-- HR-Notizen: add-only Notizen zu einem Mitarbeiter, mit optionalem -- "Wiedervorlage am"-Datum. Kein Bearbeiten/Löschen — ein Fehler wird nicht -- korrigiert, sondern bleibt sichtbar (ggf. per neuer Notiz richtiggestellt), -- gleicher Append-only-Geist wie employee_history/audit_log. -- -- Bewusst NICHT nach Autor gescoped und NICHT effective-dated: anders als -- employee_dependents sieht jede aktive HR-Person jede offene Notiz, -- unabhängig davon wer sie geschrieben hat oder zu wem sie gehört ("Meine -- Notizen" ist trotz des Namens ein geteiltes Team-Postfach), und eine -- Notiz hat keinen "existiert erst ab einem künftigen Datum"-Zustand wie -- eine Versetzung/Beförderung. -- -- Kein Eintrag in employee_history: history_event_type ist ein fixer Enum -- (siehe 20260601000000_initial_schema.sql) ohne passenden Wert, und -- Historie ist explizit eine Beschäftigungsereignis-Timeline. Jede Mutation -- schreibt stattdessen nur einen audit_log-Eintrag. create table employee_notes ( id uuid primary key default gen_random_uuid(), employee_id uuid not null references employees(id) on delete cascade, author_user_id uuid references auth.users(id), author_name text not null, category text not null default 'Allgemein' check (category in ( 'Allgemein', 'Vertraulich', 'Personalgespräch', 'Wiedervorlage', 'Lob / Anerkennung' )), note_text text not null, due_date date, done boolean not null default false, done_at timestamptz, done_by uuid references auth.users(id), created_at timestamptz not null default now() ); create index on employee_notes (employee_id); -- Deckt die "Meine Notizen"-Postfach-Query (loadOpenNotes) ab, die immer -- auf done = false filtert. create index on employee_notes (created_at desc) where not done; -- RLS narrows only what an already-GRANTed role may do; die -- "grant all ... to anon, authenticated, service_role"-Default-Privilegien -- (20260714120500_default_grants.sql) decken die neue Tabelle bereits ab. alter table employee_notes enable row level security; -- Eine einzige Blanket-Policy, gleiches Muster wie `positions`: offen vs. -- erledigt ist ein reiner App-Filter, nie eine RLS-Unterscheidung — jede -- aktive HR-Person darf jede Notiz lesen/schreiben. create policy "employee_notes_hr_all" on employee_notes for all using (is_hr_user()) with check (is_hr_user()); -- ── HR-Notiz hinzufügen ─────────────────────────────────────────────── create or replace function add_employee_note(payload jsonb) returns uuid language plpgsql as $$ declare v_id uuid; v_employee_id uuid := (payload->>'employee_id')::uuid; v_employee_name text; v_category text := coalesce(nullif(payload->>'category', ''), 'Allgemein'); v_note_text text := payload->>'note_text'; v_due_date date := nullif(payload->>'due_date', '')::date; begin perform require_hr_admin(); select first_name || ' ' || last_name into v_employee_name from employees where id = v_employee_id; if not found then raise exception 'Mitarbeiter:in nicht gefunden.'; end if; if coalesce(btrim(v_note_text), '') = '' then raise exception 'Notiztext darf nicht leer sein.'; end if; insert into employee_notes (employee_id, author_user_id, author_name, category, note_text, due_date) values (v_employee_id, auth.uid(), current_actor_name(), v_category, v_note_text, v_due_date) returning id into v_id; insert into audit_log (actor_user_id, actor_name, action, target_label, target_employee_id, details) values ( auth.uid(), current_actor_name(), 'HR-Notiz hinzugefügt', v_employee_name, v_employee_id, '[' || v_category || '] ' || left(v_note_text, 200) || case when v_due_date is not null then ', Wiedervorlage am ' || v_due_date else '' end ); return v_id; end; $$; -- ── HR-Notiz als erledigt markieren ─────────────────────────────────── create or replace function complete_employee_note(payload jsonb) returns void language plpgsql as $$ declare v_note employee_notes%rowtype; v_employee_name text; begin perform require_hr_admin(); select * into v_note from employee_notes where id = (payload->>'note_id')::uuid; if not found then raise exception 'Notiz nicht gefunden.'; end if; if v_note.done then raise exception 'Notiz ist bereits erledigt.'; end if; select first_name || ' ' || last_name into v_employee_name from employees where id = v_note.employee_id; update employee_notes set done = true, done_at = now(), done_by = auth.uid() where id = v_note.id; insert into audit_log (actor_user_id, actor_name, action, target_label, target_employee_id, details) values ( auth.uid(), current_actor_name(), 'HR-Notiz erledigt', v_employee_name, v_note.employee_id, '[' || v_note.category || '] ' || left(v_note.note_text, 200) ); end; $$;