Skip to content

fix(nextly): a trusted batch update has a trusted path - #1801

Merged
mobeenabdullah merged 4 commits into
mainfrom
fix/bulk-update-honours-override-access
Sep 11, 2026
Merged

mobeenabdullah merged 4 commits into
mainfrom
fix/bulk-update-honours-override-access

Conversation

@mobeenabdullah

Copy link
Copy Markdown
Collaborator

What

updateEntries on CollectionEntryService and CollectionBulkService now takes overrideAccess, as createEntries has since D35. When set, the collection-level gate judges no user, the publish-transition pre-resolve is told, and each per-entry write skips access (the write's own params already carried the flag; it was never forwarded).

Why

A trusted batch update had no trusted path: a plugin's system-elevated batch update or a seed was judged as an anonymous caller at the gate and refused every row on a collection whose update rule wants a user. The create path took the flag; the update path was the same method shape without it. Tracker 110, ledger task:schema-bulk-update-override-access (claimed with --force as mechanical: the sibling method is the design).

Scope

The pooled updateEntries only, to match createEntries. Neither createEntriesInTransaction nor updateEntriesInTransaction takes the flag, and they stay alike.

Tests

bulk-update-override-access.integration.test.ts: a collection whose update rule wants a user; an elevated batch with no user updates the row, and the same batch without elevation is refused and leaves the row untouched (the control that keeps the flag from being a no-op). Against main's bulk service the elevated case fails. The three batch suites beside it pass.

Also: the pre-push hook refused my first push of this branch because the test file failed check-types under the tests tsconfig, which I had not run. The hook from #1781 doing what it was merged for.

Patch changeset, every package.

updateEntries takes overrideAccess as createEntries does: the collection
gate judges no user, the transition pre-resolve is told, and the per-entry
write already honoured it once forwarded.
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 11, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-11T15:13:03.394423Z 0249e9d Manual request
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@coderabbitai

coderabbitai Bot commented Sep 11, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 39 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 15c6179d-d322-4af7-8ba7-9520879267b7

📥 Commits

Reviewing files that changed from the base of the PR and between da323d5 and 0249e9d.

⛔ Files ignored due to path filters (1)
  • .changeset/a-trusted-batch-update-has-a-trusted-path.md is excluded by !.changeset/**
📒 Files selected for processing (3)
  • packages/nextly/src/domains/collections/__tests__/bulk-update-override-access.integration.test.ts
  • packages/nextly/src/domains/collections/services/collection-bulk-service.ts
  • packages/nextly/src/services/collections/collection-entry-service.ts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@mobeenabdullah

Copy link
Copy Markdown
Collaborator Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: b34b1f44eb

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

…ss are load-bearing

A refused publish rule and a field-level update rule, each behind a gate
that allows everyone, so dropping either forwarding step fails a case.
The docblock names real callers rather than a plugin method that does
not exist; that gap is a ledger task.
@pkg-pr-new

