ci: run the Supabase RLS/stack integration suite on every PR
The gated stack tests (backend/src/__tests__/integration/*.supabase.test.ts) prove the deny-all RLS firewall and the auth<->API contract against a real local Supabase stack, but no CI trigger ever set the SUPABASE_TEST_* env vars, so they silently self-skipped on every PR. Add a workflow that boots the stack on the runner (supabase CLI pinned, minimal service set: db, auth, rest, kong), bootstraps the database the way backend/scripts/test-stack.sh does, and runs the suite. No secrets: everything is local to the runner. The bootstrap loads schema.sql and then applies every dated migration on top in filename order, which doubles as a schema-drift smoke test: the snapshot and the migrations must apply cleanly together. Running it surfaced five migrations that could not apply on top of the current schema.sql - three whose backfills read documents columns that later migrations moved to document_versions, and two overview RPCs whose return row type `create or replace` cannot change. Guard the backfills on the historical columns' existence and drop-before-create the RPCs (the pattern 20260703_02 already uses); behavior on era deployments is unchanged, and the full sequence now applies cleanly end to end (verified locally: fresh stack, schema + 44 migrations, 5/5 stack tests green). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
| Repository | open-legal-products/mike |
|---|---|
| Author | Amalanand Muthukumaran <mamalanand3@gmail.com> |
| Authored | |
| Committed | |
| Parents | 8313af19 |
| Stats | 6 files changed , +229 , -48 |
| Part of | Add schema drift checks for database upgrades |
Capture this commit into my fork
Download a Markdown prompt that tells Claude how to port this
exact commit into your working tree. Run it via
claude -p < capture-commit-2288419a.md
from inside the repo you want the change in.