Skip to content

feat(feature_flags): validate tenant ids, pin tenant flag behaviour (#375) [stack 4/11] - #388

Merged
antosubash merged 6 commits into
tenancy/03-dashboardfrom
tenancy/04-feature-flags
Oct 1, 2026
Merged

antosubash merged 6 commits into
tenancy/03-dashboardfrom
tenancy/04-feature-flags

Conversation

@antosubash

Copy link
Copy Markdown
Owner

Closes #375. Stack 4/11 of the tenancy-adoption series (base: #387).

What

The issue's premise turned out to be wrong: require_flag, is_flag_enabled and flag_enabled already resolve request.state.tenant_id. This PR pins that behaviour in tests and closes the remaining gap:

  • Tenant id validation without coupling.
    • Core simple_module_core.tenancy.tenant_exists(app, id) reads app.state.tenant_exists, which tenants publishes. It returns None when no directory is installed.
    • feature_flags returns 404 for an unknown tenant on the list, set and browse override routes.
    • Clearing an override is deliberately not validated, so an override left behind for a deleted tenant can still be removed.
  • Tests (16 tenancy + 2 core):
    • Tenant override precedence through require_flag for two tenants.
    • Fallback to the system value and then the default.
    • Boot hydration under strict mode, with no tenant bound.
    • No tenant role holds the flag permissions.
    • Unknown and known tenant ids are handled correctly.

Tests

make test-py: 3361 passed. make lint is clean.

https://claude.ai/code/session_01F8RiTBUJQnZmSq56qReZeV

@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Deploying simple-module-python with  Cloudflare Pages  Cloudflare Pages

Latest commit: 355a6f9
Status: ✅  Deploy successful!
Preview URL: https://22692dcf.simple-module-python.pages.dev
Branch Preview URL: https://tenancy-04-feature-flags.simple-module-python.pages.dev

View logs

@antosubash
antosubash added this pull request to stack #397 October 1, 2026 16:14
@antosubash
antosubash marked this pull request as ready for review October 1, 2026 16:16
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
🔒 Security Review ✅ Completed 2026-10-01T16:18:53.081283Z 355a6f9 Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@antosubash
antosubash merged commit 30d4ccd into main Oct 1, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feature_flags: tenant overrides already modeled, but no request-time dependency resolves the active tenant

1 participant