7c4302d02a
## Summary Fixes #20076 (supersedes #20250) When a related record is soft-deleted, the frontend displays "Not shared" (lock icon) because it sees a populated FK but a null relation object. This is misleading -- the record was deleted, not permission-restricted. **Backend fix** (`process-nested-relations-v2.helper.ts`): - For MANY_TO_ONE relations, widen the relation query with `.withDeleted()` and include `deletedAt` in the select - In `assignRelationResults`, if the matched record has `deletedAt` set, nullify both the FK and the relation object in the API response - Records filtered by RLS are still not returned (even with `withDeleted()`), so they correctly continue to show "Not shared" - Strip `deletedAt` from relation results before returning to the client **Frontend fix** (`RelationFromManyFieldDisplay.tsx`): - For ONE_TO_MANY junction relations, return `null` instead of `<ForbiddenFieldDisplay />` when junction records exist but target records are unavailable ### Three cases now handled correctly: | Scenario | FK in response | Relation object | Frontend display | |---|---|---|---| | **Live record** | `"abc"` | `{ id: "abc", ... }` | Record chip | | **Soft-deleted record** | `null` | `null` | Empty cell | | **RLS-hidden record** | `"abc"` | `null` | "Not shared" | ## Test plan - [ ] Create a record with a MANY_TO_ONE relation (e.g., a person linked to a company) - [ ] Soft-delete the related record (the company) - [ ] Verify the relation field shows an empty cell, not "Not shared" - [ ] Restore the related record and verify the relation reappears - [ ] Verify that RLS-hidden relations still show "Not shared" Made with [Cursor](https://cursor.com) Co-authored-by: Cursor <cursoragent@cursor.com>
136 lines
3.9 KiB
TypeScript
136 lines
3.9 KiB
TypeScript
import { randomUUID } from 'crypto';
|
|
|
|
import { createOneOperationFactory } from 'test/integration/graphql/utils/create-one-operation-factory.util';
|
|
import { deleteOneOperationFactory } from 'test/integration/graphql/utils/delete-one-operation-factory.util';
|
|
import { destroyOneOperationFactory } from 'test/integration/graphql/utils/destroy-one-operation-factory.util';
|
|
import { findOneOperationFactory } from 'test/integration/graphql/utils/find-one-operation-factory.util';
|
|
import { makeGraphqlAPIRequest } from 'test/integration/graphql/utils/make-graphql-api-request.util';
|
|
import { restoreOneOperationFactory } from 'test/integration/graphql/utils/restore-one-operation-factory.util';
|
|
|
|
const PERSON_WITH_COMPANY_GQL_FIELDS = `
|
|
id
|
|
companyId
|
|
company {
|
|
id
|
|
name
|
|
}
|
|
`;
|
|
|
|
describe('soft-deleted relation', () => {
|
|
const companyId = randomUUID();
|
|
const personId = randomUUID();
|
|
|
|
beforeAll(async () => {
|
|
await makeGraphqlAPIRequest(
|
|
createOneOperationFactory({
|
|
objectMetadataSingularName: 'company',
|
|
gqlFields: 'id name',
|
|
data: { id: companyId, name: 'SoftDeleteTestCompany' },
|
|
}),
|
|
);
|
|
|
|
await makeGraphqlAPIRequest(
|
|
createOneOperationFactory({
|
|
objectMetadataSingularName: 'person',
|
|
gqlFields: PERSON_WITH_COMPANY_GQL_FIELDS,
|
|
data: {
|
|
id: personId,
|
|
companyId,
|
|
name: { firstName: 'SoftDeleteTest' },
|
|
},
|
|
}),
|
|
);
|
|
});
|
|
|
|
afterAll(async () => {
|
|
// Ensure records are not soft-deleted before destroying
|
|
await makeGraphqlAPIRequest(
|
|
restoreOneOperationFactory({
|
|
objectMetadataSingularName: 'company',
|
|
gqlFields: 'id',
|
|
recordId: companyId,
|
|
}),
|
|
);
|
|
|
|
await makeGraphqlAPIRequest(
|
|
destroyOneOperationFactory({
|
|
objectMetadataSingularName: 'person',
|
|
gqlFields: 'id',
|
|
recordId: personId,
|
|
}),
|
|
);
|
|
|
|
await makeGraphqlAPIRequest(
|
|
destroyOneOperationFactory({
|
|
objectMetadataSingularName: 'company',
|
|
gqlFields: 'id',
|
|
recordId: companyId,
|
|
}),
|
|
);
|
|
});
|
|
|
|
it('should return company relation when company is live', async () => {
|
|
const response = await makeGraphqlAPIRequest(
|
|
findOneOperationFactory({
|
|
objectMetadataSingularName: 'person',
|
|
gqlFields: PERSON_WITH_COMPANY_GQL_FIELDS,
|
|
filter: { id: { eq: personId } },
|
|
}),
|
|
);
|
|
|
|
const person = response.body.data.person;
|
|
|
|
expect(person.companyId).toBe(companyId);
|
|
expect(person.company).toBeDefined();
|
|
expect(person.company.id).toBe(companyId);
|
|
expect(person.company.name).toBe('SoftDeleteTestCompany');
|
|
});
|
|
|
|
it('should nullify companyId when company is soft-deleted', async () => {
|
|
await makeGraphqlAPIRequest(
|
|
deleteOneOperationFactory({
|
|
objectMetadataSingularName: 'company',
|
|
gqlFields: 'id deletedAt',
|
|
recordId: companyId,
|
|
}),
|
|
);
|
|
|
|
const response = await makeGraphqlAPIRequest(
|
|
findOneOperationFactory({
|
|
objectMetadataSingularName: 'person',
|
|
gqlFields: PERSON_WITH_COMPANY_GQL_FIELDS,
|
|
filter: { id: { eq: personId } },
|
|
}),
|
|
);
|
|
|
|
const person = response.body.data.person;
|
|
|
|
expect(person.companyId).toBeNull();
|
|
expect(person.company).toBeNull();
|
|
});
|
|
|
|
it('should restore company relation when company is restored', async () => {
|
|
await makeGraphqlAPIRequest(
|
|
restoreOneOperationFactory({
|
|
objectMetadataSingularName: 'company',
|
|
gqlFields: 'id deletedAt',
|
|
recordId: companyId,
|
|
}),
|
|
);
|
|
|
|
const response = await makeGraphqlAPIRequest(
|
|
findOneOperationFactory({
|
|
objectMetadataSingularName: 'person',
|
|
gqlFields: PERSON_WITH_COMPANY_GQL_FIELDS,
|
|
filter: { id: { eq: personId } },
|
|
}),
|
|
);
|
|
|
|
const person = response.body.data.person;
|
|
|
|
expect(person.companyId).toBe(companyId);
|
|
expect(person.company).toBeDefined();
|
|
expect(person.company.id).toBe(companyId);
|
|
});
|
|
});
|