Skip to content

fix(publication): keep document index rows of superseded versions - #677

Open
midego1 wants to merge 2 commits into
unopim:3.xfrom
midego1:fix/publication-keep-superseded-document-index
Open

midego1 wants to merge 2 commits into
unopim:3.xfrom
midego1:fix/publication-keep-superseded-document-index

Conversation

@midego1

@midego1 midego1 commented Sep 4, 2026 •

Copy link
Copy Markdown
Contributor

Problem

SyncPublicationVersionDocuments deletes the publication_version_documents rows of every other version for the published (publication, locale) on each publish. That destroys the only record of which documents a sealed version attested to. The moment a version is superseded, its declaration of conformity is no longer resolvable through the asset proxy, even though the version row and its payload are kept immutable on purpose.

For a Digital Product Passport this matters: the regulation requires the passport state a product was placed on the market with to remain reachable for the product's lifetime, documents included. Anything built on top of the version history (a per-version public route, an audit export, a regulator view) currently finds versions whose documents 404.

Fix

Keep the rows. The index now records which version references which path, for every version, and the docblock says so.

Servability is decided at request time in PublicationAssetController::isReferenced() against the referencing version's state (is_current and not redacted), so the public contract is unchanged: only documents of a current, unredacted version are served from the publication-level asset URL. PrunePublicationVersionDocumentsOnRedaction is untouched and still prunes on erasure.

No migration. The unique key (publication_version_id, path) already scopes rows per version.

Tests

  • keeps the document index rows of a superseded version: after a republish with a fresh document, both versions still have their row.
  • serves only the paths the current version references once a version is superseded: the new path is 200, the superseded one is 404. This is the guard that the change does not widen what is publicly reachable.

Helper republishWithDocument() added to PublicationTestCase for the second publish.

Existing PublicationAssetTest and the redaction tests pass unchanged.

Related

Found while assessing DPP lifetime reachability for a customer. Companion PR: #678 fixes the other half of the same problem (document copies are not content-addressed, so a re-issued file never seals a new version).

Every publish deleted the `publication_version_documents` rows of all
other versions for that (publication, locale). That destroyed the only
record of which documents a sealed version attested to: the moment a
version was superseded its declaration of conformity was no longer
resolvable, even though the version row and payload were kept
immutable on purpose.

Keep the rows. The index now records which version references which
path, for every version. Servability is decided at request time in the
asset controller against the referencing version's state (`is_current`
and not redacted), so the public contract is unchanged: only documents
of a current, unredacted version are served from the publication-level
asset URL. Redaction still prunes the index for erasure.

Two tests lock both halves: superseded rows survive a republish, and a
path only a superseded version references is still 404 publicly.
@midego1
midego1 force-pushed the fix/publication-keep-superseded-document-index branch from 3fe9e3c to f9c96be Compare September 4, 2026 08:29
@midego1

midego1 commented Sep 4, 2026

Copy link
Copy Markdown
Contributor Author

Context, motivation and suggested review order for this and the related PRs: #683

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant