Repository navigation
Conversation
…kfOrgId names accepted on the KF endpoints
tefkah
marked this pull request as ready for review
October 6, 2026 15:04
Member
Author
|
Superseded by #3691, which drops kfOrgId entirely instead of making it nullable and renaming it. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Ahead of the kf-console cutover (kf-console replaces kf-auth as PubPub's OIDC provider). The console creates no personal org at sign-up, so someone who signs up after cutover has no orgs, and if
2026_06_15_makeKfOrgIdNotNullhas been run, their community insert fails. The model, the API schema, the server insert and the create form already treatkfOrgIdas optional; only that constraint blocks them.tools/migrations/2026_10_05_makeKfOrgIdNullable.js:updrops NOT NULL (safe whether or not the old migration ran, idempotent);downrestores it, refusing while NULLs exist.2026_06_15_makeKfOrgIdNotNullupnow throws "superseded" so it isn't run by mistake.kfOrgIdis kept only if the user belongs to that org (perfetchUserOrgs); otherwise, or if the lookup fails, the community is created with NULL. Users with no orgs never trigger the lookup.kfOrgIdis the account a community is billed to, staff-set, NULL until assigned.kfOrgId→kfAccountId(old terminology; in the console these are accounts). New migration2026_10_05_renameKfOrgIdToKfAccountId.jsrenames the column and both indexes (communities_kf_org_id_idxand the sync-madecommunities_kf_org_id), reversible. Model, schemas, create/transfer paths, client and copy ("KF Account") follow. The model no longer declares@Index:sequelize.sync()runs before migrations and would try to index a column that doesn't exist yet; the migrations own the index./api/kf/summaryand/api/kf/billing/usageacceptkf_account_idand stillkf_org_id(kf-console and Hubs call?kf_org_id=); transfer acceptskfAccountIdand stillkfOrgId. The IdP's orgs claim,/api/internal/users/:id/orgsand/api/kf/my-orgsare the console's contract and keep their names.Run order:
pnpm tools migrate --name 2026_10_05_makeKfOrgIdNullable, then--name 2026_10_05_renameKfOrgIdToKfAccountId, at deploy (the new code selectskfAccountId). Roll back in reverse with--down.Checked:
pnpm run check, biome on touched files,server/community/__tests__/api.test.ts(10/10), the newserver/kf/__tests__/api.test.ts(14/14 together), and both new migrations up and down against a local test database (from a NOT NULL, double-indexed starting state, data kept).Needs, before the cutover:
makeKfOrgIdNotNullbeen run on prod (and duqduq)? Either waymakeKfOrgIdNullableshould run before cutover.kfOrgId? Today nothing lets them (transfer requires membership in the target org). One option: add it to the superadmin-only update fields inserver/community/permissions.ts.kfOrgIdare invisible to/api/kf/summaryand billing usage — who sees the unassigned list?fetchUserOrgshas no timeout (unlike the other auth-server calls); worthfetchWithTimeout.