Make RoleRightsSyncService fully self-healing on every boot

FeatureSecurityService
Shipped
April 20, 2026 at 8:23 PM UTC
Author
Kamo
Commit
3609afb

Adding or removing a RoleRightType must never again require running KamoInitializerService. syncAll() now runs three phases on every startup: 1. Heal constraints — drop every CHECK constraint on every right-bearing table and ensure the two upsert-required unique constraints exist. Hibernate bakes enum values into CHECK constraints at CREATE TABLE time and never updates them, and @UniqueConstraint only takes effect on CREATE TABLE, so both drift whenever enums evolve. @Enumerated already enforces valid values at the Java layer. 2. Delete orphan rights — DELETE WHERE right_type NOT IN (current enum) across all six right-bearing tables: org_role_rights, **************** member_rights, member_rights_applied, job_title_rights, dept_rights. Handles both ORDINAL int and STRING enum-name storage. 3. Insert missing rights — unchanged; relies on the unique constraints ensured in phase 1. Idempotent — safe to re-run. Adding/removing enum values now requires only restarting SecurityService.

All changes

Like what you see shipping?

Every one of these updates lands in your workspace automatically. Start free and watch it grow week after week.

Start Free ForeverView Pricing