-
Notifications
You must be signed in to change notification settings - Fork 9
Fix notification target_roles enum mismatch #308
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Fix notification target_roles enum mismatch #308
Conversation
|
@pixelsama is attempting to deploy a commit to the zhang's projects Team on Vercel. A member of the Team first needs to authorize it. |
Summary of ChangesHello @pixelsama, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed! This pull request resolves a critical database migration failure by correcting a type mismatch in the Highlights
Using Gemini Code AssistThe full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips. Invoking Gemini You can request assistance from Gemini at any point by creating a comment using either
Customization To customize Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a Limitations & Feedback Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counter productive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for Github and other Google products, sign up here. You can also get AI-powered code generation, chat, as well as code reviews directly in the IDE at no cost with the Gemini Code Assist IDE Extension. Footnotes
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Code Review
The pull request correctly fixes the target_roles enum mismatch, which resolves the database migration failure. The new migrations establish a comprehensive notification system. However, I've identified a critical security vulnerability and several high-severity performance issues that should be addressed.
The main concerns are:
- A
SECURITY DEFINERfunction lacks proper authorization checks, allowing users to perform actions on behalf of others. - Several RLS policies and functions use subqueries that can execute for each row, leading to poor performance on large tables. I've suggested creating and using helper functions to mitigate this.
- There are also opportunities to improve the SQL style for better readability and performance.
Please review the detailed comments for specific suggestions.
Important
Fixes #<issue number>What & Why
What: Align notification migrations to use
user_role[]fortarget_rolesand keep RLS/aggregation functions consistent with the enum.Why: Migration
20250822140000_create_notifications_system.sqlfails because the policy comparestext[]withuser_role[](no operator). Matching the enum fixes SQLSTATE 42883 and letsdb pushsucceed.Fixes #307
Pre-PR Checklist
Run these:
pnpm type-checkpnpm format:checkpnpm lintpnpm buildpnpm i18n:check(if applicable)Type
Screenshots (if UI changes)
N/A