
ADD CONSTRAINT "ProjectGroupBinding_organizationId_fkey"
|
||||
FOREIGN KEY ("organizationId") REFERENCES "Organization"("id")
|
||||
ON DELETE CASCADE ON UPDATE CASCADE,
|
||||
ADD CONSTRAINT "ProjectGroupBinding_organizationId_projectId_fkey"
|
||||
FOREIGN KEY ("organizationId", "projectId") REFERENCES "Project"("organizationId", "id")
|
||||
ON DELETE CASCADE ON UPDATE CASCADE,
|
||||
ADD CONSTRAINT "ProjectGroupBinding_organizationId_selectedAgentRoleId_fkey"
|
||||
FOREIGN KEY ("organizationId", "selectedAgentRoleId")
|
||||
REFERENCES "OrganizationAgentRole"("organizationId", "id")
|
||||
ON DELETE RESTRICT ON UPDATE CASCADE;
|
||||
|
||||
CREATE INDEX "ProjectGroupBinding_organizationId_idx"
|
||||
ON "ProjectGroupBinding"("organizationId");
|
||||
@@ -0,0 +1,31 @@
|
||||
-- ADR-0017: once an Organization starts configuring roles, every committed
|
||||
-- state must contain exactly one active default. The deferred trigger permits
|
||||
-- an atomic default switch while rejecting zero-default transitions.
|
||||
CREATE FUNCTION cph_enforce_agent_role_default() RETURNS trigger
|
||||
LANGUAGE plpgsql AS $$
|
||||
DECLARE
|
||||
target_organization_id TEXT := COALESCE(NEW."organizationId", OLD."organizationId");
|
||||
active_default_count INTEGER;
|
||||
BEGIN
|
||||
IF NOT EXISTS (SELECT 1 FROM "Organization" WHERE "id" = target_organization_id) THEN
|
||||
RETURN NULL;
|
||||
END IF;
|
||||
|
||||
SELECT count(*) INTO active_default_count
|
||||
FROM "OrganizationAgentRole"
|
||||
WHERE "organizationId" = target_organization_id
|
||||
AND "isDefault" = true
|
||||
AND "disabledAt" IS NULL;
|
||||
|
||||
IF active_default_count <> 1 THEN
|
||||
RAISE EXCEPTION 'Organization % must have exactly one active default Agent role; found %',
|
||||
target_organization_id, active_default_count;
|
||||
END IF;
|
||||
RETURN NULL;
|
||||
END;
|
||||
$$;
|
||||
|
||||
CREATE CONSTRAINT TRIGGER "OrganizationAgentRole_exactly_one_active_default"
|
||||
AFTER INSERT OR UPDATE OR DELETE ON "OrganizationAgentRole"
|
||||
DEFERRABLE INITIALLY DEFERRED
|
||||
FOR EACH ROW EXECUTE FUNCTION cph_enforce_agent_role_default();
|
||||
@@ -0,0 +1,30 @@
|
||||
-- Organization-owned role configuration cannot be re-parented. Besides being
|
||||
-- a tenant boundary, immutability ensures the deferred default-role invariant
|
||||
-- checks the same Organization before and after an update.
|
||||
CREATE OR REPLACE FUNCTION cph_enforce_agent_role_default() RETURNS trigger
|
||||
LANGUAGE plpgsql AS $$
|
||||
DECLARE
|
||||
target_organization_id TEXT := COALESCE(NEW."organizationId", OLD."organizationId");
|
||||
active_default_count INTEGER;
|
||||
BEGIN
|
||||
IF TG_OP = 'UPDATE' AND NEW."organizationId" <> OLD."organizationId" THEN
|
||||
RAISE EXCEPTION 'OrganizationAgentRole.organizationId is immutable';
|
||||
END IF;
|
||||
|
||||
IF NOT EXISTS (SELECT 1 FROM "Organization" WHERE "id" = target_organization_id) THEN
|
||||
RETURN NULL;
|
||||
END IF;
|
||||
|
||||
SELECT count(*) INTO active_default_count
|
||||
FROM "OrganizationAgentRole"
|
||||
WHERE "organizationId" = target_organization_id
|
||||
AND "isDefault" = true
|
||||
AND "disabledAt" IS NULL;
|
||||
|
||||
IF active_default_count <> 1 THEN
|
||||
RAISE EXCEPTION 'Organization % must have exactly one active default Agent role; found %',
|
||||
target_organization_id, active_default_count;
|
||||
END IF;
|
||||
RETURN NULL;
|
||||
END;
|
||||
$$;
|
||||
@@ -0,0 +1,25 @@
|
||||
-- ADR-0017's default-role function is total over Organizations. Enforce the
|
||||
-- other side of the invariant when an Organization itself is created.
|
||||
CREATE FUNCTION cph_enforce_organization_default_role() RETURNS trigger
|
||||
LANGUAGE plpgsql AS $$
|
||||
DECLARE
|
||||
active_default_count INTEGER;
|
||||
BEGIN
|
||||
SELECT count(*) INTO active_default_count
|
||||
FROM "OrganizationAgentRole"
|
||||
WHERE "organizationId" = NEW."id"
|
||||
AND "isDefault" = true
|
||||
AND "disabledAt" IS NULL;
|
||||
|
||||
IF active_default_count <> 1 THEN
|
||||
RAISE EXCEPTION 'Organization % must have exactly one active default Agent role; found %',
|
||||
NEW."id", active_default_count;
|
||||
END IF;
|
||||
RETURN NULL;
|
||||
END;
|
||||
$$;
|
||||
|
||||
CREATE CONSTRAINT TRIGGER "Organization_requires_active_default_role"
|
||||
AFTER INSERT ON "Organization"
|
||||
DEFERRABLE INITIALLY DEFERRED
|
||||
FOR EACH ROW EXECUTE FUNCTION cph_enforce_organization_default_role();
|
||||
Reference in New Issue
Block a user