Skip to content

feat(store): org tokens search skips soft-deleted rows - #1950

Merged
rohilsurana merged 5 commits into
mainfrom
soft-delete-org-tokens-reads
Sep 29, 2026
Merged

rohilsurana merged 5 commits into
mainfrom
soft-delete-org-tokens-reads

Conversation

@rohilsurana

@rohilsurana rohilsurana commented Sep 25, 2026 •

Copy link
Copy Markdown
Member

Last of the org view repositories. Same shape as #1939, #1943, #1945, #1946, #1947.

Summary

The org tokens search now skips soft-deleted transactions, billing accounts and organizations. A soft-deleted user no longer lends their name to a token.

Changes

  • Start from fromLive(billing_transactions), add live(billing_customers).
  • Join organizations and add live(organizations), like feat(store): project users search skips soft-deleted rows #1946 and feat(store): org service user credentials search skips soft-deleted rows #1949. The search is scoped by billing_customers.org_id, and a billing account is not soft-deleted when its org goes, so without this a soft-deleted org still listed its tokens.
  • live(users) goes in the left join, not the where clause. The token stays, the deleted user's name and avatar come back empty. Dropping the row would change the totals an org sees.
  • New docker-backed suite org_tokens_repository_pg_test.go. Updated expected SQL in org_tokens_repository_test.go.

Notes for review

  • Nothing writes billing_transactions.deleted_at yet. The filter is here for when deleting an org becomes a soft delete and takes its transactions with it.
  • First left join in this batch. The siblings all inner-join users and drop the row.
  • user_id still comes back for a deleted user, only the name is gone.
  • Out of scope: billing_transactions_repository.go reads the same table for the balance and the org's own list, with no filter. Once orgs are soft-deleted the two views will disagree. Tracked separately.

Test Plan

  • go test -run 'TestOrgTokensRepository' ./internal/store/postgres/ passes
  • The new suite fails on main, naming the soft-deleted transaction, account, org and user
  • golangci-lint run ./internal/store/postgres/... is clean
  • No end to end run. Seeding real tokens needs billing set up with a provider.

SQL Safety

  • Values flow through ? placeholders, goqu.Ex{}, or goqu.Record{} — never fmt.Sprintf or + building a query that gets executed.
  • ToSQL() callers capture and forward params (query, params, err := stmt.ToSQL(); db.…Context(ctx, …, query, params...)). Never query, _, err := ….
  • No ? placeholders inside single-quoted SQL literals in goqu.L.
  • No new //nolint:forbidigo or // #nosec G20x annotations.

@vercel

vercel Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
frontier Ready Ready Preview Sep 29, 2026 8:33am UTC

@coderabbitai

coderabbitai Bot commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Note

Reviews paused

It looks like this branch is under active development. To avoid overwhelming you with review comments due to an influx of new commits, CodeRabbit has automatically paused this review. You can configure this behavior by changing the reviews.auto_review.auto_pause_after_reviewed_commits setting.

Use the following commands to manage reviews:

  • @coderabbitai resume to resume automatic reviews.
  • @coderabbitai review to trigger a single review.

Use the checkboxes below for quick actions:

  • ▶️ Resume reviews
  • 🔍 Trigger review

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: raystack/frontier/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: 1df46b9b-2cda-4bef-9e5d-17a3af3ea120

📥 Commits

Reviewing files that changed from the base of the PR and between 5f12dea and aaa3694.

📒 Files selected for processing (1)
  • internal/store/postgres/org_tokens_repository.go

Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 1 remain after this review.


📝 Summary

Summary by CodeRabbit

  • Bug Fixes
    • Organization token listings now exclude tokens associated with deleted billing transactions, billing accounts, or organizations, so only tokens tied to active records are shown.
    • Tokens without an associated user remain visible. Tokens linked to deleted users still appear, but the user’s name is hidden.
    • Token searches return matches only from live records, avoiding results tied to deleted transactions, accounts, users, or organizations. These changes apply to both token listings and search results.

Walkthrough

The organization token query filters soft-deleted transactions, billing customers, organizations, and users. Updated SQL expectations and PostgreSQL integration tests cover these query behaviors.

