-- QA-015: it_service_requests and its assignments used USING (true), so any -- signed-in user could read every office's requests, edit any request, assign -- staff, or approve (status -> scheduled) via the REST API. The app only hid -- these actions in the UI. Mirror the app's rules server-side: -- * admin/programmer/dispatcher/it_staff see and manage all requests -- * other users see their own requests and their offices' requests, and may -- edit only their own while draft/pending_approval -- * assigned staff may update the requests they're assigned to -- * only admins approve (enforced by trigger; RLS can't compare OLD/NEW) -- ----- it_service_requests ----- DROP POLICY IF EXISTS "Authenticated users can read it_service_requests" ON it_service_requests; DROP POLICY IF EXISTS "ISR: select" ON it_service_requests; CREATE POLICY "ISR: select" ON it_service_requests FOR SELECT TO authenticated USING ( creator_id = auth.uid() OR EXISTS (SELECT 1 FROM public.profiles p WHERE p.id = auth.uid() AND p.role IN ('admin','programmer','dispatcher','it_staff')) OR office_id IN (SELECT uo.office_id FROM public.user_offices uo WHERE uo.user_id = auth.uid()) ); DROP POLICY IF EXISTS "Authenticated users can update it_service_requests" ON it_service_requests; DROP POLICY IF EXISTS "ISR: update" ON it_service_requests; CREATE POLICY "ISR: update" ON it_service_requests FOR UPDATE TO authenticated USING ( EXISTS (SELECT 1 FROM public.profiles p WHERE p.id = auth.uid() AND p.role IN ('admin','programmer','dispatcher','it_staff')) OR (creator_id = auth.uid() AND status IN ('draft','pending_approval')) OR EXISTS (SELECT 1 FROM public.it_service_request_assignments a WHERE a.request_id = it_service_requests.id AND a.user_id = auth.uid()) ); -- WITH CHECK defaults to USING, so a creator can't move their own request -- out of draft/pending_approval (e.g. self-approve to 'scheduled'). CREATE OR REPLACE FUNCTION public.isr_guard_approval() RETURNS trigger LANGUAGE plpgsql SECURITY DEFINER SET search_path = public AS $$ BEGIN -- Only end-user requests are guarded; service-role jobs have no auth.uid(). IF auth.uid() IS NOT NULL AND (NEW.approved_by_user_id IS DISTINCT FROM OLD.approved_by_user_id OR (OLD.status = 'pending_approval' AND NEW.status NOT IN ('pending_approval', 'cancelled'))) AND NOT EXISTS (SELECT 1 FROM public.profiles WHERE id = auth.uid() AND role = 'admin') THEN RAISE EXCEPTION 'Only admins can approve IT service requests' USING ERRCODE = '42501'; END IF; RETURN NEW; END; $$; DROP TRIGGER IF EXISTS isr_guard_approval ON it_service_requests; CREATE TRIGGER isr_guard_approval BEFORE UPDATE ON it_service_requests FOR EACH ROW EXECUTE FUNCTION public.isr_guard_approval(); -- ----- it_service_request_assignments ----- -- Same people who may edit the request may assign/unassign staff. DROP POLICY IF EXISTS "Authenticated users can insert it_service_request_assignments" ON it_service_request_assignments; DROP POLICY IF EXISTS "ISR assignments: insert" ON it_service_request_assignments; CREATE POLICY "ISR assignments: insert" ON it_service_request_assignments FOR INSERT TO authenticated WITH CHECK ( EXISTS (SELECT 1 FROM public.profiles p WHERE p.id = auth.uid() AND p.role IN ('admin','programmer','dispatcher','it_staff')) OR EXISTS (SELECT 1 FROM public.it_service_requests r WHERE r.id = it_service_request_assignments.request_id AND r.creator_id = auth.uid() AND r.status IN ('draft','pending_approval')) ); DROP POLICY IF EXISTS "Authenticated users can delete it_service_request_assignments" ON it_service_request_assignments; DROP POLICY IF EXISTS "ISR