@@ -145,6 +145,8 @@ async function supersedeVersionInTx(tx: DbTransaction, versionId: string, now: D
145145}
146146
147147interface RecordWorkspaceFileVersionParams {
148+ /** The workspace the write was scoped to; the file row's column is nullable for other contexts. */
149+ workspaceId : string
148150 /** Head row loaded before the file row was updated. */
149151 head : WorkspaceFileVersionRow | undefined
150152 /** The file row as it was before this write (locked). */
@@ -198,7 +200,7 @@ export async function recordWorkspaceFileVersionInTx(
198200 . values ( {
199201 id : generateId ( ) ,
200202 fileId : previous . id ,
201- workspaceId : next . workspaceId as string ,
203+ workspaceId : params . workspaceId ,
202204 version : ( head ?. version ?? 0 ) + 1 ,
203205 ...contentColumns ( previous , params . previousProvenance ) ,
204206 contentHash : null ,
@@ -248,13 +250,13 @@ export async function recordWorkspaceFileVersionInTx(
248250/** Inserts the new current version described by a write. */
249251async function insertVersion (
250252 tx : DbTransaction ,
251- { next, nextProvenance, contentHash, write, now } : RecordWorkspaceFileVersionParams ,
253+ { workspaceId , next, nextProvenance, contentHash, write, now } : RecordWorkspaceFileVersionParams ,
252254 version : number
253255) : Promise < void > {
254256 await tx . insert ( workspaceFileVersion ) . values ( {
255257 id : generateId ( ) ,
256258 fileId : next . id ,
257- workspaceId : next . workspaceId as string ,
259+ workspaceId,
258260 version,
259261 ...contentColumns ( next , nextProvenance ) ,
260262 contentHash,
@@ -334,6 +336,14 @@ export interface WorkspaceFileVersionRecord {
334336 secretProvenance : WorkspaceFileSecretProvenanceSnapshot
335337}
336338
339+ /** Reads a stored status back, treating anything unrecognized as unknown so a revert fails closed. */
340+ function toSnapshotStatus ( status : string | null ) : WorkspaceFileSecretProvenanceSnapshot [ 'status' ] {
341+ if ( status === null || status === 'exact' || status === 'unknown' || status === 'unrecorded' ) {
342+ return status
343+ }
344+ return 'unknown'
345+ }
346+
337347function toVersionRecord ( row : WorkspaceFileVersionRow ) : WorkspaceFileVersionRecord {
338348 return {
339349 fileId : row . fileId ,
@@ -349,7 +359,7 @@ function toVersionRecord(row: WorkspaceFileVersionRow): WorkspaceFileVersionReco
349359 updatedAt : row . updatedAt ,
350360 supersededAt : row . supersededAt ,
351361 secretProvenance : {
352- status : row . secretProvenanceStatus as WorkspaceFileSecretProvenanceSnapshot [ 'status' ] ,
362+ status : toSnapshotStatus ( row . secretProvenanceStatus ) ,
353363 entries : row . secretProvenanceEntries ,
354364 } ,
355365 }
0 commit comments