The database moved to a container of our own; the platform is gone. This takes out what was left of it — and, where the leftovers were load bearing, moves rather than deletes. Moved, not deleted: supabase/migrations/ -> db/migrations/ the schema's source of truth supabase/build-org.ts -> scripts/build-org.ts lib/supabase/types.ts -> lib/types.ts 52 import sites repointed The bookkeeping needed care. It lived in `supabase_migrations.schema_migrations`, and simply renaming the schema would have left the runner facing an empty table: it would have called all 67 migrations pending and replayed them against a database that is long since current. So the runner now creates `migrationen.schema_migrations` and, once, copies the old rows across — guarded so a second run does nothing and a fresh database skips it entirely. Only then does migration 20260907100000 drop the old schema. Deleted: the CLI config, the seed, the historical schema/function dumps (nothing read them), scripts/umzug-von-supabase.sh (the move is done), and both Supabase packages plus the CLI. Nothing in the application imported them — the build now succeeds with no environment variables at all, which is the proof. Integration tests: six of them signed in through Supabase Auth and asserted against the anon key and the service role. That model is gone, so the tests were not portable — they are deleted. session-context and employee-status-filter already ran on pg and are untouched; om-reporting is ported to a direct connection because it guards a real risk (the reporting line rule exists twice, once in SQL and once in TypeScript). CI: the integration job started a Supabase stack. It now runs a postgres service, applies deploy/db-init and every migration to an empty database — that was the valuable part, and it still holds — then checks that a second run is a no-op, which is what proves the bookkeeping works. Docs: security-review.md audited a service-role key, a cookie adapter and auth.users, none of which exist. Restating findings about removed components would suggest today's system had been reviewed; it has not. It now records what was removed and says a fresh review is due. data-model.md was already marked obsolete and described the pre-OM schema; azure-migration.md was a plan for a route not taken. Both deleted. Verified: npm ci, typecheck, lint, 445 tests, build — all clean without the packages. Integration tests skip cleanly with no database. Migration SQL and the runner are reviewed but NOT executed: no Docker here, and the old instance no longer resolves. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
682 lines
36 KiB
PL/PgSQL
682 lines
36 KiB
PL/PgSQL
-- Auch geplante Änderungen lassen sich zurücknehmen und berichtigen.
|
|
--
|
|
-- Bisher endete beides an der Gegenwart: was noch nicht wirksam war, blieb
|
|
-- stehen. Der Grund war kein Prinzip, sondern eine fehlende Verbindung — eine
|
|
-- noch nicht wirksame Änderung lebt als payload in pending_org_changes, und
|
|
-- zwischen ihr und der Historienzeile gab es keinen Schlüssel, nur Person und
|
|
-- Datum. Darüber zu raten hätte irgendwann die falsche Zeile getroffen: in
|
|
-- den Daten liegen bereits ein Eintritt und eine Vertragsänderung am selben
|
|
-- Tag.
|
|
--
|
|
-- employee_history bekommt deshalb pending_id. change_employee_data setzt es,
|
|
-- wenn es eine geplante Änderung anlegt; für alles Wirksame bleibt es null.
|
|
--
|
|
-- Eine geplante Änderung kann **zwei** Historienzeilen tragen — Stammdaten
|
|
-- und Vertrag werden getrennt geführt, hängen aber am selben Vorgang. Deshalb
|
|
-- entfernt das Zurücknehmen nur die Felder der betroffenen Gruppe aus dem
|
|
-- payload und bricht den Vorgang nur ab, wenn danach nichts übrig bleibt.
|
|
--
|
|
-- Bestehende Zeilen werden verknüpft, wo es eindeutig ist: genau ein
|
|
-- laufender Vorgang der Person am selben Stichtag, den nicht schon eine
|
|
-- andere Zeile beansprucht. Alles andere bleibt ohne Bezug — und damit
|
|
-- weiterhin unantastbar, mit einer Meldung, die das sagt.
|
|
|
|
alter table employee_history
|
|
add column if not exists pending_id uuid references pending_org_changes(id) on delete set null;
|
|
|
|
comment on column employee_history.pending_id is
|
|
'Der geplante Vorgang, zu dem diese Zeile gehört; null, sobald die Änderung wirksam ist oder es nie einen Vorgang gab. Ohne diesen Bezug lässt sich eine geplante Änderung nicht zurücknehmen — Person und Datum allein sind nicht eindeutig.';
|
|
|
|
create index if not exists idx_employee_history_pending on employee_history (pending_id) where pending_id is not null;
|
|
|
|
CREATE OR REPLACE FUNCTION public.change_employee_data(payload jsonb)
|
|
RETURNS void
|
|
LANGUAGE plpgsql
|
|
SET search_path TO 'public', 'pg_temp'
|
|
AS $function$
|
|
declare
|
|
v_employee_id uuid := (payload->>'employee_id')::uuid;
|
|
v_effective_date date := coalesce(nullif(payload->>'effective_date', '')::date, current_date);
|
|
v_old employees%rowtype;
|
|
v_name text;
|
|
v_person_changes jsonb := '[]'::jsonb;
|
|
v_contract_changes jsonb := '[]'::jsonb;
|
|
v_person jsonb := payload->'person';
|
|
v_contract jsonb := payload->'contract';
|
|
v_role jsonb := payload->'role';
|
|
v_immediate boolean;
|
|
v_new_work_days text[];
|
|
v_new_title_prefix text[];
|
|
v_new_title_suffix text[];
|
|
v_pending_id uuid;
|
|
begin
|
|
perform require_hr_admin();
|
|
select * into v_old from employees where id = v_employee_id;
|
|
v_name := v_old.first_name || ' ' || v_old.last_name;
|
|
v_immediate := v_effective_date <= current_date;
|
|
|
|
-- Der `?`-Test bleibt: ein fehlender Schlüssel heisst „nicht übermittelt",
|
|
-- nicht „geleert". Ohne ihn würde jedes nicht gesendete Feld als Änderung
|
|
-- auf null gemeldet.
