Repository navigation
fix(tenancy): harden device ownership resolution - #27
Merged
Merged
Conversation
Read at most two device records by key and fail closed when a key resolves to multiple persisted devices. Preserve the existing no-document error contract.
Query organisations by canonical ownerId only. Organisation documents never used owner_id, and removing that unindexed OR arm preserves use of the ownerId_1 index.
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
This change hardens tenancy ownership resolution by tightening device lookups and removing unsupported organisation ownership fallbacks that could hide data integrity issues and degrade query performance.
LoadDevicenow enforces that a device key resolves to exactly one persisted device. Instead of relying onFindOne, it performs a bounded query with a limit of two results so the resolver can explicitly reject ambiguous keys while still failing correctly for missing devices. This prevents ownership resolution from silently operating on inconsistent data and makes failure modes deterministic.The organisation ownership lookup has also been simplified to use only the canonical
ownerIdfield. Organisations never persisted the legacyowner_idvariant, so the previous$orcondition introduced unnecessary complexity and prevented MongoDB from fully using theownerId_1index. Restricting the query to the canonical indexed field avoids collection scans and aligns the resolver with the actual persistence model.The accompanying tests strengthen coverage around:
Overall, this improves correctness, fail-closed behaviour, and query efficiency in tenancy resolution.