Skip to content

feat(background_tasks): stamp executions with tenant, retry as original tenant (#371) [stack 8/11] - #392

Merged
antosubash merged 8 commits into
tenancy/07-audit-logfrom
tenancy/08-background-tasks
Oct 1, 2026
Merged

antosubash merged 8 commits into
tenancy/07-audit-logfrom
tenancy/08-background-tasks

Conversation

@antosubash

Copy link
Copy Markdown
Owner

Closes #371. Stack 8/11 of the tenancy-adoption series (base: #391).

What

  • Worker tenancy listeners already existed (sync_db._build_engine, run_worker.py). They are verified and covered by test_worker_tenancy.py, not redone.
  • TaskExecution gets a nullable tenant_id, stamped in on_task_publish from the message header, falling back to current_tenant_id.
    • A platform or beat publish stays NULL.
    • A later signal with no tenant never blanks an existing stamp.
    • There is no mixin, because beat publishes have no tenant.
  • Retry runs as the original tenant.
    • _publish runs under tenant_context(row.tenant_id), or under all_tenants() for a platform row. A platform admin who belongs to another org therefore doesn't hit the stamp mismatch.
    • _new_attempt copies tenant_id, and bulk retry can be narrowed to one tenant.
  • Migration b5d3f08a6e17 adds tenant_id plus a (tenant_id, status, queued_at) index. The existing (status, queued_at) index is kept for the platform-wide screens.
  • The admin screens stay platform-wide, with a tenant column, a tenant filter and a tenant fact on the detail page (i18n).

Tests

  • 15 tests in test_execution_tenancy.py: stamping, no blanking, the retry tenant (unit and endpoint, single and bulk), filters, and 403 for tenant roles.
  • The module suite is green: 222 passed.
  • make test-js passes. make lint and make doctor are clean.

Follow-ups

The "retry all" dialog text doesn't mention the tenant narrowing yet. The backend does honour it.

https://claude.ai/code/session_01F8RiTBUJQnZmSq56qReZeV

…nd retry as it (#371)

TaskExecution gets a nullable, indexed tenant_id (NULL = beat / platform
publish) stamped in on_task_publish from the message's tenant header or the
publisher's current tenant, plus a (tenant_id, status, queued_at) index. Not
MultiTenantMixin: beat publishes have no tenant. Retries re-publish under the
original row's tenant (all_tenants() for a platform row) and copy tenant_id, so
an operator who is a member of another org cannot trip the stamp mismatch.
Admin screens stay platform-wide with a tenant column and filter.

Claude-Session: https://claude.ai/code/session_01F8RiTBUJQnZmSq56qReZeV
@cloudflare-workers-and-pages

cloudflare-workers-and-pages Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Deploying simple-module-python with  Cloudflare Pages  Cloudflare Pages

Latest commit: 6d49da1
Status: ✅  Deploy successful!
Preview URL: https://0770995b.simple-module-python.pages.dev
Branch Preview URL: https://tenancy-08-background-tasks.simple-module-python.pages.dev

View logs

…r default_tenant (review of #371)

- prerun/postrun and the terminal signals pass the header's tenant into
  the upsert; never blank an existing stamp (platform messages stay NULL).
- set_database_url takes default_tenant and builds EngineTenancy with it,
  so all_tenants() inserts in a worker land in the install's tenant
  (mirrors DatabaseState.default_tenant_id). Module startup and
  run_worker.py pass it.
- Move the event-bus bridge to _signal_bus.py to keep signals.py under
  the 300-line cap (bind/unbind re-exported).

Claude-Session: https://claude.ai/code/session_01F8RiTBUJQnZmSq56qReZeV
@antosubash
antosubash added this pull request to stack #397 October 1, 2026 16:14
@antosubash
antosubash marked this pull request as ready for review October 1, 2026 16:16
@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
🔒 Security Review ✅ Completed 2026-10-01T16:20:30.414954Z ac22c5e Draft marked ready
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@antosubash
antosubash merged commit 66a4c91 into main Oct 1, 2026
21 of 25 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

background_tasks: tenant-scope TaskExecution, and register the tenant listeners in the Celery worker process

1 participant