|
|
if v_person ? 'first_name' then v_person_changes := app_aenderung(v_person_changes, 'Vorname', v_old.first_name, v_person->>'first_name'); end if;
|
|
if v_person ? 'last_name' then v_person_changes := app_aenderung(v_person_changes, 'Nachname', v_old.last_name, v_person->>'last_name'); end if;
|
|
if v_person ? 'gender' then v_person_changes := app_aenderung(v_person_changes, 'Geschlecht', v_old.gender::text, v_person->>'gender'); end if;
|
|
-- Datumswerte über ::date::text vergleichen, damit „2026-8-3" und
|
|
-- „2026-08-03" nicht als Änderung gelten.
|
|
if v_person ? 'birth_date' then v_person_changes := app_aenderung(v_person_changes, 'Geburtsdatum', v_old.birth_date::text, (nullif(v_person->>'birth_date','')::date)::text); end if;
|
|
if v_person ? 'sv_nummer' then v_person_changes := app_aenderung(v_person_changes, 'SV-Nummer', v_old.sv_nummer, v_person->>'sv_nummer'); end if;
|
|
if v_person ? 'nationality' then v_person_changes := app_aenderung(v_person_changes, 'Staatsbürgerschaft', v_old.nationality, v_person->>'nationality'); end if;
|
|
if v_person ? 'address' then v_person_changes := app_aenderung(v_person_changes, 'Adresse', v_old.address, v_person->>'address'); end if;
|
|
if v_person ? 'postal_code' then v_person_changes := app_aenderung(v_person_changes, 'Postleitzahl', v_old.postal_code, v_person->>'postal_code'); end if;
|
|
if v_person ? 'city' then v_person_changes := app_aenderung(v_person_changes, 'Ort', v_old.city, v_person->>'city'); end if;
|
|
if v_person ? 'address_country' then v_person_changes := app_aenderung(v_person_changes, 'Land', v_old.address_country, v_person->>'address_country'); end if;
|
|
if v_person ? 'email' then v_person_changes := app_aenderung(v_person_changes, 'E-Mail', v_old.email, v_person->>'email'); end if;
|
|
if v_person ? 'phone' then v_person_changes := app_aenderung(v_person_changes, 'Telefon', v_old.phone, v_person->>'phone'); end if;
|
|
if v_person ? 'emergency_contact_name' then v_person_changes := app_aenderung(v_person_changes, 'Notfallkontakt', v_old.emergency_contact_name, v_person->>'emergency_contact_name'); end if;
|
|
if v_person ? 'emergency_contact_phone' then v_person_changes := app_aenderung(v_person_changes, 'Notfallkontakt Telefon', v_old.emergency_contact_phone, v_person->>'emergency_contact_phone'); end if;
|
|
if v_person ? 'emergency_contact_relation' then v_person_changes := app_aenderung(v_person_changes, 'Notfallkontakt Verhältnis', v_old.emergency_contact_relation, v_person->>'emergency_contact_relation'); end if;
|
|
|
|
if v_person ? 'title_prefix' then
|
|
v_new_title_prefix := coalesce((select array_agg(elem) from jsonb_array_elements_text(v_person->'title_prefix') elem), '{}');
|
|
v_person_changes := app_aenderung(v_person_changes, 'Titel (vorangestellt)',
|
|
array_to_string(v_old.title_prefix, ', '), array_to_string(v_new_title_prefix, ', '));
|
|
end if;
|
|
if v_person ? 'title_suffix' then
|
|
v_new_title_suffix := coalesce((select array_agg(elem) from jsonb_array_elements_text(v_person->'title_suffix') elem), '{}');
|
|
v_person_changes := app_aenderung(v_person_changes, 'Titel (nachgestellt)',
|
|
array_to_string(v_old.title_suffix, ', '), array_to_string(v_new_title_suffix, ', '));
|
|
end if;
|
|
|
|
if v_contract ? 'employment_type' then v_contract_changes := app_aenderung(v_contract_changes, 'Beschäftigungsausmaß', v_old.employment_type::text, v_contract->>'employment_type'); end if;
|
|
-- Über ::numeric::text, damit „38.50" und „38.5" gleich zählen.
|
|
if v_contract ? 'weekly_hours' then v_contract_changes := app_aenderung(v_contract_changes, 'Wochenstunden', v_old.weekly_hours::text, (nullif(v_contract->>'weekly_hours','')::numeric)::text); end if;
|
|
if v_contract ? 'contract_type' then v_contract_changes := app_aenderung(v_contract_changes, 'Vertragsart', v_old.contract_type::text, v_contract->>'contract_type'); end if;
|
|
if v_contract ? 'contract_end_date' then v_contract_changes := app_aenderung(v_contract_changes, 'Befristet bis', v_old.contract_end_date::text, (nullif(v_contract->>'contract_end_date','')::date)::text); end if;
|
|
|
|
if v_role ? 'worker_type' then v_contract_changes := app_aenderung(v_contract_changes, 'Angestellte:r/Arbeiter:in', v_old.worker_type::text, v_role->>'worker_type'); end if;
|
|
if v_role ? 'collective_agreement' then v_contract_changes := app_aenderung(v_contract_changes, 'Kollektivvertrag', v_old.collective_agreement::text, v_role->>'collective_agreement'); end if;
|
|
if v_role ? 'work_days' then
|
|
v_new_work_days := coalesce((select array_agg(elem) from jsonb_array_elements_text(v_role->'work_days') elem), '{}');
|
|
v_contract_changes := app_aenderung(v_contract_changes, 'Arbeitstage',
|
|
array_to_string(v_old.work_days, ', '), array_to_string(v_new_work_days, ', '));
|
|
end if;
|
|
if v_role ? 'is_betriebsrat' then v_contract_changes := app_aenderung(v_contract_changes, 'Betriebsrat', v_old.is_betriebsrat::text, v_role->>'is_betriebsrat'); end if;
|
|
if v_role ? 'has_dienstwagen' then v_contract_changes := app_aenderung(v_contract_changes, 'Dienstwagen', v_old.has_dienstwagen::text, v_role->>'has_dienstwagen'); end if;
|
|
if v_role ? 'is_laterale_fuehrung' then v_contract_changes := app_aenderung(v_contract_changes, 'Laterale Führung', v_old.is_laterale_fuehrung::text, v_role->>'is_laterale_fuehrung'); end if;
|
|
if v_role ? 'is_c_level' then v_contract_changes := app_aenderung(v_contract_changes, 'C-Level', v_old.is_c_level::text, v_role->>'is_c_level'); end if;
|
|
if v_role ? 'dienstwagen_art' then v_contract_changes := app_aenderung(v_contract_changes, 'Dienstwagen Antrieb', v_old.dienstwagen_art, nullif(v_role->>'dienstwagen_art', '')); end if;
|
|
|
|
if v_immediate then
|
|
update employees set
|
|
first_name = coalesce(v_person->>'first_name', first_name),
|
|
last_name = coalesce(v_person->>'last_name', last_name),
|
|
gender = coalesce((v_person->>'gender')::gender_type, gender),
|
|
birth_date = coalesce((v_person->>'birth_date')::date, birth_date),
|
|
sv_nummer = coalesce(v_person->>'sv_nummer', sv_nummer),
|
|
nationality = coalesce(v_person->>'nationality', nationality),
|
|
address = coalesce(v_person->>'address', address),
|
|
postal_code = coalesce(v_person->>'postal_code', postal_code),
|
|
city = coalesce(v_person->>'city', city),
|
|
address_country = coalesce(v_person->>'address_country', address_country),
|
|
email = coalesce(v_person->>'email', email),
|
|
phone = coalesce(v_person->>'phone', phone),
|
|
emergency_contact_name = case when v_person ? 'emergency_contact_name' then nullif(v_person->>'emergency_contact_name', '') else emergency_contact_name end,
|
|
emergency_contact_phone = case when v_person ? 'emergency_contact_phone' then nullif(v_person->>'emergency_contact_phone', '') else emergency_contact_phone end,
|
|
emergency_contact_relation = case when v_person ? 'emergency_contact_relation' then nullif(v_person->>'emergency_contact_relation', '') else emergency_contact_relation end,
|
|
title_prefix = case when v_person ? 'title_prefix' then v_new_title_prefix else title_prefix end,
|
|
title_suffix = case when v_person ? 'title_suffix' then v_new_title_suffix else title_suffix end,
|
|
employment_type = coalesce((v_contract->>'employment_type')::employment_type, employment_type),
|
|
weekly_hours = coalesce((v_contract->>'weekly_hours')::numeric, weekly_hours),
|
|
contract_type = coalesce((v_contract->>'contract_type')::contract_type, contract_type),
|
|
contract_end_date = case when v_contract ? 'contract_end_date' then nullif(v_contract->>'contract_end_date','')::date else contract_end_date end,
|
|
worker_type = coalesce((v_role->>'worker_type')::worker_type, worker_type),
|
|
collective_agreement = coalesce((v_role->>'collective_agreement')::collective_agreement, collective_agreement),
|
|
work_days = case when v_role ? 'work_days' then v_new_work_days else work_days end,
|
|
is_betriebsrat = coalesce((v_role->>'is_betriebsrat')::boolean, is_betriebsrat),
|
|
has_dienstwagen = coalesce((v_role->>'has_dienstwagen')::boolean, has_dienstwagen),
|
|
is_laterale_fuehrung = coalesce((v_role->>'is_laterale_fuehrung')::boolean, is_laterale_fuehrung),
|
|
is_c_level = coalesce((v_role->>'is_c_level')::boolean, is_c_level),
|
|
dienstwagen_art = case
|
|
when coalesce((v_role->>'has_dienstwagen')::boolean, has_dienstwagen) then
|
|
coalesce(nullif(v_role->>'dienstwagen_art', ''), dienstwagen_art, 'Verbrenner')
|
|
else null
|
|
end
|
|
where id = v_employee_id;
|
|
elsif jsonb_array_length(v_person_changes) > 0 or jsonb_array_length(v_contract_changes) > 0 then
|
|
insert into pending_org_changes (employee_id, change_type, effective_date, payload)
|
|
values (v_employee_id, 'contract_change', v_effective_date, payload)
|
|
returning id into v_pending_id;
|
|
end if;
|
|
|
|
if jsonb_array_length(v_person_changes) > 0 then
|
|
insert into employee_history (employee_id, event_date, event_type, description, changes, pending_id)
|
|
values (v_employee_id, v_effective_date, 'Stammdatenänderung',
|
|
'Geänderte Felder: ' || app_aenderungsfelder(v_person_changes) || ', wirksam ab ' || v_effective_date, v_person_changes, v_pending_id);
|
|
insert into audit_log (actor_user_id, actor_name, action, target_label, target_employee_id, details, changes)
|
|
values (app_current_user_id(), current_actor_name(), 'Stammdatenänderung', v_name, v_employee_id,
|
|
app_aenderungsfelder(v_person_changes) || ', wirksam ab ' || v_effective_date, v_person_changes);
|
|
end if;
|
|
|
|
if jsonb_array_length(v_contract_changes) > 0 then
|
|
insert into employee_history (employee_id, event_date, event_type, description, changes, pending_id)
|
|
values (v_employee_id, v_effective_date, 'Vertragsänderung',
|
|
'Geänderte Felder: ' || app_aenderungsfelder(v_contract_changes) || ', wirksam ab ' || v_effective_date, v_contract_changes, v_pending_id);
|
|
insert into audit_log (actor_user_id, actor_name, action, target_label, target_employee_id, details, changes)
|
|
values (app_current_user_id(), current_actor_name(), 'Vertragsänderung', v_name, v_employee_id,
|
|
app_aenderungsfelder(v_contract_changes) || ', wirksam ab ' || v_effective_date, v_contract_changes);
|
|
end if;
|
|
end;
|
|
$function$;
|
|
|
|
|
|
-- Die Feldtabelle: Beschriftung → Spalte, Typ und Gruppe.
|
|
--
|
|
-- Die Gruppe ist neu. Eine noch nicht wirksame Änderung liegt als payload in
|
|
-- pending_org_changes, und dort sind die Felder nach person / contract / role
|
|
-- sortiert — so, wie change_employee_data sie entgegennimmt. Wer eine
|
|
-- geplante Änderung berichtigen oder zurücknehmen will, muss wissen, unter
|
|
-- welchem Schlüssel ein Feld dort steht.
|
|
create or replace function app_feld_karte()
|
|
returns jsonb
|
|
language sql
|
|
immutable
|
|
set search_path to 'public', 'pg_temp'
|
|
as $function$
|
|
select jsonb_build_object(
|
|
'Vorname', jsonb_build_array('first_name', 'text', 'person'),
|
|
'Nachname', jsonb_build_array('last_name', 'text', 'person'),
|
|
'Geschlecht', jsonb_build_array('gender', 'gender_type', 'person'),
|
|
'Geburtsdatum', jsonb_build_array('birth_date', 'date', 'person'),
|
|
'SV-Nummer', jsonb_build_array('sv_nummer', 'text', 'person'),
|
|
'Staatsbürgerschaft', jsonb_build_array('nationality', 'text', 'person'),
|
|
'Adresse', jsonb_build_array('address', 'text', 'person'),
|
|
'Postleitzahl', jsonb_build_array('postal_code', 'text', 'person'),
|
|
'Ort', jsonb_build_array('city', 'text', 'person'),
|
|
'Land', jsonb_build_array('address_country', 'text', 'person'),
|
|
'E-Mail', jsonb_build_array('email', 'text', 'person'),
|
|
'Telefon', jsonb_build_array('phone', 'text', 'person'),
|
|
'Notfallkontakt', jsonb_build_array('emergency_contact_name', 'text', 'person'),
|
|
'Notfallkontakt Telefon', jsonb_build_array('emergency_contact_phone', 'text', 'person'),
|
|
'Notfallkontakt Verhältnis', jsonb_build_array('emergency_contact_relation', 'text', 'person'),
|
|
'Titel (vorangestellt)', jsonb_build_array('title_prefix', 'liste', 'person'),
|
|
'Titel (nachgestellt)', jsonb_build_array('title_suffix', 'liste', 'person'),
|
|
'Beschäftigungsausmaß', jsonb_build_array('employment_type', 'employment_type', 'contract'),
|
|
'Wochenstunden', jsonb_build_array('weekly_hours', 'numeric', 'contract'),
|
|
'Vertragsart', jsonb_build_array('contract_type', 'contract_type', 'contract'),
|
|
'Befristet bis', jsonb_build_array('contract_end_date', 'date', 'contract'),
|
|
'Angestellte:r/Arbeiter:in', jsonb_build_array('worker_type', 'worker_type', 'role'),
|
|
'Kollektivvertrag', jsonb_build_array('collective_agreement', 'collective_agreement', 'role'),
|
|
'Arbeitstage', jsonb_build_array('work_days', 'liste', 'role'),
|
|
'Betriebsrat', jsonb_build_array('is_betriebsrat', 'boolean', 'role'),
|
|
'Dienstwagen', jsonb_build_array('has_dienstwagen', 'boolean', 'role'),
|
|
'Laterale Führung', jsonb_build_array('is_laterale_fuehrung', 'boolean', 'role'),
|
|
'C-Level', jsonb_build_array('is_c_level', 'boolean', 'role'),
|
|
'Dienstwagen Antrieb', jsonb_build_array('dienstwagen_art', 'text', 'role')
|
|
);
|
|
$function$;
|
|
|
|
comment on function app_feld_karte() is
|
|
'Beschriftung eines Feldes → [Spalte, Typ, Gruppe im payload]. Quelle für das Zurücksetzen, Berichtigen und Abbrechen von Historieneinträgen.';
|
|
|
|
|
|
-- Einen Historieneintrag zurücknehmen — samt seiner Wirkung.
|
|
--
|
|
-- Zwei Fälle, und sie sind grundverschieden:
|
|
--
|
|
-- **Bereits wirksam.** Die Änderung steht in den Stammdaten. Je Feld wird auf
|
|
-- den Wert davor zurückgesetzt — aber nur, wenn kein späterer Eintrag
|
|
-- dasselbe Feld angefasst hat; sonst gilt der spätere weiter. Das ist „die
|
|
-- letztgültige Änderung ist die schlagende".
|
|
--
|
|
-- **Noch nicht wirksam.** Es gibt nichts zurückzusetzen; die Änderung wartet
|
|
-- als payload in pending_org_changes. Zurückgenommen wird sie, indem ihre
|
|
-- Felder aus dem payload verschwinden. Bleibt danach nichts übrig, wird die
|
|
-- geplante Änderung abgebrochen — bleibt etwas, läuft sie mit dem Rest.
|
|
--
|
|
-- Der zweite Fall braucht einen verlässlichen Bezug zwischen Historienzeile
|
|
-- und geplanter Änderung. Den gab es nicht, und über Person und Datum zu
|
|
-- raten hätte irgendwann die falsche Zeile getroffen: in den Daten liegen
|
|
-- bereits ein Eintritt und eine Vertragsänderung am selben Tag. Deshalb
|
|
-- trägt employee_history jetzt pending_id.
|
|
--
|
|
-- Eine geplante Änderung kann **zwei** Historienzeilen haben — Stammdaten und
|
|
-- Vertrag werden getrennt geführt. Deshalb wird immer nur die Gruppe des
|
|
-- betroffenen Eintrags entfernt, nie der ganze payload.
|
|
create or replace function delete_history_entry(payload jsonb)
|
|
returns void
|
|
language plpgsql
|
|
security definer
|
|
set search_path to 'public', 'pg_temp'
|
|
as $function$
|
|
declare
|
|
v_id uuid := (payload->>'history_id')::uuid;
|
|
v_eintrag employee_history%rowtype;
|
|
v_name text;
|
|
v_karte constant jsonb := app_feld_karte();
|
|
v_aenderung jsonb;
|
|
v_feld text;
|
|
v_wert text;
|
|
v_spalte text;
|
|
v_typ text;
|
|
v_gruppe text;
|
|
v_spaeter boolean;
|
|
v_zurueckgesetzt jsonb := '[]'::jsonb;
|
|
v_setz text[] := '{}';
|
|
v_plan pending_org_changes%rowtype;
|
|
v_neuer_payload jsonb;
|
|
v_leer boolean;
|
|
begin
|
|
perform require_hr_admin();
|
|
|
|
select * into v_eintrag from employee_history where id = v_id;
|
|
if not found then
|
|
raise exception 'Historieneintrag nicht gefunden.';
|
|
end if;
|
|
|
|
if v_eintrag.event_type = 'Eintritt' then
|
|
raise exception 'Der Eintritt lässt sich nicht löschen — er ist der Anfang der Zeitleiste.';
|
|
end if;
|
|
|
|
if v_eintrag.event_type not in ('Stammdatenänderung', 'Vertragsänderung') then
|
|
raise exception 'Nur Stammdaten- und Vertragsänderungen lassen sich hier zurücknehmen. Für % gibt es den passenden Vorgang.', v_eintrag.event_type;
|
|
end if;
|
|
|
|
if v_eintrag.changes is null or jsonb_array_length(v_eintrag.changes) = 0 then
|
|
raise exception 'Zu diesem Eintrag sind keine Feldwerte erfasst — es gibt nichts, worauf zurückgesetzt werden könnte.';
|
|
end if;
|
|
|
|
select first_name || ' ' || last_name into v_name from employees where id = v_eintrag.employee_id;
|
|
|
|
-- ── Noch nicht wirksam: die geplante Änderung entschärfen ──────────
|
|
if v_eintrag.event_date > current_date then
|
|
if v_eintrag.pending_id is null then
|
|
raise exception 'Zu dieser geplanten Änderung ist kein Vorgang hinterlegt. Sie stammt aus der Zeit vor dieser Verknüpfung und lässt sich hier nicht abbrechen.';
|
|
end if;
|
|
|
|
select * into v_plan from pending_org_changes where id = v_eintrag.pending_id for update;
|
|
if not found or v_plan.status <> 'pending' then
|
|
raise exception 'Der geplante Vorgang läuft nicht mehr — er wurde bereits angewendet oder abgebrochen.';
|
|
end if;
|
|
|
|
v_neuer_payload := v_plan.payload;
|
|
for v_aenderung in select * from jsonb_array_elements(v_eintrag.changes) loop
|
|
v_feld := v_aenderung->>'feld';
|
|
if not v_karte ? v_feld then
|
|
continue;
|
|
end if;
|
|
v_spalte := v_karte->v_feld->>0;
|
|
v_gruppe := v_karte->v_feld->>2;
|
|
if v_neuer_payload ? v_gruppe then
|
|
v_neuer_payload := jsonb_set(v_neuer_payload, array[v_gruppe], (v_neuer_payload->v_gruppe) - v_spalte);
|
|
end if;
|
|
end loop;
|
|
|
|
v_leer := coalesce(jsonb_array_length(
|
|
(select jsonb_agg(k) from jsonb_object_keys(coalesce(v_neuer_payload->'person', '{}'::jsonb)) k)), 0) = 0
|
|
and coalesce(jsonb_array_length(
|
|
(select jsonb_agg(k) from jsonb_object_keys(coalesce(v_neuer_payload->'contract', '{}'::jsonb)) k)), 0) = 0
|
|
and coalesce(jsonb_array_length(
|
|
(select jsonb_agg(k) from jsonb_object_keys(coalesce(v_neuer_payload->'role', '{}'::jsonb)) k)), 0) = 0;
|
|
|
|
if v_leer then
|
|
update pending_org_changes set status = 'cancelled' where id = v_plan.id;
|
|
else
|
|
update pending_org_changes set payload = v_neuer_payload where id = v_plan.id;
|
|
end if;
|
|
|
|
delete from employee_history where id = v_id;
|
|
|
|
insert into audit_log (actor_user_id, actor_name, action, target_label, target_employee_id, details, changes)
|
|
values (app_current_user_id(), current_actor_name(), 'Geplante Änderung abgebrochen', v_name, v_eintrag.employee_id,
|
|
v_eintrag.event_type || ' zum ' || v_eintrag.event_date || ' abgebrochen: ' || app_aenderungsfelder(v_eintrag.changes) ||
|
|
case when v_leer then ' (der Vorgang entfällt ganz)' else ' (der Vorgang läuft mit den übrigen Feldern weiter)' end,
|
|
v_eintrag.changes);
|
|
return;
|
|
end if;
|
|
|
|
-- ── Bereits wirksam: Feld für Feld zurücksetzen ────────────────────
|
|
for v_aenderung in select * from jsonb_array_elements(v_eintrag.changes) loop
|
|
v_feld := v_aenderung->>'feld';
|
|
|
|
if not v_karte ? v_feld then
|
|
continue;
|
|
end if;
|
|
|
|
select exists (
|
|
select 1
|
|
from employee_history h,
|
|
lateral jsonb_array_elements(coalesce(h.changes, '[]'::jsonb)) a
|
|
where h.employee_id = v_eintrag.employee_id
|
|
and h.id <> v_eintrag.id
|
|
and a->>'feld' = v_feld
|
|
and (h.event_date, h.created_at) > (v_eintrag.event_date, v_eintrag.created_at)
|
|
) into v_spaeter;
|
|
|
|
if v_spaeter then
|
|
continue;
|
|
end if;
|
|
|
|
v_spalte := v_karte->v_feld->>0;
|
|
v_typ := v_karte->v_feld->>1;
|
|
v_wert := v_aenderung->>'vorher';
|
|
|
|
if v_typ = 'liste' then
|
|
v_setz := v_setz || format('%I = coalesce(string_to_array(%L, '', ''), ''{}'')', v_spalte, nullif(v_wert, ''));
|
|
else
|
|
v_setz := v_setz || format('%I = %L::%s', v_spalte, nullif(v_wert, ''), v_typ);
|
|
end if;
|
|
|
|
v_zurueckgesetzt := v_zurueckgesetzt || jsonb_build_object(
|
|
'feld', v_feld,
|
|
'vorher', v_aenderung->>'nachher',
|
|
'nachher', v_wert
|
|
);
|
|
end loop;
|
|
|
|
-- Alles in einem UPDATE: chk_weekly_hours verknüpft Beschäftigungsausmaß
|
|
-- und Wochenstunden, und zwischen zwei getrennten Anweisungen stünde
|
|
-- zwangsläufig ein Zwischenstand, den die Bedingung verbietet.
|
|
if array_length(v_setz, 1) > 0 then
|
|
begin
|
|
execute format('update employees set %s where id = %L', array_to_string(v_setz, ', '), v_eintrag.employee_id);
|
|
exception when check_violation then
|
|
raise exception 'Zurücksetzen nicht möglich: die Werte von damals passen nicht mehr zum heutigen Stand (%). Vermutlich wurde ein zusammengehörendes Feld später einzeln geändert.', sqlerrm;
|
|
end;
|
|
end if;
|
|
|
|
delete from employee_history where id = v_id;
|
|
|
|
insert into audit_log (actor_user_id, actor_name, action, target_label, target_employee_id, details, changes)
|
|
values (app_current_user_id(), current_actor_name(), 'Historieneintrag gelöscht', v_name, v_eintrag.employee_id,
|
|
v_eintrag.event_type || ' vom ' || v_eintrag.event_date ||
|
|
case when jsonb_array_length(v_zurueckgesetzt) = 0
|
|
then ' gelöscht; keine Werte zurückgesetzt (spätere Änderungen gelten)'
|
|
else ' gelöscht und zurückgesetzt: ' || app_aenderungsfelder(v_zurueckgesetzt) end,
|
|
v_zurueckgesetzt);
|
|
end;
|
|
$function$;
|
|
|
|
comment on function delete_history_entry(jsonb) is
|
|
'Nimmt eine Stammdaten- oder Vertragsänderung zurück. Bereits wirksam: setzt je Feld auf den Wert davor, sofern kein späterer Eintrag dasselbe Feld geändert hat. Noch nicht wirksam: entfernt die Felder aus dem geplanten Vorgang und bricht ihn ab, wenn nichts übrig bleibt. SECURITY DEFINER, weil employee_history absichtlich keine delete-Policy hat.';
|
|
|
|
|
|
-- Einen Historieneintrag berichtigen.
|
|
--
|
|
-- Löschen nimmt einen Eintrag zurück, der nie hätte entstehen dürfen. Hier
|
|
-- geht es um den anderen Fall: der Vorgang stimmt, aber der erfasste Wert
|
|
-- oder das Datum nicht. Ohne diesen Weg bliebe nur „löschen und neu
|
|
-- erfassen" — und dann stünden in der Akte zwei Einträge für eine Änderung,
|
|
-- von denen der erste nie stattgefunden hat.
|
|
--
|
|
-- Geändert wird das **Nachher** und das **Datum**. Das Vorher bleibt: es
|
|
-- beschreibt, was vor der Änderung galt, und das lässt sich nachträglich
|
|
-- nicht anders beschliessen.
|
|
--
|
|
-- Bereits wirksam: die Stammdaten werden nachgezogen, wobei je Feld der
|
|
-- jüngste Eintrag gewinnt, der es trägt — dieselbe Regel wie beim Löschen,
|
|
-- von der anderen Seite gelesen, und sie trägt zusätzlich den Fall, dass ein
|
|
-- neues Datum die Reihenfolge verschiebt.
|
|
--
|
|
-- Noch nicht wirksam: geändert wird der payload des geplanten Vorgangs und
|
|
-- sein Stichtag. An den Stammdaten passiert nichts — dort steht die Änderung
|
|
-- ja noch nicht.
|
|
create or replace function update_history_entry(payload jsonb)
|
|
returns void
|
|
language plpgsql
|
|
security definer
|
|
set search_path to 'public', 'pg_temp'
|
|
as $function$
|
|
declare
|
|
v_id uuid := (payload->>'history_id')::uuid;
|
|
v_eintrag employee_history%rowtype;
|
|
v_datum date;
|
|
v_name text;
|
|
v_karte constant jsonb := app_feld_karte();
|
|
v_alt jsonb;
|
|
v_feld text;
|
|
v_neuer_wert text;
|
|
v_neu jsonb := '[]'::jsonb;
|
|
v_korrektur jsonb := '[]'::jsonb;
|
|
v_setz text[] := '{}';
|
|
v_spalte text;
|
|
v_typ text;
|
|
v_gruppe text;
|
|
v_gueltig text;
|
|
v_plan pending_org_changes%rowtype;
|
|
v_neuer_payload jsonb;
|
|
v_war_zukunft boolean;
|
|
begin
|
|
perform require_hr_admin();
|
|
|
|
select * into v_eintrag from employee_history where id = v_id;
|
|
if not found then
|
|
raise exception 'Historieneintrag nicht gefunden.';
|
|
end if;
|
|
|
|
if v_eintrag.event_type = 'Eintritt' then
|
|
raise exception 'Der Eintritt lässt sich hier nicht berichtigen.';
|
|
end if;
|
|
|
|
if v_eintrag.event_type not in ('Stammdatenänderung', 'Vertragsänderung') then
|
|
raise exception 'Nur Stammdaten- und Vertragsänderungen lassen sich hier berichtigen. Für % gibt es den passenden Vorgang.', v_eintrag.event_type;
|
|
end if;
|
|
|
|
if v_eintrag.changes is null or jsonb_array_length(v_eintrag.changes) = 0 then
|
|
raise exception 'Zu diesem Eintrag sind keine Feldwerte erfasst — es gibt nichts zu berichtigen.';
|
|
end if;
|
|
|
|
v_war_zukunft := v_eintrag.event_date > current_date;
|
|
v_datum := coalesce(nullif(payload->>'event_date', '')::date, v_eintrag.event_date);
|
|
|
|
-- Ein Eintrag bleibt auf seiner Seite der Gegenwart. Beides zu erlauben
|
|
-- hiesse, eine gelaufene Änderung in eine geplante zu verwandeln (oder
|
|
-- umgekehrt) — dann müssten Stammdaten und payload gegenläufig angepasst
|
|
-- werden, und dafür gibt es die fachlichen Vorgänge.
|
|
if v_war_zukunft and v_datum <= current_date then
|
|
raise exception 'Eine geplante Änderung lässt sich hier nicht vorziehen. Dafür ist „Daten ändern" der richtige Weg.';
|
|
end if;
|
|
if not v_war_zukunft and v_datum > current_date then
|
|
raise exception 'Eine bereits wirksame Änderung lässt sich nicht in die Zukunft verschieben.';
|
|
end if;
|
|
|
|
select first_name || ' ' || last_name into v_name from employees where id = v_eintrag.employee_id;
|
|
|
|
-- Neue Werteliste bauen: Vorher bleibt, Nachher darf ersetzt werden.
|
|
for v_alt in select * from jsonb_array_elements(v_eintrag.changes) loop
|
|
v_feld := v_alt->>'feld';
|
|
select w->>'nachher' into v_neuer_wert
|
|
from jsonb_array_elements(coalesce(payload->'werte', '[]'::jsonb)) w
|
|
where w->>'feld' = v_feld;
|
|
|
|
if v_neuer_wert is null then
|
|
v_neu := v_neu || v_alt;
|
|
else
|
|
v_neu := v_neu || jsonb_build_object('feld', v_feld, 'vorher', v_alt->>'vorher', 'nachher', nullif(v_neuer_wert, ''));
|
|
if coalesce(v_alt->>'nachher', '') is distinct from coalesce(nullif(v_neuer_wert, ''), '') then
|
|
v_korrektur := v_korrektur || jsonb_build_object('feld', v_feld, 'vorher', v_alt->>'nachher', 'nachher', nullif(v_neuer_wert, ''));
|
|
end if;
|
|
end if;
|
|
end loop;
|
|
|
|
if jsonb_array_length(v_korrektur) = 0 and v_datum = v_eintrag.event_date then
|
|
raise exception 'Nichts geändert.';
|
|
end if;
|
|
|
|
update employee_history
|
|
set changes = v_neu,
|
|
event_date = v_datum,
|
|
description = 'Geänderte Felder: ' || app_aenderungsfelder(v_neu) || ', wirksam ab ' || v_datum
|
|
where id = v_id;
|
|
|
|
-- ── Noch nicht wirksam: den geplanten Vorgang nachziehen ───────────
|
|
if v_war_zukunft then
|
|
if v_eintrag.pending_id is null then
|
|
raise exception 'Zu dieser geplanten Änderung ist kein Vorgang hinterlegt. Sie stammt aus der Zeit vor dieser Verknüpfung und lässt sich hier nicht berichtigen.';
|
|
end if;
|
|
|
|
select * into v_plan from pending_org_changes where id = v_eintrag.pending_id for update;
|
|
if not found or v_plan.status <> 'pending' then
|
|
raise exception 'Der geplante Vorgang läuft nicht mehr — er wurde bereits angewendet oder abgebrochen.';
|
|
end if;
|
|
|
|
v_neuer_payload := jsonb_set(v_plan.payload, '{effective_date}', to_jsonb(v_datum::text));
|
|
for v_alt in select * from jsonb_array_elements(v_neu) loop
|
|
v_feld := v_alt->>'feld';
|
|
if not v_karte ? v_feld then
|
|
continue;
|
|
end if;
|
|
v_spalte := v_karte->v_feld->>0;
|
|
v_typ := v_karte->v_feld->>1;
|
|
v_gruppe := v_karte->v_feld->>2;
|
|
if not v_neuer_payload ? v_gruppe then
|
|
v_neuer_payload := jsonb_set(v_neuer_payload, array[v_gruppe], '{}'::jsonb);
|
|
end if;
|
|
v_neuer_payload := jsonb_set(
|
|
v_neuer_payload,
|
|
array[v_gruppe, v_spalte],
|
|
case
|
|
when v_alt->>'nachher' is null then 'null'::jsonb
|
|
when v_typ = 'liste' then to_jsonb(string_to_array(v_alt->>'nachher', ', '))
|
|
when v_typ = 'boolean' then to_jsonb((v_alt->>'nachher')::boolean)
|
|
when v_typ = 'numeric' then to_jsonb((v_alt->>'nachher')::numeric)
|
|
else to_jsonb(v_alt->>'nachher')
|
|
end,
|
|
true);
|
|
end loop;
|
|
|
|
update pending_org_changes
|
|
set payload = v_neuer_payload, effective_date = v_datum
|
|
where id = v_plan.id;
|
|
|
|
insert into audit_log (actor_user_id, actor_name, action, target_label, target_employee_id, details, changes)
|
|
values (app_current_user_id(), current_actor_name(), 'Geplante Änderung berichtigt', v_name, v_eintrag.employee_id,
|
|
v_eintrag.event_type || ' zum ' || v_eintrag.event_date ||
|
|
case when v_datum <> v_eintrag.event_date then ' auf ' || v_datum || ' verschoben' else '' end ||
|
|
case when jsonb_array_length(v_korrektur) > 0 then '; berichtigt: ' || app_aenderungsfelder(v_korrektur) else '' end,
|
|
v_korrektur);
|
|
return;
|
|
end if;
|
|
|
|
-- ── Bereits wirksam: Stammdaten nachziehen ─────────────────────────
|
|
for v_feld in select distinct e->>'feld' from jsonb_array_elements(v_neu) e loop
|
|
if not v_karte ? v_feld then
|
|
continue;
|
|
end if;
|
|
|
|
select a->>'nachher' into v_gueltig
|
|
from employee_history h,
|
|
lateral jsonb_array_elements(coalesce(h.changes, '[]'::jsonb)) a
|
|
where h.employee_id = v_eintrag.employee_id
|
|
and a->>'feld' = v_feld
|
|
and h.event_date <= current_date
|
|
order by h.event_date desc, h.created_at desc
|
|
limit 1;
|
|
|
|
v_spalte := v_karte->v_feld->>0;
|
|
v_typ := v_karte->v_feld->>1;
|
|
|
|
if v_typ = 'liste' then
|
|
v_setz := v_setz || format('%I = coalesce(string_to_array(%L, '', ''), ''{}'')', v_spalte, nullif(v_gueltig, ''));
|
|
else
|
|
v_setz := v_setz || format('%I = %L::%s', v_spalte, nullif(v_gueltig, ''), v_typ);
|
|
end if;
|
|
end loop;
|
|
|
|
if array_length(v_setz, 1) > 0 then
|
|
begin
|
|
execute format('update employees set %s where id = %L', array_to_string(v_setz, ', '), v_eintrag.employee_id);
|
|
exception when check_violation then
|
|
raise exception 'Der berichtigte Wert passt nicht zum übrigen Stand (%). Zusammengehörende Felder — etwa Beschäftigungsausmaß und Wochenstunden — müssen gemeinsam stimmen.', sqlerrm;
|
|
end;
|
|
end if;
|
|
|
|
insert into audit_log (actor_user_id, actor_name, action, target_label, target_employee_id, details, changes)
|
|
values (app_current_user_id(), current_actor_name(), 'Historieneintrag berichtigt', v_name, v_eintrag.employee_id,
|
|
v_eintrag.event_type || ' vom ' || v_eintrag.event_date ||
|
|
case when v_datum <> v_eintrag.event_date then ' auf ' || v_datum || ' umdatiert' else '' end ||
|
|
case when jsonb_array_length(v_korrektur) > 0
|
|
then '; berichtigt: ' || app_aenderungsfelder(v_korrektur) else '' end,
|
|
v_korrektur);
|
|
end;
|
|
$function$;
|
|
|
|
comment on function update_history_entry(jsonb) is
|
|
'Berichtigt Wert und/oder Datum einer Stammdaten- oder Vertragsänderung. Bereits wirksam: die Stammdaten werden je Feld aus dem jüngsten wirksamen Eintrag abgeleitet. Noch nicht wirksam: payload und Stichtag des geplanten Vorgangs werden nachgezogen. SECURITY DEFINER, weil employee_history absichtlich keine update-Policy hat.';
|
|
|
|
|
|
-- Bestehende Zeilen verknüpfen, wo genau ein Vorgang in Frage kommt.
|
|
with kandidat as (
|
|
select h.id as history_id,
|
|
(select p.id
|
|
from pending_org_changes p
|
|
where p.employee_id = h.employee_id
|
|
and p.effective_date = h.event_date
|
|
and p.status = 'pending'
|
|
and p.change_type = 'contract_change'
|
|
and not exists (
|
|
select 1 from employee_history x
|
|
where x.pending_id = p.id and x.event_type = h.event_type
|
|
)
|
|
limit 2) as plan_id,
|
|
(select count(*)
|
|
from pending_org_changes p
|
|
where p.employee_id = h.employee_id
|
|
and p.effective_date = h.event_date
|
|
and p.status = 'pending'
|
|
and p.change_type = 'contract_change') as anzahl
|
|
from employee_history h
|
|
where h.event_date > current_date
|
|
and h.pending_id is null
|
|
and h.event_type in ('Stammdatenänderung', 'Vertragsänderung')
|
|
)
|
|
update employee_history h
|
|
set pending_id = k.plan_id
|
|
from kandidat k
|
|
where h.id = k.history_id
|
|
and k.anzahl = 1
|
|
and k.plan_id is not null;
|
|
|
|
|
|
-- Selbstprüfung.
|
|
do $$
|
|
declare
|
|
v_ced text := pg_get_functiondef('public.change_employee_data(jsonb)'::regprocedure);
|
|
v_del text := pg_get_functiondef('public.delete_history_entry(jsonb)'::regprocedure);
|
|
v_upd text := pg_get_functiondef('public.update_history_entry(jsonb)'::regprocedure);
|
|
begin
|
|
if not exists (
|
|
select 1 from information_schema.columns
|
|
where table_schema = 'public' and table_name = 'employee_history' and column_name = 'pending_id'
|
|
) then
|
|
raise exception 'employee_history.pending_id fehlt';
|
|
end if;
|
|
|
|
if (length(v_ced) - length(replace(v_ced, 'v_pending_id)', ''))) / length('v_pending_id)') <> 2 then
|
|
raise exception 'change_employee_data schreibt pending_id nicht in beide Historien-Einträge';
|
|
end if;
|
|
|
|
if v_ced not like '%returning id into v_pending_id%' then
|
|
raise exception 'change_employee_data merkt sich den angelegten Vorgang nicht';
|
|
end if;
|
|
|
|
if jsonb_array_length(app_feld_karte()->'Adresse') <> 3 then
|
|
raise exception 'Die Feldtabelle nennt die Gruppe nicht';
|
|
end if;
|
|
if app_feld_karte()->'Adresse'->>2 <> 'person' or app_feld_karte()->'Wochenstunden'->>2 <> 'contract' then
|
|
raise exception 'Die Gruppen in der Feldtabelle stimmen nicht';
|
|
end if;
|
|
|
|
if v_del not like '%pending_id is null%' or v_upd not like '%pending_id is null%' then
|
|
raise exception 'Der Zukunftsfall wird nicht behandelt';
|
|
end if;
|
|
|
|
-- Die Policies bleiben, wie sie sind.
|
|
if exists (
|
|
select 1 from pg_policy p join pg_class c on c.oid = p.polrelid
|
|
where c.relname = 'employee_history' and p.polcmd in ('d', 'w')
|
|
) then
|
|
raise exception 'employee_history hat eine update- oder delete-Policy bekommen';
|
|
end if;
|
|
end
|
|
$$;
|