Skip to content

test(database): #351 group-assignment regression test is integration-tagged, may not run in default CI #546

Description

@cristim

Discovered while auditing PR #533 (which closes #351).

Two follow-ups from the #533 review. The PR's runtime behaviour correctly satisfies #351 (group_ids seeded on both INSERT paths, idempotent backfill via assignAdminGroupAndWarn, WARN on residual drift), so this is a hardening follow-up, not a regression of the fix itself.

  1. Regression test does not run in standard CI. The only test, TestEnsureAdminUser_GroupAssignment in internal/database/postgres/migrations/ensure_admin_user_test.go, carries //go:build integration and needs a running postgres container. A standard go test ./... run (without -tags integration) skips it entirely, so the fix(auth): bootstrap admin must be auto-assigned to the Administrators group (ensureAdminUser gap) #351 security-relevant invariant has no protection in the default CI pipeline. Confirm the CI workflow runs the integration suite; if it does not, either add an integration-test job or add a non-integration unit test that exercises the backfill SQL against an in-memory or mocked layer.

  2. Backfill lives in Go, not in a migration. Issue fix(auth): bootstrap admin must be auto-assigned to the Administrators group (ensureAdminUser gap) #351 acceptance criterion 2 asks for the backfill in migration 000024 (or an extension), idempotent. PR fix(auth): auto-assign bootstrap admin to Administrators group (closes #351) #533 instead backfills in assignAdminGroupAndWarn, invoked only when RunMigrations is called with a non-empty admin email. A DB restored from a backup, or migrated without ADMIN_EMAIL set, would not get the backfill applied to pre-existing drifted admin rows. A SQL-level idempotent backfill (in a new migration) would close that path. Decide whether the Go-level backfill is sufficient for the deployment model or whether a migration-level backfill is warranted.

Acceptance

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions