Files
cairnobs/metadata/migrations/0024_create_dashboard_permissions.sql
jcoffey-dev f756a9d4f6 Rename the project spec and update every reference to it
The charter file carried a tool-specific name while being the repository's own
document: mission, non-negotiable constraints, the pinned stack, repo
conventions and phase status, cited as authority by thirty files across the
agent, api, deploy, docs, search and terraform trees.

PROJECT-SPEC.md says what it is. All 42 references are updated in the same
commit, including the relative link in docs/status.md, so nothing points at a
filename that no longer exists.
2026-08-28 15:57:12 -07:00

15 lines
738 B
SQL

-- Additive-only per-resource grant: lets a specific user exceed their
-- tenant-baseline role on one dashboard (e.g. an Editor granted Admin on
-- a dashboard they don't own). No deny-overrides -- named non-goal in
-- /docs/phase-4-rbac-design.md and PROJECT-SPEC.md's Phase 4 exit criteria.
CREATE TABLE IF NOT EXISTS dashboard_permissions
(
id UUID PRIMARY KEY,
dashboard_id UUID NOT NULL REFERENCES dashboards(id) ON DELETE CASCADE,
user_id UUID NOT NULL REFERENCES users(id) ON DELETE CASCADE,
role TEXT NOT NULL CHECK (role IN ('viewer', 'editor', 'admin')),
granted_by UUID REFERENCES users(id),
created_at TIMESTAMPTZ NOT NULL DEFAULT now(),
UNIQUE (dashboard_id, user_id)
)