[Performance review] Query current case eligibility without tenant-wide grant lists #7
Closed
opened 2026-09-08 10:24:52 +02:00 by zemion
·
2 comments
No Branch/Tag Specified
Labels
Clear labels
area/api
area/auth
area/db
area/devex
area/docs
area/governance
area/marketing
area/migrations
area/module-system
area/rbac
area/release
area/security
area/tenancy
area/webui
audit/complexity
audit/duplication
audit/false-positive
audit/needs-design
audit/quick-fix
audit/structural
codex/needs-human
codex/ready
module/access
module/addresses
module/admin
module/appointments
module/approvals
module/audit
module/calendar
module/campaign
module/cases
module/committee
module/connectors
module/core
module/dashboard
module/dataflow
module/datasources
module/decisions
module/dist-lists
module/dms
module/docs
module/encryption
module/erp
module/evaluation
module/files
module/fit-connect
module/forms
module/forms-runtime
module/helpdesk
module/identity
module/identity-trust
module/idm
module/ledger
module/mail
module/mandates
module/notifications
module/ops
module/organizations
module/parties
module/payments
module/permits
module/policy
module/poll
module/portal
module/postbox
module/projects
module/quick-access
module/records
module/reporting
module/risk-compliance
module/scheduling
module/search
module/services
module/tasks
module/templates
module/tenancy
module/tickets
module/views
module/voting
module/wiki
module/workflow
module/workflow-engine
module/xoev
module/xrechnung
module/xta-osci
source/backlog-import
source/security-audit
source/todo-scan
HTTP API contracts, routers, schemas, or API smoke behavior.
Authentication, sessions, access bootstrap, or login behavior.
Database sessions, models, transactions, or persistence primitives.
Local developer workflow, scripts, tests, tooling, or release helpers.
Durable documentation and project guidance.
Governance policy, audit, privacy, retention, or compliance behavior.
Public website, product messaging, publication copy, or legal page content.
Alembic migrations, schema bootstrap, or persistence evolution.
Module discovery, manifests, capabilities, routing, or optional integrations.
Permissions, roles, delegation, or authorization policy.
Versioning, release locks, tags, packaging, or dependency pins.
Security posture, static analysis, supply-chain hardening, or vulnerability remediation.
Tenant boundaries, provisioning, or tenant-scoped data behavior.
Shared WebUI shell, frontend components, routing, or frontend tests.
Complexity finding from Radon, Xenon, or equivalent maintainability scans.
Duplicated-code finding from jscpd or equivalent similarity scans.
Audit finding reviewed as a narrow false positive or acceptable risk.
Audit finding that needs an architectural or product decision before implementation.
Audit finding that appears narrow and directly fixable.
Audit finding that needs design, refactoring, or behavior review.
Needs an explicit human decision before Codex should implement.
Suitable for Codex to pick up with the existing issue context.
GovOPlaN access, identity, authentication, RBAC, and administration behavior.
GovOPlaN Addresses module behavior or integration.
GovOPlaN Admin module behavior or integration.
GovOPlaN Appointments module behavior or integration.
GovOPlaN Approvals module behavior or integration.
GovOPlaN Audit module behavior or integration.
GovOPlaN Calendar module behavior or integration.
GovOPlaN campaign module behavior or integration.
GovOPlaN Cases module behavior or integration.
GovOPlaN Committee module behavior or integration.
GovOPlaN Connectors module behavior or integration.
GovOPlaN core runner, shared primitives, shell, or extension points.
GovOPlaN Dashboard module behavior or integration.
GovOPlaN Dataflow module behavior or integration.
GovOPlaN governed datasource contracts, catalogs, and integrations.
GovOPlaN formal Decisions module behavior or integration.
GovOPlaN Distribution Lists module behavior or integration.
GovOPlaN Dms module behavior or integration.
GovOPlaN Docs module behavior or integration.
GovOPlaN Encryption key custody, cryptographic policy, and E2EE integration.
GovOPlaN Erp module behavior or integration.
GovOPlaN Evaluation module behavior or integration.
GovOPlaN files module behavior or integration.
GovOPlaN Fit Connect module behavior or integration.
GovOPlaN Forms module behavior or integration.
GovOPlaN Forms Runtime module behavior or integration.
GovOPlaN Helpdesk module behavior or integration.
GovOPlaN Identity module behavior or integration.
GovOPlaN Identity Trust module behavior or integration.
GovOPlaN Idm module behavior or integration.
GovOPlaN Ledger module behavior or integration.
GovOPlaN mail module behavior or integration.
GovOPlaN Mandates, jurisdiction, responsibility, and authority behavior or integration.
GovOPlaN Notifications module behavior or integration.
GovOPlaN Ops module behavior or integration.
GovOPlaN Organizations module behavior or integration.
GovOPlaN procedure Parties, representation, and delivery-authority behavior or integration.
GovOPlaN Payments module behavior or integration.
GovOPlaN Permits module behavior or integration.
GovOPlaN Policy module behavior or integration.
GovOPlaN Poll module behavior or integration.
GovOPlaN Portal module behavior or integration.
GovOPlaN Postbox module behavior or integration.
GovOPlaN Projects module behavior or integration.
GovOPlaN configurable task-local Quick Access behavior and integrations.
GovOPlaN Records and eAkte lifecycle behavior or integration.
GovOPlaN Reporting module behavior or integration.
GovOPlaN Risk Compliance module behavior or integration.
GovOPlaN Scheduling module behavior or integration.
GovOPlaN Search module behavior or integration.
GovOPlaN versioned institutional Services behavior or integration.
GovOPlaN Tasks module behavior or integration.
GovOPlaN Templates module behavior or integration.
GovOPlaN Tenancy module behavior or integration.
GovOPlaN Tickets module behavior or integration.
GovOPlaN governed task views, interface projections, and workflow view integration.
GovOPlaN Voting module behavior or integration.
GovOPlaN Wiki module behavior or integration.
GovOPlaN Workflow module behavior or integration.
GovOPlaN Workflow Engine runtime, persistence, or integration.
GovOPlaN Xoev module behavior or integration.
GovOPlaN Xrechnung module behavior or integration.
GovOPlaN Xta Osci module behavior or integration.
priority
p0
Immediate stop-the-line priority.
priority
p1
High priority for the next focused work window.
priority
p2
Normal planned priority.
priority
p3
Low priority or opportunistic cleanup.
Imported from markdown backlog, roadmap, plan, or TODO files.
Created from a structured security or code-quality audit report.
Imported from inline TODO/FIXME/HACK markers by the Gitea TODO importer.
status
blocked
Cannot progress without a decision, dependency, credential, or external change.
status
in-progress
Currently being worked.
status
needs-info
Needs clarifying input before implementation can proceed safely.
status
ready
Ready for implementation.
status
triage
Needs review, ownership, priority, or acceptance criteria.
type
bug
A reproducible defect, regression, or incorrect behavior.
type
debt
Cleanup, refactoring, risk reduction, or deferred engineering work.
type
docs
Documentation, process, or developer workflow work.
type
feature
New user-visible behavior or platform capability.
type
task
Implementation, maintenance, migration, or operational work.
type
user-story
End-to-end user journey or real-world process story used to steer product slices.
Milestone
No items
No Milestone
Projects
Clear projects
No projects
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: GovOPlaN/govoplan-cases#7
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
P3: zero-match search in 50-case/100-grant fixture still loads all grants and constructs large ID lists. Use SQL predicates/EXISTS with current purpose-aware grant rules and exact authorized pagination. Include principal/tenant/search/count equivalence and query growth tests.
Tracking: GovOPlaN/govoplan-core#298
User authorized implementation on 2026-09-08. Work is local until explicitly published; keep this issue open until verification and publication state are recorded. Preserve tenant isolation, current authorization, immutable history, audit evidence, deterministic ordering, retry safety and existing API compatibility. Add focused regressions and owning EN/DE documentation. No live mail/provider side effects or historical data rewrites.
Local implementation receipt — 2026-09-08
Current tenant/purpose-aware case grant eligibility now uses correlated EXISTS instead of tenant-wide grant/ID materialization; authorization precedes count and pagination. Zero-match fixture loads 0 grant objects instead of 100.43 tests+4 subtests plus Core exact JSON predicate regressions and PostgreSQL compilation pass. User-first actor selection mechanics are shared with Committee; service-account-specific collections remain separate. EN/DE docs updated.
Verification: tools/checks/check-focused.sh completed successfully,72/72 manifest architecture checks passed, and changed-source Ruff F plus git diff --check passed across 16 repositories. Tests use isolated databases/mock providers; no live data/provider mutation, commit, push, tag, deployment or release was performed. Changes remain local and unpublished: keep this issue OPEN until publication/rollout state is recorded. Before rollout, back up and test coordinated Mail/Files/Connectors/Datasources migrations on a database copy. PostgreSQL concurrency, real provider races and representative load testing remain operational verification, not a claimed certification.
Source publication and database verification — 2026-09-08
Remote main branches and annotated tags were verified against the exact coordinated commits. The implementation-specific tests and EN/DE documentation recorded above remain the acceptance evidence. Cross-module focused checks, manifest shapes, 63 WebUI build configurations and 230 browser tests passed. This records source publication, not a package-registry release, runtime image, website deployment or production rollout.
Database correction to the previous local-only note: the already-running development server had automatically applied Files a2b3c4d5e701, Mail b5d6e7f8091a, Connectors d2a4c6e8f0b1 and Datasources e2b8d4a0f6c3 during reloads. Their heads and expected schema/indexes were verified in the local development PostgreSQL database. A current-state backup was captured and restored into a private, isolated PostgreSQL 16 cluster; this was not a pre-upgrade backup. The supported no-op migration preserved all 281 tables and 142,287 rows by per-row SHA-256 comparison, and retained the same migration heads. Files source identity recomputation matched all 7,385 rows (2 non-null identities, zero mismatches). Both Datasources PostgreSQL concurrency tests, previously skipped without a dedicated database, passed against that isolated cluster. The test cluster was stopped. No real mail delivery, POP3 retrieval/deletion, legacy mailbox reconciliation or external connector import was initiated.
Representative production load/deadline testing and real-provider race/compatibility verification remain separate operational rollout checks; this is not security certification. Operational follow-up: GovOPlaN/govoplan-core#299.
Closing this implementation issue: its code, regression, documentation and source-publication criteria are satisfied. Operational checks above are not claimed complete.