Skip to content

feat: establish shared file ownership foundation - #8609

Draft
mzxchandra wants to merge 12 commits into
codex/project-entity-enforcementfrom
codex/file-ownership-foundation
Draft

mzxchandra wants to merge 12 commits into
codex/project-entity-enforcementfrom
codex/file-ownership-foundation

Conversation

@mzxchandra

@mzxchandra mzxchandra commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • Prepare shared file infrastructure for Project files while preserving workspace files. Canonical files retain workspace_id and organization_id and gain a nullable project_id FK; a database check permits at most one owner. Existing personal/chat attachments may have none, with their access and lifecycle unchanged.
  • Keep the consolidated entityType/entityId interface above storage. Native FKs enforce parent existence and concurrent deletion; shared directory locks and domain guards cover folders, history, creator attribution, billing and cleanup. Search/share owner pairs derive from canonical FK columns.
  • Carry Project ownership through accounting, payer transfers, teardown, uploads, retention, public shares, search and compiled-document caches. Use finite retirement cleanup plus one paginated storage inventory for late uploads, and preserve search invalidation across owner changes.
  • Fence realtime admission and stale joins, distinguish permission-service outages from revocation, and recognize executable document references without treating quoted examples as dependencies.
  • Add compatible migrations 0398–0403 and awaited validation/backfill scripts. Fresh db:push also installs the file-integrity functions and triggers. Project file endpoints and UI arrive in feat: add shared Project files #8610.

Stacked on #8590; #8580 has merged. Project Files #8610 targets this branch and pairs with Mothership #594.

Rollout and rollback

Deploy the foundation and verify retirement of incompatible app/realtime tasks and worker jobs before enabling Project files. Traffic cutover alone is insufficient. The feature remains disabled by default in the follow-up. Earlier draft migrations ran only on disposable databases and were replaced before release.

This foundation is the compatible rollback target once Project files exist: Project UI access is unavailable, while accounting and lifecycle consumers continue handling those rows.

Type of Change

  • Other: file ownership and rollout compatibility foundation

Testing

  • Root lint, all 26 workspace type-check tasks, all audits, migration safety, generated artifacts, docs manifest and block registry pass.
  • Full root tests pass: 373 script tests and all 19 workspace tasks; the app suite passes 34,792 tests with 20 existing skips.
  • Fresh migration and replay pass; Drizzle generation produces no schema drift or invalid indexes. All 59 ownership, history, creator and share-lifetime database checks pass.
  • Real PostgreSQL/local-storage regressions cover cleanup durability, payer-transfer serialization, search fairness, interrupted-index recovery, finite retirement and paginated orphan discovery.
  • All 16 Project Socket.IO checks pass, including confirmed revocation, service outages, delayed admission, owner-qualified join intent and stale leaves. Negative controls demonstrate the relevant failures before their fixes.
  • Earlier schema-push, Redis and integration-fixture checks remain covered by the manually dispatched CI jobs. Workflow triggers and timeouts are unchanged.

Checklist

  • Code follows project style guidelines
  • Self-reviewed the storage, concurrency and compatibility boundaries
  • Relevant tests updated and passing
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

@vercel

vercel Bot commented Oct 4, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
docs Skipped Skipped Oct 6, 2026 8:57pm UTC

Request Review

Add canonical entity ownership while preserving legacy workspace writers.
Make storage accounting, lifecycle cleanup, search, document artifacts, and
realtime transport tolerate project-owned data before feature activation.

Keep Project file user/API/tool entry points in the stacked feature change.
@mzxchandra
mzxchandra force-pushed the codex/file-ownership-foundation branch from 9a1af75 to 6f8882e Compare October 5, 2026 21:02
@mzxchandra mzxchandra changed the title feat: establish entity-owned file compatibility feat: establish shared file ownership foundation Oct 5, 2026
@mzxchandra

Copy link
Copy Markdown
Contributor Author

@greptile

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@mzxchandra I have started the AI code review. It will take a few minutes to complete.

@greptile-apps

greptile-apps Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[Critical risk] Introduces shared file ownership and project-scoped document access.

The PR appears safe to merge with respect to the changes since the previous review.

Summary

The PR establishes Project file ownership alongside workspace files, carrying owner scope through database integrity, billing, cleanup, search, and realtime documents. The latest changes qualify document join and leave intent by owner and add race-focused integration coverage.

Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart LR
  A[File operation] --> B{Canonical owner}
  B -->|Workspace| C[Workspace authorization and lifecycle]
  B -->|Project| D[Project authorization and lifecycle]
  C --> E[Shared file storage]
  D --> E
  E --> F[Search, billing, cleanup, and realtime]
Loading

Reviews (4) · Last reviewed commit: "fix(realtime): fence file joins by owner..."

Comment thread apps/realtime/src/handlers/file-doc.ts Outdated

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 181 files

Re-trigger cubic

Comment thread apps/realtime/src/handlers/file-doc-app.ts
Comment thread apps/realtime/src/handlers/file-doc.ts
Comment thread apps/realtime/vitest.config.ts
Comment thread apps/sim/lib/uploads/documents/compile.ts Outdated
Comment thread apps/realtime/src/middleware/permissions.ts Outdated
Comment thread apps/sim/lib/uploads/contexts/workspace/workspace-file-versions.ts
Comment thread apps/sim/lib/projects/files/purge.ts
Comment thread apps/sim/lib/uploads/documents/references.ts Outdated
Comment thread apps/sim/lib/projects/files/prefix-cleanup.ts
Comment thread packages/auth/src/principal.ts
@mzxchandra

Copy link
Copy Markdown
Contributor Author

@greptile

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@mzxchandra I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 192 files

Turn on auto-fix | Re-trigger cubic

Comment thread apps/realtime/src/handlers/file-doc.ts Outdated
Comment thread apps/sim/lib/users/account-deletion.ts Outdated
Comment thread packages/db/file-entity-ownership.integration.ts
Comment thread scripts/check-unused-exports.baseline.json
Comment thread apps/sim/lib/billing/cleanup-dispatcher.ts Outdated
Comment thread apps/sim/lib/workspace-files/search/dispatcher.ts Outdated
Comment thread apps/sim/lib/uploads/documents/compile.ts Outdated
Comment thread apps/sim/background/cleanup-soft-deletes.ts
Comment thread packages/db/migrations/0403_file_search_owner_scope.sql
Comment thread apps/sim/lib/projects/files/prefix-cleanup.ts Outdated
@mzxchandra

Copy link
Copy Markdown
Contributor Author

@greptile

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@mzxchandra I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 191 files

Reply with feedback, questions, or to request a fix.

Fix all with cubic | Turn on auto-fix | Re-trigger cubic

Comment thread apps/realtime/src/handlers/file-doc.ts
@mzxchandra

Copy link
Copy Markdown
Contributor Author

@greptile

@mzxchandra

Copy link
Copy Markdown
Contributor Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@mzxchandra I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 191 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

You've manually re-run cubic several times on this PR. Each manual re-review checks the full PR again and counts toward your usage quota. To preserve your usage limits, we recommend letting cubic automatically review new commits.

Turn on auto-fix | Re-trigger cubic

This branch was previously deployed

1 inactive deployment
Preview — 347cc6c5 Deployed Oct 6, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant