feat: gated domain signup spaces and migration preflight (LM-16549) - #21
Conversation
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Team Run ID: 📒 Files selected for processing (10)
Included review availability: This review used your included allowance. 0 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 1 review per hour. 📝 WalkthroughWalkthroughThe change adds opt-in exact-domain signup routing to existing private spaces in the default signup organization. It also adds a dry-run and apply migration, a CLI for that migration, and rollout guidance describing configuration, access limits, verification, and rollback. ChangesDomain-based space assignment
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~25 minutes Change: Feature Sequence Diagram(s)sequenceDiagram
participant SignupRequest
participant DrizzleAdapter
participant getSignupSpaceId
participant Database
SignupRequest->>DrizzleAdapter: createUser with email
DrizzleAdapter->>getSignupSpaceId: resolve configured domain mapping
getSignupSpaceId-->>DrizzleAdapter: SpaceId or null
DrizzleAdapter->>Database: validate space and default organization
DrizzleAdapter->>Database: add user to space as member
Merge Risk: ⚪ Minimal · up to No concrete merge-blocking issue is established. Keep signup routing disabled until provisioning and access verification are complete; private-space membership alone does not provide organization-wide content isolation. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 6 functions across 9 files. (1 skipped: 1 unsupported.)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Comment |
There was a problem hiding this comment.
🔍 Devin Review: 1 flag
Not posted on this PR by your GitHub settings — view it in Devin Review. (Configure)
Adds opt-in signup domain assignment to an existing private space inside the configured default organization. Exact matching domains receive ordinary space membership; other domains retain existing behavior. Invalid/missing/foreign/public targets fail the signup transaction. Routing stays disabled until an operator provides a recorded live space ID.
Includes a generic dry-run-first provisioning/membership migration tool. It validates target identity and private settings, preserves existing roles, serializes apply runs, and removes only explicitly selected ordinary source-space memberships. Customer identifiers, production IDs, and membership details are not embedded.
Tracks LM-16549. This PR is ready for code review. Provisioning, migration, merge, and deployment remain blocked on the rollout decisions below.
Validation:
Rollout blockers:
See deploy/domain-space-rollout.md for configuration, dry-run inputs, acceptance matrix, rollout sequence, and rollback limits.