Repository navigation
fix(cli): bind db update consent to the printed plan with --plan <id> - #1777
Conversation
Closes #1660 Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01F2unpL2YeNYqQ2XBeVkFnm
🦋 Changeset detectedLatest commit: b98bb70 The changes in this PR will be included in the next version bump. This PR includes changesets to release 10 packages
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
Code review: PR #1777 (
|
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 6787a656d6
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
| const content = plan.operations.map( | ||
| (operation) => `${operation.operationClass}:${operation.label}`, | ||
| ) | ||
| return createHash('sha256').update(JSON.stringify(content)).digest('hex').slice(0, 12) |
There was a problem hiding this comment.
Hash the SQL that the user reviewed
When an extension or custom migration is changed after the plan is printed while retaining the same operation labels and classes, the old --plan value still passes this check even though describePlan displayed different SQL statements. The loop then supplies Prisma’s --confirm automatically and can execute destructive SQL the user never reviewed. Include plan.statements—or another canonical representation of the complete printed plan—in the digest.
Useful? React with 👍 / 👎.
| "Apply 1 destructive operation(s) to postgres? Data they remove cannot be recovered: | ||
| - Alter type of "KnowledgeBase"."contentEmbedding" to vector(3072)" requires explicit | ||
| consent, and the session is not interactive. Grant it by passing --confirm postgres. | ||
| consent, and the session is not interactive. Grant it by passing --plan <id>. |
There was a problem hiding this comment.
Preserve Prisma's actual --confirm diagnostic
This fence is presented as output from a non-interactive Prisma db update, but the pinned command’s --help states that non-interactive consent comes from --confirm <database>, and Prisma still emits that flag in this diagnostic. The OpenSaaS wrapper emits its own plan-ID error before invoking the destructive update; it does not rewrite Prisma’s message. Keeping --plan <id> inside the quoted Prisma output therefore gives users an output example they cannot actually encounter.
Useful? React with 👍 / 👎.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01F2unpL2YeNYqQ2XBeVkFnm
Coverage Report for Core Package Coverage (./packages/core)
File CoverageNo changed files found. |
Coverage Report for UI Package Coverage (./packages/ui)
File CoverageNo changed files found. |
Coverage Report for CLI Package Coverage (./packages/cli)
File Coverage
|
||||||||||||||||||||||||||||||||||||||||||||||||||
Coverage Report for Auth Package Coverage (./packages/auth)
File CoverageNo changed files found. |
Coverage Report for Storage Package Coverage (./packages/storage)
File CoverageNo changed files found. |
Coverage Report for RAG Package Coverage (./packages/rag)
File CoverageNo changed files found. |
Coverage Report for Storage S3 Package Coverage (./packages/storage-s3)
File CoverageNo changed files found. |
Coverage Report for Storage Vercel Package Coverage (./packages/storage-vercel)
File CoverageNo changed files found. |
Summary
pnpm db:update --plan <id>, which runs as written.opensaas db update --plan <id>re-plans as a dry run. It applies only a destructive plan whose id matches, passing Prisma the consent token for the database actually connected (Dev database or theDATABASE_URLdatabase name). Otherwise it prints the new plan and id and changes nothing.--plan, or with nothing parked, is refused and printed first. Non-destructive plans apply with plainpnpm db:update.--confirmis removed fromopensaas db update. Root/starter/rag CLAUDE.md, READMEs and docs updated.Test plan
tests/staged-reconcile.test.ts) use the printed idpnpm lint,pnpm formatpostgres(not added; needs a live DATABASE_URL)Closes #1660
🤖 Generated with Claude Code
https://claude.ai/code/session_01F2unpL2YeNYqQ2XBeVkFnm
Generated by Claude Code