Enforce Lite-mode scoping server-side; rename IsChild→IsLite (schema kept) - #40
Merged
Merged
Conversation
…ma kept) Lite-mode (restricted) home members are enforced beyond the UI: - FinancePlans reads/writes, FinanceDocumentItemViews (insight/search), GetFinanceOverviewKeyFigure and GetAccountBalance(Ex) are scoped to the member's own accounts/control centers; foreign targets get 401. - Overview outgo figures normalized to positive magnitudes; document-item view rounds expense amounts to 2 decimals before sign flip. - Version bumped to 1.8.400. Terminology: HomeMember.IsChild -> IsLite across the EF model, the EDM/OData wire property, controllers and tests. The SQLite column keeps its historical name ISCHILD via explicit [Column] mapping - no schema change, no upgrade step. Integration tests pin the new wire name (payload contains IsLite, never IsChild). Tests: 412 unit + 6 integration pass (dotnet test achihapi.sln). Co-Authored-By: Claude Code <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Two coupled batches, one commit (
f3e9bf7):1. Lite-mode (restricted home member) server-side scoping
FinancePlansreads/writes,FinanceDocumentItemViews(insight/search pipeline),GetFinanceOverviewKeyFigureandGetAccountBalance(Ex)now scope to the member's own accounts/control centers; foreign targets get 401 (GetAccountBalancealso gained an account↔home binding it previously lacked).ROUND(… , 2)applied before the expense sign flip (DatabaseSeederview +FinanceDocumentmodel).FinanceLiteScopeTest(unit) +FinanceLiteScopeODataTest(integration over real HTTP).2.
IsChild→IsLiterename — code + wire, schema untouched[Column("ISCHILD")]— no schema change, no SchemaUpgrade step; dev server boots cleanly against the existinghih.db.EdmModelBuilderis model-bound, so the OData/JSON property becomesIsLiteautomatically for serialization and PUT/POST binding (13 controllers' LINQ filters/guards renamed, deadUserInfomodel included).HomeMemberspayload contains"IsLite", never"IsChild".Compatibility note ⚠
Pairs with achihui PR #365 (UI wire flipped to
IsLite). Deploy the two together: an old UI PUTingIsChildagainst this API is rejected by strict OData binding (loud); a new UI against the old API would silently treat all members as non-Lite.Test plan
dotnet build achihapi.sln— 0 errorsdotnet test— 412 unit + 6 integration pass (incl. new wire-format assertions)POST /healthHealthy after restart against real DB🤖 Generated with Claude Code