Skip to content

fix: 복구 버전에서 통합 고객 데이터 변경 차단 - #59

Merged
SUMZ711 merged 1 commit into
mainfrom
fix/rollback-customer-writes
Oct 6, 2026
Merged

SUMZ711 merged 1 commit into
mainfrom
fix/rollback-customer-writes

Conversation

@SUMZ711

@SUMZ711 SUMZ711 commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

PR #56의 새 schema가 적용된 후 구버전으로 rollback하면, 기존 고객 수정·삭제·첨부 변경 경로가 통합 고객 데이터를 덮어쓰거나 일부 연결만 변경할 수 있습니다. 구버전 baseline에서 인증된 /api/customers 및 하위 경로의 쓰기 요청을 CustomerMerge table 생성 이후 handler 진입 전에 거절합니다. 읽기와 다른 WARP 기능은 유지합니다.

  • 고객 행을 읽지 않고 sqlite_master의 table 존재 여부만 매 요청 확인합니다. schema 적용 전에는 기존 쓰기를 허용하고, 적용 후에는 409, 메타데이터 조회 실패에는 503을 반환합니다.
  • POST/PUT/PATCH/DELETE와 URL 인코딩된 경로도 보호합니다. 기존 auth/account boundary는 유지합니다.
  • migration이 candidate 시작 전에 실행되므로 schema 적용부터 새 버전 전환까지, 그리고 구버전으로 rollback한 동안 고객 기능은 임시 읽기 전용입니다. 새 alias·버전 검증 앱으로 복구한 후 쓰기를 재개합니다. guard 우회·table 삭제·DB restore는 사용하지 않습니다.
  • 신규 feature PR #56에서는 baseline 전용 guard/test를 제거하며, 실제 직전 slot 이미지에는 이 보호를 보존합니다. 기존 legacy merge POST는 #58에서 이미 차단했습니다.

승인 범위: #56 (comment)
관련: #56, #57, #58. 공유 IAM·인프라·비밀값은 변경하지 않습니다.

검증: 실제 proxy를 합성 auth와 in-memory SQLite로 실행하여 schema 전후 전환, encoded paths, 모든 쓰기, GET/HEAD/OPTIONS 및 다른 경로 유지, 실패 시 차단 확인. Python 31개, typecheck, proxy lint, diff check 통과.

@SUMZ711
SUMZ711 merged commit e85588a into main Oct 6, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant