Skip to content

Complete native PostgreSQL and SQLite repositories - #129

Open
arvindh123 wants to merge 4 commits into
mainfrom
codex/complete-db-repositories
Open

arvindh123 wants to merge 4 commits into
mainfrom
codex/complete-db-repositories

Conversation

@arvindh123

@arvindh123 arvindh123 commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Closes #126. Completes the PostgreSQL/SQLite repository migration started in #119 in this single follow-up PR.

All production database operations now use typed domain operations and private native PostgreSQL/SQLite adapters. Business validation, authorization evaluation, transaction orchestration, cache barriers, and audit/outbox behavior stay shared. The runtime SQL translator and generic query compatibility API are removed; test fixtures supply explicit SQL for each backend.

  • Port identity, credentials/session/email/OAuth/signing-key storage, tenants, authorization/guardrails/listings, PKI, bootstrap, audit/outbox, cleanup, custom endpoints, and runtime queries.
  • Reuse one canonical grant expansion and scope/ceiling implementation per backend. Preserve caller-owned transactions, tenant/entity lock ordering, SQLite writer coordination, and PKI retry savepoints.
  • Fix nullable resource sorting in both directions with deterministic pagination. Add regressions for actual resource/outbox rollback, nested savepoint recovery, JSON semantic parity, and resource/entity revisions.
  • Preserve PostgreSQL refresh replay revocation under concurrent exchange and post-commit audit writes: use an entity guard compatible with audit foreign-key locks, with a deterministic regression.
  • Enforce the native storage boundary and migration pairing/schema parity. Preserve applied migrations and public API contracts. Update developer guidance and the persistent, single-process SQLite quick start.

The environment example includes a PostgreSQL host URL and port, SQLite URL alternatives, pool options, and admin/encryption guidance, with the current Make/Compose limitations explained. Both URL examples parse with Atom's dotenvy parser; Docker Compose configuration validation also passes.

The UI CI audit exposed GHSA-vcvr-r3jv-pc5j in the existing Next.js pin. This PR also updates Next.js to 16.3.6; frozen install, lint, all 116 UI tests, production build, and the high-severity production audit pass (one moderate advisory remains).

Validation (completed locally on the submitted tree):

  • All 74 test binaries compiled; the 72 included binaries were run on each backend, plus PostgreSQL SoftHSM recovery (145 successful suite executions). Shared unit/integration tests use fresh PostgreSQL and SQLite databases, serialized per binary with isolated Redis. Includes cache invalidation, credentials/refresh/email flows, authorization/listing/ceiling parity, bootstrap, tenant/identity lifecycle, object coordination, single-connection transactions, rollback/outbox/audit failure, sorting, search, and SQLite ownership/durability/restart tests.
  • PKI suites on both backends, including GlobalSign EST v1.0.7 interoperability and SoftHSM PKCS#11; PostgreSQL SoftHSM backup/restore signing recovery.
  • Live SQLite server startup/migrations, admin login, GraphQL create/update, second-process ownership rejection, and restart with persisted data, sessions, and signing keys.
  • cargo fmt --all --check, cargo clippy --locked -- -D warnings, database boundary/schema parity, frozen v1 contracts and their 12 gate tests, vendored proto check, and generated GraphQL schema comparison.

CI covers Rust tests on both database backends, PKI recovery and smoke, UI, documentation, and API/contracts. The Checks tab shows the latest run.

Coverage limits are explicit: the two live AMQP suites (m27_live_amqp_delivery, m28_amqp_mtls_local_principal) compile but were not executed because their external broker/mTLS setup is not provisioned, matching existing CI exclusions. PostgreSQL lock-observation cases (three object-coordination cases, two entity-authorization cases, and the audit foreign-key lock regression), the process-replacement test, and synthetic PKI serial-collision injection remain PostgreSQL-specific. SQLite is covered by its writer/ownership, concurrent mutation, restart, and shared savepoint regressions; these PostgreSQL-specific skips are not claimed as SQLite passes. SoftHSM backup recovery is verified on PostgreSQL; the provider path runs on both backends.

SQLite-to-PostgreSQL data transfer is outside this issue: changing DATABASE_URL selects a backend and does not move existing data. No applied migrations are changed.

Move all remaining storage behind typed domain operations with private native adapters. Remove runtime SQL translation and preserve transaction, authorization and outbox behavior. Add sorting, rollback, savepoint and JSON parity regressions.

Closes #126
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Deploying with  Cloudflare Workers  Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

Status Name Latest Commit Preview URL Updated (UTC)
✅ Deployment successful!
View logs
atom-docs 7bb780a Commit Preview URL

Branch Preview URL
Sep 30 2026, 10:12 PM

Correct the explicit SQLite audit fixture SQL and update Next.js to 16.3.6 after CI reported GHSA-vcvr-r3jv-pc5j. UI frozen install, lint, 116 tests, build, and high-severity production audit pass.
Remove the remaining PostgreSQL-only wording from the introduction to match the native PostgreSQL/SQLite implementation.
@arvindh123
arvindh123 marked this pull request as ready for review September 30, 2026 22:50
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-30T22:55:22.941695Z 69ad0ce Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

Add the host DATABASE_URL, PostgreSQL port, SQLite alternatives, pool options, and administrator/encryption guidance. Explain the current Make and Compose backend selection behavior. Both URL examples parse with dotenvy, and Compose configuration validation passes.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Complete PostgreSQL/SQLite repository migration and review fixes in one PR

1 participant