pkg-pr-new Bot commented Sep 11, 2026 •

Copy link
Copy Markdown

Open in StackBlitz

@nextlyhq/adapter-drizzle

npm i https://pkg.pr.new/@nextlyhq/adapter-drizzle@0249e9d

@nextlyhq/adapter-mysql

npm i https://pkg.pr.new/@nextlyhq/adapter-mysql@0249e9d

@nextlyhq/adapter-postgres

npm i https://pkg.pr.new/@nextlyhq/adapter-postgres@0249e9d

@nextlyhq/adapter-sqlite

npm i https://pkg.pr.new/@nextlyhq/adapter-sqlite@0249e9d

@nextlyhq/admin

npm i https://pkg.pr.new/@nextlyhq/admin@0249e9d

@nextlyhq/admin-css

npm i https://pkg.pr.new/@nextlyhq/admin-css@0249e9d

@nextlyhq/blocks-engine

npm i https://pkg.pr.new/@nextlyhq/blocks-engine@0249e9d

@nextlyhq/blocks-react

npm i https://pkg.pr.new/@nextlyhq/blocks-react@0249e9d

@nextlyhq/builder

npm i https://pkg.pr.new/@nextlyhq/builder@0249e9d

create-nextly-app

npm i https://pkg.pr.new/create-nextly-app@0249e9d

@nextlyhq/eslint-plugin

npm i https://pkg.pr.new/@nextlyhq/eslint-plugin@0249e9d

nextly

npm i https://pkg.pr.new/nextly@0249e9d

@nextlyhq/plugin-form-builder

npm i https://pkg.pr.new/@nextlyhq/plugin-form-builder@0249e9d

@nextlyhq/plugin-page-builder

npm i https://pkg.pr.new/@nextlyhq/plugin-page-builder@0249e9d

@nextlyhq/plugin-sdk

npm i https://pkg.pr.new/@nextlyhq/plugin-sdk@0249e9d

@nextlyhq/plugin-seo

npm i https://pkg.pr.new/@nextlyhq/plugin-seo@0249e9d

@nextlyhq/storage-s3

npm i https://pkg.pr.new/@nextlyhq/storage-s3@0249e9d

@nextlyhq/storage-uploadthing

npm i https://pkg.pr.new/@nextlyhq/storage-uploadthing@0249e9d

@nextlyhq/storage-vercel-blob

npm i https://pkg.pr.new/@nextlyhq/storage-vercel-blob@0249e9d

@nextlyhq/ui

npm i https://pkg.pr.new/@nextlyhq/ui@0249e9d

commit: 0249e9d

@github-actions

github-actions Bot commented Sep 11, 2026 •

Copy link
Copy Markdown
Contributor

Whole-Repository Code Hygiene Summary

Full dead-code, duplication, and complexity report for the PR branch as it stands now. Playground is excluded. Quality gate enforcement on introduced issues is performed by the Changed files job.

🌿 Fallow

Warning

Review needed

⚠️ 73 code issues · ⚠️ 692 clone groups · ⚠️ 1045 health findings

See inline review comments for per-finding details.

Code issues (73)
Category Count
Unused files 2
Unused exports 5
Unused dependencies 19
Unused devDependencies 6
Unresolved imports 2
Unlisted dependencies 1
Circular dependencies 38
Duplication (692 groups · 28940 lines · 4.1%)
Locations Lines Tokens
schemas/_dialect-bundles/mysql.relations.ts:40-134
schemas/_dialect-bundles/postgres.relations.ts:40-134
schemas/_dialect-bundles/sqlite.relations.ts:40-134
95 593
cli/commands/db-sync-demote.ts:70-75
cli/commands/db-sync-promote.ts:38-43
cli/commands/dev-build.ts:100-105
cli/commands/dev-build.ts:179-184
cli/commands/dev-build.ts:299-304
cli/commands/dev-build.ts:411-416
cli/commands/dev-build.ts:552-557
cli/commands/dev-server.ts:575-580
cli/commands/dev-server.ts:840-845
cli/commands/dev-server.ts:1143-1148
cli/commands/migrate-field-groups.ts:110-115
6 70
entries/EntryList/EntryTableSkeleton.tsx:74-98
collection/components/CollectionTableSkeleton.tsx:94-118
field-group/components/FieldGroupTableSkeleton.tsx:90-114
plugins/components/PluginsTableSkeleton.tsx:86-110
singles/components/SinglesTableSkeleton.tsx:77-101
src/components/table-skeleton.tsx:100-124
25 89
collections/config/validate-config.ts:380-433
field-groups/config/validate-field-group.ts:185-238
singles/config/validate-single.ts:190-243
54 152
dispatcher/handlers/collection-dispatcher.ts:925-967
field-groups/services/field-group-table-provisioning.ts:186-236
singles/services/reconcile-single-companion.ts:110-160
51 149

… and 687 more groups.

Across 422 files.

Complexity (1045 functions above threshold)
File Function Severity Cyclomatic Cognitive CRAP Lines
singles/services/single-mutation-service.ts:981 <arrow> critical 251 ! 324 ! 13859.2 ! 1625
collections/services/collection-mutation-service.ts:6264 <arrow> critical 174 ! 177 ! 6713.6 ! 1301
src/init/reload-config.ts:1319 applyReload critical 144 ! 228 ! 4623 ! 1433
shared/lib/entry-validation.ts:223 validateFieldValue critical 109 ! 157 ! 2675.3 ! 432
blocks-engine/src/measure-bytes.ts:646 surveyDocument critical 102 ! 250 ! 137.1 ! 658

5010 files, 76774 functions analyzed (thresholds: cyclomatic > 20, cognitive > 15, CRAP >= 30)

Codebase health

Metric Value
Maintainability 91.7 / 100
Avg complexity 1.8

Tip

Run fallow fix --dry-run to preview auto-fixes.
Add /** @public */ above exports to preserve them.

@mobeenabdullah

Copy link
Copy Markdown
Collaborator Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 2d3b82603d

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@mobeenabdullah

Copy link
Copy Markdown
Collaborator Author

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Bravo.

Reviewed commit: 0249e9de1e

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

@mobeenabdullah
mobeenabdullah merged commit 0121364 into main Sep 11, 2026
16 checks passed
@github-actions github-actions Bot added scope: core nextly type: docs Documentation only labels Sep 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

scope: core nextly type: docs Documentation only

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant