Repository navigation
Conversation
midego1
force-pushed
the
fix/publication-keep-superseded-document-index
branch
2 times, most recently
from
September 4, 2026 07:31
ee0841c to
3fe9e3c
Compare
Every publish deleted the `publication_version_documents` rows of all other versions for that (publication, locale). That destroyed the only record of which documents a sealed version attested to: the moment a version was superseded its declaration of conformity was no longer resolvable, even though the version row and payload were kept immutable on purpose. Keep the rows. The index now records which version references which path, for every version. Servability is decided at request time in the asset controller against the referencing version's state (`is_current` and not redacted), so the public contract is unchanged: only documents of a current, unredacted version are served from the publication-level asset URL. Redaction still prunes the index for erasure. Two tests lock both halves: superseded rows survive a republish, and a path only a superseded version references is still 404 publicly.
midego1
force-pushed
the
fix/publication-keep-superseded-document-index
branch
from
September 4, 2026 08:29
3fe9e3c to
f9c96be
Compare
Contributor
Author
|
Context, motivation and suggested review order for this and the related PRs: #683 |
This was referenced Sep 4, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
SyncPublicationVersionDocumentsdeletes thepublication_version_documentsrows of every other version for the published(publication, locale)on each publish. That destroys the only record of which documents a sealed version attested to. The moment a version is superseded, its declaration of conformity is no longer resolvable through the asset proxy, even though the version row and its payload are kept immutable on purpose.For a Digital Product Passport this matters: the regulation requires the passport state a product was placed on the market with to remain reachable for the product's lifetime, documents included. Anything built on top of the version history (a per-version public route, an audit export, a regulator view) currently finds versions whose documents 404.
Fix
Keep the rows. The index now records which version references which path, for every version, and the docblock says so.
Servability is decided at request time in
PublicationAssetController::isReferenced()against the referencing version's state (is_currentand not redacted), so the public contract is unchanged: only documents of a current, unredacted version are served from the publication-level asset URL.PrunePublicationVersionDocumentsOnRedactionis untouched and still prunes on erasure.No migration. The unique key
(publication_version_id, path)already scopes rows per version.Tests
keeps the document index rows of a superseded version: after a republish with a fresh document, both versions still have their row.serves only the paths the current version references once a version is superseded: the new path is 200, the superseded one is 404. This is the guard that the change does not widen what is publicly reachable.Helper
republishWithDocument()added toPublicationTestCasefor the second publish.Existing
PublicationAssetTestand the redaction tests pass unchanged.Related
Found while assessing DPP lifetime reachability for a customer. Companion PR: #678 fixes the other half of the same problem (document copies are not content-addressed, so a re-issued file never seals a new version).