Skip to content

feat(users): retire legacy users_user.tenant_id (#381) [stack 5/11] - #389

Merged
antosubash merged 7 commits into
tenancy/04-feature-flagsfrom
tenancy/05-users
Oct 1, 2026
Merged

antosubash merged 7 commits into
tenancy/04-feature-flagsfrom
tenancy/05-users

Conversation

@antosubash

Copy link
Copy Markdown
Owner

Closes #381 (which replaces #360 and #362). Stack 5/11 of the tenancy-adoption series (base: #388).

What

Since #370, tenants_membership and the per-request resolver are the only source of a user's tenant. This PR retires the legacy column:

  • UserContext.from_user no longer copies users_user.tenant_id. The claim path for generic providers is unchanged.
  • tenant_id is removed from User and UserRead.
  • Migration d4e8a1b6c392 on the users chain drops the column and its index. The downgrade re-adds both, nullable. Upgrade, downgrade and re-upgrade were verified on SQLite.
  • User is platform-global by design (documented in multi-tenancy.md).

#362 regression test

modules/tenants/tests/test_membership_changes.py keeps one session cookie unchanged while the membership changes underneath it:

  • Removal: the user's next request loses access.
  • Promote, then demote: invite returns 403, then 201, then 403.
  • Join a second tenant and switch: both tenants are listed and switching works.

No re-login is needed in any case.

Tests

make test-py: 3364 passed. make lint and make doctor are clean.

https://claude.ai/code/session_01F8RiTBUJQnZmSq56qReZeV

UserContext.from_user no longer copies a tenant from the user row, UserRead
drops tenant_id, and an Alembic migration drops the column and its index.
Adds a regression test that membership add/remove/role change/switch apply
on the next request without re-login.

Claude-Session: https://claude.ai/code/session_01F8RiTBUJQnZmSq56qReZeV
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Deploying simple-module-python with  Cloudflare Pages  Cloudflare Pages

Latest commit: a6b0a7e
Status: ✅  Deploy successful!
Preview URL: https://6bb5606e.simple-module-python.pages.dev
Branch Preview URL: https://tenancy-05-users.simple-module-python.pages.dev

View logs

@antosubash
antosubash added this pull request to stack #397 October 1, 2026 16:14
@antosubash
antosubash marked this pull request as ready for review October 1, 2026 16:16
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
🔒 Security Review ✅ Completed 2026-10-01T16:19:50.432029Z a6b0a7e Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@antosubash
antosubash merged commit 57736fc into main Oct 1, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

users: retire legacy users_user.tenant_id now that tenants_membership is the source of truth

1 participant