Repository navigation
fix(security): drop profile grants on the removed crm_competitor object - #552
Merged
Merged
Conversation
main was failing `pnpm validate` with four cross-reference errors — every profile that granted CRUD on `crm_competitor` was pointing at an object that no longer exists. Two merges disagreed semantically while merging cleanly on text: #547 added competitor grants to four profiles (the object existed on its base), and d97f3a0 removed the demo-only competitor module. Neither touched the other's files, so git had nothing to conflict on. The picklist field `crm_opportunity.competitors` is unrelated and stays — it never referenced the removed object. Verified on a clean checkout: validate clean (15 objects, 6 permissions), typecheck clean, 128/128 tests pass. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
|
The latest updates on your projects. Learn more about Vercel for GitHub. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
mainis currently failingpnpm validatewith four cross-reference errors — every profile that grants CRUD oncrm_competitorpoints at an object that no longer exists:Reproduced on a clean checkout of
mainat7f0b3ef4, so this is not specific to any open PR — but it turns every open PR'sBuild and Testred until it is fixed.Root cause — a semantic conflict git could not see
Two merges disagreed on meaning while merging cleanly on text:
crm_competitorexisted on its base, so granting CRUD on it was correct.crm_competitorobject.#551 touched objects, views, navigation and seed data; #547 touched
src/profiles/. No file overlapped, so git had nothing to conflict on and GitHub's mergeability check — which is textual — stayed green for both. Neither PR was wrong on its own; only their merge order was.Changes
crm_competitorgrant fromsales_rep,sales_manager,marketing_userandsystem_admin, and reword the surrounding comments that described the competitor catalog.crm_opportunity.competitorspicklist field is unrelated and stays — it never referenced the removed object. (revert: remove demo-only contract kanban and competitor module (#532 follow-up) #551 deliberately restored it as the hardcoded select.)Verification
On a clean checkout with this fix applied:
pnpm validate— clean: 15 Objects / 309 Fields, 6 Permissions, 12 Positions. The only remaining output is the two pre-existingcampaign_enrollmentflow-variable warnings, which are expected and documented as safe to ignore.pnpm typecheck— clean.pnpm test— 128/128 passing (11 files).Type of Change
Checklist
pnpm validatepassespnpm typecheckpassespnpm testpassesRefs #547, refs #551. No new issue filed: this is the mechanical consequence of the two merges above, not a product defect. The removed demo module itself is archived at tag
demo-series-2026-07if it is ever needed again.