Skip to content

People PostgreSQL port must detach validated mutation commands before callbacks #230

Description

@seonghobae

Finding and retained repair

Canonical owner is #64. Direct PostgresPeopleMutationPort.create_* previously validated exact frozen commands but kept the same caller-owned object across authorization, connection/cursor callbacks, SQL, audit, and idempotency. Test-first 2064a52… made a connection callback rewrite Position Organization identity; production e4cab11d32f22dc40841acbc9cf86c082bb25f67 imported dataclasses.replace and detaches a fresh exact command immediately after the adapter exact-type gate. The detached command is the only persistence authority thereafter. Fresh CodeRabbit review of exact e4cab11… found no defect in that ordering.

Current successor

#64 is now exact 9771be6d65bef77408cd5ad1ae316f0a8d8fb5e3. Later #229 adds pre-port result-target authority; #231 adds a separate application-side command snapshot before purpose-bound authorization for generic mutations and confirmed hire. Neither supersedes #230. Current #231 production touches only mutations.py and hire.py; postgres_mutations.py remains unchanged from the reviewed #230 implementation.

Current #64 workflows are Foundation 33943808189, Security 33943808260, SAST 33943808200, and CodeQL PR 33943808117; Foundation job 101246125948 is queued before checkout with no assigned runner. No current-head hosted GREEN or qualifying approval is claimed.

Keep #230 open until a verified successor carrying the adapter repair reaches protected truth. Do not weaken authorization, remove callback regressions, copy #65 source, force-push, destructively rebase, self-approve, use routine administrator bypass, or transfer predecessor merge evidence.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions