Let the same choice open notes and drafts
All checks were successful
CI / Lint, Typen, Tests, Build (push) Successful in 11m47s
CI / Migrationen auf leerer Datenbank (push) Successful in 10m10s

The picker in the bell now governs both lists, so note_subscriptions is
renamed to colleague_subscriptions -- a name that only mentions notes would
mislead the next reader.

Reading and writing a draft now reach differently far. hire_drafts_owner
(for all) is split into four policies: select lets in your own drafts and
those of the people you added, while insert/update/delete stay with the
owner. A draft is unfinished work with no lock and no history; two people
writing into the same row would overwrite each other silently.

That split forces a change in the actions: a policy does not reject a write,
it lets it hit no rows. saveHireDraft and deleteHireDraft now read the row
count instead of reporting success over a row that never changed.

The card shows a foreign draft with its author and without Fortsetzen or
Loeschen -- offering a button that reliably ends in a database error is a
promise without cover.

check-schema-types.mjs learns `alter table ... rename to`; without it the
drift check reports one rename as two errors.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
2026-09-10 16:05:40 +02:00
parent e8e675fd07
commit eeaf210e78
17 changed files with 650 additions and 54 deletions

View File

@@ -2,6 +2,7 @@ import { sql, type Expression, type SqlBool } from "kysely";
import type { Tx } from "./db";
import { jsonArrayFrom, zeitstempel } from "./db/json";
import { fmtName } from "./format";
import { istHinzugewaehlt } from "./kollegen";
import type { OrgEb } from "./org";
import type { Database } from "./types";
@@ -29,7 +30,8 @@ export type NotizZeile = Omit<Database["public"]["Tables"]["employee_notes"]["Ro
// mitarbeiterübergreifend, unabhängig davon, zu welcher Person sie gehören.
//
// **Wessen** Notizen erscheinen, entscheidet jede Person selbst: die eigenen
// immer, dazu die hinzugewählten Kolleg:innen (note_subscriptions).
// immer, dazu die hinzugewählten Kolleg:innen (colleague_subscriptions) —
// dieselbe Auswahl, die auch die Entwürfe steuert.
//
// Bis September 2026 war es ein gemeinsamer Topf — jede HR-Person sah jede
// Notiz. Der Wunsch, sich standardmässig nur selbst zu sehen, kam aus dem
@@ -48,7 +50,7 @@ export type NotizZeile = Omit<Database["public"]["Tables"]["employee_notes"]["Ro
* Drei Fälle kommen durch:
*
* 1. **Die eigenen, immer.** Sie sind der Grund, warum es die Glocke gibt.
* `note_subscriptions` lässt einen Selbstbezug nicht zu; die Bedingung
* `colleague_subscriptions` lässt einen Selbstbezug nicht zu; die Bedingung
* steht hier trotzdem, damit die Zusage nicht davon abhängt, dass eine
* Prüfbedingung an anderer Stelle bestehen bleibt.
*
@@ -73,9 +75,7 @@ export function sichtbareNotizen(userId: string, spalte = "n.author_user_id"): E
return sql<SqlBool>`(
${verfasser} is null
or ${verfasser} = ${userId}
or exists (
select 1 from note_subscriptions s
where s.user_id = ${userId} and s.author_user_id = ${verfasser}))`;
or ${istHinzugewaehlt(userId, spalte)})`;
}
/**