Files
photos/migrations/0003_multi_tenant.sql
T
nils 9da159aa0f
ci / docker (push) Successful in 9s
Multi-tenant: albums owned per photographer
- albums.owner_id (migration 0003, backfilled to the original user)
- owned::{album,photo,share} are the only admin data-access paths; another
  tenant's resources are indistinguishable from nonexistent (404)
- every admin handler threaded through ownership; each ALLOWED_EMAILS entry
  is now its own isolated workspace
- tenant-isolation integration test matrix (tests/tenancy.rs, env-gated on
  TEST_DATABASE_URL) driving the real router
2026-07-17 14:52:23 +02:00

11 lines
465 B
SQL

-- Albums gain an owner: the tenancy root. Photos, shares, ratings and tags
-- all hang off albums, so this single column scopes everything.
alter table albums add column owner_id uuid references users(id);
-- Existing albums belong to the instance's original photographer.
update albums set owner_id = (select id from users order by created_at limit 1);
alter table albums alter column owner_id set not null;
create index albums_owner_idx on albums (owner_id);