Files
tasq/supabase/migrations/20260924090000_isr_rls_hardening.sql
T
redz1029 3cb980b629 QA hardening: security RLS fixes, Flutter 3.47.5 upgrade, UI/validation fixes
Security — enforce write authorization server-side (was UI/RPC-only):
- it_service_requests RLS: block cross-office read/edit + self-approve (QA-015)
- pass_slips RLS: owner can complete but not self-approve (QA-046)
- swap_requests RLS: scope select/update to participants + admin (QA-047)
- storage: tighten it_service_attachments + task_attachments write/delete (QA-027)
- admin_user_management edge function: allow programmers to manage users (QA-016)

Fixes:
- workforce generator "uncovered shifts" false alarms (QA-043/044)
- network-map VLAN + New-location dialog validation, disabled-until-valid (QA-048)
- de-flake time-of-day-dependent dashboard metrics test (QA-045)

Toolchain:
- upgrade to Flutter 3.47.5 / Dart 3.13.4; font_awesome_flutter 11.0.0,
  flutter_quill 11.6.0, pdfrx 2.6.5; clear resulting deprecations (QA-002)

analyze clean; 139 tests pass; web build succeeds. Report + evidence in docs/qa/.

Note: also carries the in-progress Brick model cleanup already present in the
working tree. QA-001 (AI keys public in the build) is deferred by owner decision.

Co-Authored-By: claude-flow <ruv@ruv.net>
2026-09-26 11:52:16 +08:00

174 lines
7.6 KiB
PL/PgSQL

-- QA-015: it_service_requests and its assignments used USING (true), so any
-- signed-in user could read every office's requests, edit any request, assign
-- staff, or approve (status -> scheduled) via the REST API. The app only hid
-- these actions in the UI. Mirror the app's rules server-side:
-- * admin/programmer/dispatcher/it_staff see and manage all requests
-- * other users see their own requests and their offices' requests, and may
-- edit only their own while draft/pending_approval
-- * assigned staff may update the requests they're assigned to
-- * only admins approve (enforced by trigger; RLS can't compare OLD/NEW)
-- ----- it_service_requests -----
DROP POLICY IF EXISTS "Authenticated users can read it_service_requests" ON it_service_requests;
DROP POLICY IF EXISTS "ISR: select" ON it_service_requests;
CREATE POLICY "ISR: select" ON it_service_requests
FOR SELECT TO authenticated USING (
creator_id = auth.uid()
OR EXISTS (SELECT 1 FROM public.profiles p
WHERE p.id = auth.uid()
AND p.role IN ('admin','programmer','dispatcher','it_staff'))
OR office_id IN (SELECT uo.office_id FROM public.user_offices uo
WHERE uo.user_id = auth.uid())
);
DROP POLICY IF EXISTS "Authenticated users can update it_service_requests" ON it_service_requests;
DROP POLICY IF EXISTS "ISR: update" ON it_service_requests;
CREATE POLICY "ISR: update" ON it_service_requests
FOR UPDATE TO authenticated USING (
EXISTS (SELECT 1 FROM public.profiles p
WHERE p.id = auth.uid()
AND p.role IN ('admin','programmer','dispatcher','it_staff'))
OR (creator_id = auth.uid() AND status IN ('draft','pending_approval'))
OR EXISTS (SELECT 1 FROM public.it_service_request_assignments a
WHERE a.request_id = it_service_requests.id
AND a.user_id = auth.uid())
);
-- WITH CHECK defaults to USING, so a creator can't move their own request
-- out of draft/pending_approval (e.g. self-approve to 'scheduled').
CREATE OR REPLACE FUNCTION public.isr_guard_approval()
RETURNS trigger
LANGUAGE plpgsql
SECURITY DEFINER
SET search_path = public
AS $$
BEGIN
-- Only end-user requests are guarded; service-role jobs have no auth.uid().
IF auth.uid() IS NOT NULL
AND (NEW.approved_by_user_id IS DISTINCT FROM OLD.approved_by_user_id
OR (OLD.status = 'pending_approval'
AND NEW.status NOT IN ('pending_approval', 'cancelled')))
AND NOT EXISTS (SELECT 1 FROM public.profiles
WHERE id = auth.uid() AND role = 'admin') THEN
RAISE EXCEPTION 'Only admins can approve IT service requests'
USING ERRCODE = '42501';
END IF;
RETURN NEW;
END;
$$;
DROP TRIGGER IF EXISTS isr_guard_approval ON it_service_requests;
CREATE TRIGGER isr_guard_approval
BEFORE UPDATE ON it_service_requests
FOR EACH ROW EXECUTE FUNCTION public.isr_guard_approval();
-- ----- it_service_request_assignments -----
-- Same people who may edit the request may assign/unassign staff.
DROP POLICY IF EXISTS "Authenticated users can insert it_service_request_assignments" ON it_service_request_assignments;
DROP POLICY IF EXISTS "ISR assignments: insert" ON it_service_request_assignments;
CREATE POLICY "ISR assignments: insert" ON it_service_request_assignments
FOR INSERT TO authenticated WITH CHECK (
EXISTS (SELECT 1 FROM public.profiles p
WHERE p.id = auth.uid()
AND p.role IN ('admin','programmer','dispatcher','it_staff'))
OR EXISTS (SELECT 1 FROM public.it_service_requests r
WHERE r.id = it_service_request_assignments.request_id
AND r.creator_id = auth.uid()
AND r.status IN ('draft','pending_approval'))
);
DROP POLICY IF EXISTS "Authenticated users can delete it_service_request_assignments" ON it_service_request_assignments;
DROP POLICY IF EXISTS "ISR assignments: delete" ON it_service_request_assignments;
CREATE POLICY "ISR assignments: delete" ON it_service_request_assignments
FOR DELETE TO authenticated USING (
EXISTS (SELECT 1 FROM public.profiles p
WHERE p.id = auth.uid()
AND p.role IN ('admin','programmer','dispatcher','it_staff'))
OR EXISTS (SELECT 1 FROM public.it_service_requests r
WHERE r.id = it_service_request_assignments.request_id
AND r.creator_id = auth.uid()
AND r.status IN ('draft','pending_approval'))
);
-- ----- insert_it_service_request_with_number -----
-- Two problems surfaced after the SELECT policy above was tightened:
-- 1. The number generator reads MAX(request_number) under the CALLER's RLS.
-- A non-privileged creator now sees only their own/office rows, so MAX
-- came back empty and it regenerated 'ISR-YYYY-0001', colliding with the
-- unique constraint. It must count ALL rows -> SECURITY DEFINER.
-- 2. Migration 20260604 added an 8-arg overload via CREATE OR REPLACE without
-- dropping the original 7-arg function, leaving two overloads (PGRST203 on
-- partial calls). Drop both signatures, then recreate one.
DROP FUNCTION IF EXISTS insert_it_service_request_with_number(text, text[], uuid, uuid, text, uuid, text);
DROP FUNCTION IF EXISTS insert_it_service_request_with_number(text, text[], uuid, uuid, uuid, text, uuid, text);
CREATE FUNCTION insert_it_service_request_with_number(
p_event_name text,
p_services text[],
p_creator_id uuid,
p_id uuid DEFAULT NULL,
p_office_id uuid DEFAULT NULL,
p_requested_by text DEFAULT NULL,
p_requested_by_user_id uuid DEFAULT NULL,
p_status text DEFAULT 'draft'
)
RETURNS TABLE(id uuid, request_number text)
LANGUAGE plpgsql
SECURITY DEFINER
SET search_path = public
AS $$
DECLARE
v_seq int;
v_id uuid;
v_number text;
v_creator uuid;
v_status text;
v_is_privileged boolean;
BEGIN
-- Under SECURITY DEFINER the INSERT bypasses the WITH CHECK creator guard, so
-- pin the creator to the caller (a signed-in user can't forge someone else's
-- ownership). Service-role callers (auth.uid() null) keep the passed value.
v_creator := COALESCE(auth.uid(), p_creator_id);
-- Alias the table: the RETURNS TABLE(id …) OUT column shadows an unqualified
-- `id`, so reference profiles columns as p.id / p.role.
SELECT EXISTS (
SELECT 1 FROM public.profiles p
WHERE p.id = auth.uid()
AND p.role IN ('admin','programmer','dispatcher','it_staff')
) INTO v_is_privileged;
-- Non-privileged creators can only start a request in draft/pending_approval,
-- so they can't create one already 'scheduled' to skip admin approval.
v_status := p_status;
IF auth.uid() IS NOT NULL AND NOT v_is_privileged
AND v_status NOT IN ('draft','pending_approval') THEN
v_status := 'pending_approval';
END IF;
-- ponytail: MAX+1 is racy under concurrent creates (two callers can compute
-- the same seq; the loser hits the unique constraint). Fine at this volume;
-- switch to a per-year sequence if ISR creation ever goes concurrent.
SELECT COALESCE(MAX(
CAST(NULLIF(regexp_replace(r.request_number, '^ISR-\d{4}-', ''), '') AS int)
), 0) + 1
INTO v_seq
FROM it_service_requests r
WHERE r.request_number LIKE 'ISR-' || EXTRACT(YEAR FROM now())::text || '-%';
v_number := 'ISR-' || EXTRACT(YEAR FROM now())::text || '-' || LPAD(v_seq::text, 4, '0');
v_id := COALESCE(p_id, gen_random_uuid());
INSERT INTO it_service_requests (
id, request_number, event_name, services,
creator_id, office_id, requested_by, requested_by_user_id, status
)
VALUES (
v_id, v_number, p_event_name, p_services,
v_creator, p_office_id, p_requested_by, p_requested_by_user_id, v_status
);
RETURN QUERY SELECT v_id, v_number;
END;
$$;