Skip to content

Seed InternalUser account + Internal Service Accounts team

Placeholder ppxd requested to merge feat/internal-user-seeder into main

Summary

Phase 2 of the Tentacle install-script bootstrap-key redesign. Re-opened after PR #335 was auto-closed when its base (PR #334) merged + deleted its branch.

`InternalUserSeeder` (Order=350) ensures:

  • `user_account` row id=8888 exists (raw SQL INSERT — EF rejects explicit Id for sequence-default columns)
  • "Internal Service Accounts" team exists in space 0 with warning description
  • `SystemServiceAccount` role assigned to team with `SpaceId=null` (cross-space)
  • InternalUser is a team member
  • Normalises legacy `display_name='internal_user'` (from `001_initial_schema.sql`) to canonical `'System'`

End-to-end integration test `SeedRuns_InternalUserHasMachineCreatePermission_ViaAuthorizationService` walks the full `IAuthorizationService.CheckPermissionAsync` path — if this passes, register calls carrying InternalUser-owned API keys will pass MachineCreate.

Least-privilege test `SeedRuns_InternalUserDoesNotHaveMachineDelete` guards against role widening.

Test plan

  • Unit: 5230/5230 pass
  • Integration: 8 new tests pin DB-level invariants
  • Build: zero errors
  • CI: fix for legacy display_name normalisation merged on this branch (commit `7b67f8b6`)

🤖 Generated with Claude Code

Merge request reports

Loading