Changes

Organization token filtering

Layer / File(s) Summary
Live-record query filters
internal/store/postgres/org_tokens_repository.go, internal/store/postgres/org_tokens_repository_test.go
The base query filters soft-deleted transactions, billing customers, organizations, and users. SQL expectations cover the joins and filters across query variants.
PostgreSQL behavior tests
internal/store/postgres/org_tokens_repository_pg_test.go
Integration tests check that deleted transactions and accounts are excluded, deleted organizations return no tokens, transactions without users remain listed, deleted users retain token IDs but hide their titles, and search excludes matches associated with deleted records.

Priority: ⬇️ Low

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Bug fix

Suggested reviewers: amangit07

Merge Risk: ⚪ Minimal · up to aaa36

This change does not introduce the identified invalid-user-ID risk. No actionable merge-blocking issue remains after normal checks.

Architecture Summary

Architecture risk: 🔵 Low · up to aaa36

The change affects 1 system.

Changed systems: internal

Architecture concerns
No architecture-level concerns identified.

Review details

Systems and components

  • observed — internal (service) was modified; 3 changed files map to changed impact.

Before / after behavior

  • observed — Modified behavior in internal/store/postgres/org_tokens_repository_pg_test.go: Adds the PostgreSQL test suite, initializes a repository and database fixture, seeds live and soft-deleted related records, and truncates the fixture tables after each test. Setup and cleanup failures fail the test.
  • observed — Modified behavior in internal/store/postgres/org_tokens_repository_pg_test.go: Adds helpers for SQL execution and ID lookup, repository searches sorted by description with a limit of 50, token lookup by description, and extraction of token descriptions.
  • observed — Modified behavior in internal/store/postgres/org_tokens_repository_pg_test.go: Adds assertions that soft-deleted transactions and accounts are excluded, deleted organizations yield no tokens, userless transactions remain listed, soft-deleted users retain token IDs but have hidden titles, and search results omit matches associated with deleted records.
  • observed — Modified behavior in internal/store/postgres/org_tokens_repository_pg_test.go: Adds the test entry point that runs OrgTokensRepositoryPGTestSuite.
🚥 Pre-merge checks | ✅ 2
✅ Passed checks (2 passed)
Check name Status Explanation
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coveralls

coveralls commented Sep 25, 2026 •

Copy link
Copy Markdown

Coverage Report for CI Build 36543437182

Coverage increased (+0.08%) to 52.777%

Details

  • Coverage increased (+0.08%) from the base build.
  • Patch coverage: 23 of 23 lines across 1 file are fully covered (100%).
  • No coverage regressions found.

Uncovered Changes

No uncovered changes found.

Coverage Regressions

No coverage regressions found.


Coverage Stats

Coverage Status
Relevant Lines: 41268
Covered Lines: 21780
Line Coverage: 52.78%
Coverage Strength: 17.0 hits per line

💛 - Coveralls

Comment thread internal/store/postgres/org_tokens_repository.go Outdated

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 1


ℹ️ Review info
⚙️ Run configuration

Configuration used: Repository: raystack/frontier/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: de6d8823-fcfb-4053-8367-aed4fc044caf

📥 Commits

Reviewing files that changed from the base of the PR and between e44bcd6 and b9b61d4.

📒 Files selected for processing (2)
  • internal/store/postgres/org_tokens_repository.go
  • internal/store/postgres/org_tokens_repository_test.go

Included review availability: This review used your included allowance. Your plan provides up to 2 included reviews per hour; 1 remain after this review.

Comment thread internal/store/postgres/org_tokens_repository.go
@rohilsurana
rohilsurana force-pushed the soft-delete-org-tokens-reads branch from aaa3694 to afc4d56 Compare September 29, 2026 08:33
@rohilsurana
rohilsurana merged commit 58583d2 into main Sep 29, 2026
8 checks passed
@rohilsurana
rohilsurana deleted the soft-delete-org-tokens-reads branch September 29, 2026 09:10

This branch was successfully deployed

1 active deployment
Preview — afc4d56d Deployed Sep 29, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants