Skip to content

v0.3.1

Latest

Choose a tag to compare

@pablofelipe pablofelipe released this 02 Aug 00:46

Evidence and reliability release. One real bug fixed, plus a multi-tenancy verification pass on top of the already-shipped authorization model.

Highlights

  • Fixed an N+1 in the GraphQL vehicle query — requesting the user field on a vehicle list re-queried its owner once per row instead of reusing the row already joined by the underlying query. Measured before fixing: 202 SQL executions and ~150-290ms for a 200-vehicle result; after: 2 executions, ~35ms (matching the no-user baseline). Covered by a new regression test that asserts the already-loaded owner is reused by reference, not just that the returned data is correct.

Under the hood

  • ADR-0012 documents how tenant isolation is actually enforced: a per-call-site check (ResourceAuthorization.IsAuthorizedInTenant) comparing the actor's tenant — resolved fresh from the database every request, never from the JWT — against each resource's tenant. No database-level row-level security or global query filter exists; the guarantee is a code discipline, not a structural one, and that trade-off is now an explicit, revisitable decision instead of an implicit assumption.
  • New concurrency test (TenantIsolationConcurrencyTest) proves two tenants querying at the same time never see each other's data, against a real PostgreSQL instance. No test in the suite had exercised this before.
  • OWASP ZAP baseline scan run against both REST and GraphQL, results committed (docs/security/): zero findings above medium risk on either surface; the only findings are missing security headers (CSP, X-Frame-Options, etc.).
  • Documentation writing standard added (docs/standards/) and applied to tighten prose across the README and core docs.

Compatibility

Pre-1.0 release — the public API is not yet declared stable (see CHANGELOG.md). No breaking changes in this release; none are expected before the next minor.