Enter the personnel number, tell the two kinds of company car apart, record who to call

Three requests from use, one of which changes the schema's mind about
something.

The personnel number is no longer issued. It was GENERATED ALWAYS AS
IDENTITY, which refuses a supplied value outright — but it has to match Loga
and Interflex, and a number this application invents is unknown there, so the
same person ends up with two. Identity dropped, entered everywhere instead:
in the wizard, in the import, and validated against a duplicate with a
message that names the number.

Worth stating plainly: the column had no unique constraint. The identity
prevented collisions as a side effect, and once the value comes from outside
that side effect is gone. The constraint is the point now, and it was
missing.

Company cars distinguish Verbrenner from Elektro, tied to has_dienstwagen by
a CHECK so "E-KFZ" cannot appear against someone without a car. The list
filters on it — with, without, only electric, only combustion — which is the
question the report was really about; it was answerable before only through
an export and manual work.

Emergency contact is name, phone and relationship. Relationship stays free
text: the examples given — Gattin/Gatte, Schwester/Bruder, Freund — are not
a list that closes without telling someone their arrangement does not count.
Name and phone are all-or-nothing, in the database and in both forms: a name
without a number helps nobody, a number without a name does not say who
answers.

Two mistakes of mine on the way, both caught by checks I had written into
the migrations rather than by me:

  - The first CHECK on the car type would have permitted exactly the case it
    was written against. `art in (…)` yields NULL rather than false when the
    column is null, and a CHECK counts NULL as satisfied. It needs an
    explicit `is not null` in front.
  - The constraint was added before the backfill, so it rejected every
    existing row with a car.

Existing cars are recorded as Verbrenner, which is an assumption — but a
visible one: "Elektro" appears nowhere nobody confirmed it.

hire_employee and change_employee_data both had to learn the new columns.
They name their columns one by one, and what is missing there is dropped in
silence — the interface would have collected the fields and thrown them
away, which is what happened to the email address this morning.

Verified against the live database, all rolled back: a hire without a number
is refused, a duplicate is refused naming it, a freely chosen one goes
through; E-KFZ plus contact arrive intact; a contact without a phone is
refused. A change records both, with before and after in the audit detail.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
2026-08-11 21:27:00 +02:00
parent 53d5d41784
commit 9d754359e0
18 changed files with 637 additions and 28 deletions

View File

@@ -0,0 +1,91 @@
-- change_employee_data kennt Notfallkontakt und Antriebsart.
--
-- Ohne diesen Schritt liessen sich die neuen Felder anlegen, aber nie
-- ändern: die Funktion vergleicht und schreibt namentlich aufgezählte
-- Spalten, und was dort fehlt, wird stillschweigend übergangen. Das ist die
-- unangenehme Sorte Lücke — die Oberfläche zeigt ein Eingabefeld, das
-- Speichern meldet Erfolg, und der Wert bleibt stehen.
--
-- Beide Ergänzungen laufen über app_aenderung(), landen also mit Vorher und
-- Nachher im Protokoll wie alles andere auch.
do $$
declare
v_def text;
v_neu text;
begin
select pg_get_functiondef(p.oid) into v_def
from pg_proc p join pg_namespace n on n.oid = p.pronamespace
where n.nspname = 'public' and p.proname = 'change_employee_data' limit 1;
-- ── Vergleiche: Notfallkontakt hinter Telefon, Antriebsart hinter C-Level
v_neu := regexp_replace(
v_def,
'(if\s+v_person\s+\?\s+''phone''\s+then\s+v_person_changes\s*:=\s*app_aenderung\(v_person_changes,\s*''Telefon'',\s*v_old\.phone,\s*v_person->>''phone''\);\s*end\s+if;)',
$neu$\1
if v_person ? 'emergency_contact_name' then v_person_changes := app_aenderung(v_person_changes, 'Notfallkontakt', v_old.emergency_contact_name, v_person->>'emergency_contact_name'); end if;
if v_person ? 'emergency_contact_phone' then v_person_changes := app_aenderung(v_person_changes, 'Notfallkontakt Telefon', v_old.emergency_contact_phone, v_person->>'emergency_contact_phone'); end if;
if v_person ? 'emergency_contact_relation' then v_person_changes := app_aenderung(v_person_changes, 'Notfallkontakt Verhältnis', v_old.emergency_contact_relation, v_person->>'emergency_contact_relation'); end if;$neu$,
'g'
);
if v_neu = v_def then raise exception 'Der Vergleichsblock für den Notfallkontakt liess sich nicht einhängen.'; end if;
v_def := v_neu;
v_neu := regexp_replace(
v_def,
'(if\s+v_role\s+\?\s+''is_c_level''\s+then\s+v_contract_changes\s*:=\s*app_aenderung\(v_contract_changes,\s*''C-Level'',\s*v_old\.is_c_level::text,\s*v_role->>''is_c_level''\);\s*end\s+if;)',
$neu$\1
if v_role ? 'dienstwagen_art' then v_contract_changes := app_aenderung(v_contract_changes, 'Dienstwagen Antrieb', v_old.dienstwagen_art, nullif(v_role->>'dienstwagen_art', '')); end if;$neu$,
'g'
);
if v_neu = v_def then raise exception 'Der Vergleich für die Antriebsart liess sich nicht einhängen.'; end if;
v_def := v_neu;
-- ── Schreiben
v_neu := regexp_replace(
v_def,
'(phone\s*=\s*coalesce\(v_person->>''phone'',\s*phone\),)',
$neu$\1
emergency_contact_name = case when v_person ? 'emergency_contact_name' then nullif(v_person->>'emergency_contact_name', '') else emergency_contact_name end,
emergency_contact_phone = case when v_person ? 'emergency_contact_phone' then nullif(v_person->>'emergency_contact_phone', '') else emergency_contact_phone end,
emergency_contact_relation = case when v_person ? 'emergency_contact_relation' then nullif(v_person->>'emergency_contact_relation', '') else emergency_contact_relation end,$neu$,
'g'
);
if v_neu = v_def then raise exception 'Der Schreibblock für den Notfallkontakt liess sich nicht einhängen.'; end if;
v_def := v_neu;
-- Die Antriebsart hängt an has_dienstwagen: wird der Dienstwagen
-- abgemeldet, muss sie mit, sonst weist der CHECK die Zeile ab.
v_neu := regexp_replace(
v_def,
'(is_c_level\s*=\s*coalesce\(\(v_role->>''is_c_level''\)::boolean,\s*is_c_level\))',
$neu$\1,
dienstwagen_art = case
when coalesce((v_role->>'has_dienstwagen')::boolean, has_dienstwagen) then
coalesce(nullif(v_role->>'dienstwagen_art', ''), dienstwagen_art, 'Verbrenner')
else null
end$neu$,
'g'
);
if v_neu = v_def then raise exception 'Der Schreibblock für die Antriebsart liess sich nicht einhängen.'; end if;
execute v_neu;
end;
$$;
-- ═══ Gegenprobe ══════════════════════════════════════════════════
do $$
declare v_def text;
begin
select pg_get_functiondef(p.oid) into v_def
from pg_proc p join pg_namespace n on n.oid = p.pronamespace
where n.nspname = 'public' and p.proname = 'change_employee_data' limit 1;
if v_def not like '%Notfallkontakt Verhältnis%' then
raise exception 'change_employee_data() vergleicht den Notfallkontakt nicht.';
end if;
if v_def not like '%dienstwagen_art = case%' then
raise exception 'change_employee_data() schreibt die Antriebsart nicht.';
end if;
end;
$$;