assignments: delete" ON it_service_request_assignments; CREATE POLICY "ISR assignments: delete" ON it_service_request_assignments FOR DELETE TO authenticated USING ( EXISTS (SELECT 1 FROM public.profiles p WHERE p.id = auth.uid() AND p.role IN ('admin','programmer','dispatcher','it_staff')) OR EXISTS (SELECT 1 FROM public.it_service_requests r WHERE r.id = it_service_request_assignments.request_id AND r.creator_id = auth.uid() AND r.status IN ('draft','pending_approval')) ); -- ----- insert_it_service_request_with_number ----- -- Two problems surfaced after the SELECT policy above was tightened: -- 1. The number generator reads MAX(request_number) under the CALLER's RLS. -- A non-privileged creator now sees only their own/office rows, so MAX -- came back empty and it regenerated 'ISR-YYYY-0001', colliding with the -- unique constraint. It must count ALL rows -> SECURITY DEFINER. -- 2. Migration 20260604 added an 8-arg overload via CREATE OR REPLACE without -- dropping the original 7-arg function, leaving two overloads (PGRST203 on -- partial calls). Drop both signatures, then recreate one. DROP FUNCTION IF EXISTS insert_it_service_request_with_number(text, text[], uuid, uuid, text, uuid, text); DROP FUNCTION IF EXISTS insert_it_service_request_with_number(text, text[], uuid, uuid, uuid, text, uuid, text); CREATE FUNCTION insert_it_service_request_with_number( p_event_name text, p_services text[], p_creator_id uuid, p_id uuid DEFAULT NULL, p_office_id uuid DEFAULT NULL, p_requested_by text DEFAULT NULL, p_requested_by_user_id uuid DEFAULT NULL, p_status text DEFAULT 'draft' ) RETURNS TABLE(id uuid, request_number text) LANGUAGE plpgsql SECURITY DEFINER SET search_path = public AS $$ DECLARE v_seq int; v_id uuid; v_number text; v_creator uuid; v_status text; v_is_privileged boolean; BEGIN -- Under SECURITY DEFINER the INSERT bypasses the WITH CHECK creator guard, so -- pin the creator to the caller (a signed-in user can't forge someone else's -- ownership). Service-role callers (auth.uid() null) keep the passed value. v_creator := COALESCE(auth.uid(), p_creator_id); -- Alias the table: the RETURNS TABLE(id …) OUT column shadows an unqualified -- `id`, so reference profiles columns as p.id / p.role. SELECT EXISTS ( SELECT 1 FROM public.profiles p WHERE p.id = auth.uid() AND p.role IN ('admin','programmer','dispatcher','it_staff') ) INTO v_is_privileged; -- Non-privileged creators can only start a request in draft/pending_approval, -- so they can't create one already 'scheduled' to skip admin approval. v_status := p_status; IF auth.uid() IS NOT NULL AND NOT v_is_privileged AND v_status NOT IN ('draft','pending_approval') THEN v_status := 'pending_approval'; END IF; -- ponytail: MAX+1 is racy under concurrent creates (two callers can compute -- the same seq; the loser hits the unique constraint). Fine at this volume; -- switch to a per-year sequence if ISR creation ever goes concurrent. SELECT COALESCE(MAX( CAST(NULLIF(regexp_replace(r.request_number, '^ISR-\d{4}-', ''), '') AS int) ), 0) + 1 INTO v_seq FROM it_service_requests r WHERE r.request_number LIKE 'ISR-' || EXTRACT(YEAR FROM now())::text || '-%'; v_number := 'ISR-' || EXTRACT(YEAR FROM now())::text || '-' || LPAD(v_seq::text, 4, '0'); v_id := COALESCE(p_id, gen_random_uuid()); INSERT INTO it_service_requests ( id, request_number, event_name, services, creator_id, office_id, requested_by, requested_by_user_id, status ) VALUES ( v_id, v_number, p_event_name, p_services, v_creator, p_office_id, p_requested_by, p_requested_by_user_id, v_status ); RETURN QUERY SELECT v_id, v_number; END; $$;