Require explicit approver_ids when publishing a document major version
The publish flow ignored a document's stored default approvers and only requested approval when approver_ids were passed in the call, so a major publish with no approver_ids silently published directly without routing through the approval flow — there was no way to tell "caller forgot approvers" (null) from "caller wants no approval" (empty). Make approver_ids an explicit choice, enforced once in the service so it covers every caller (console, MCP, n8n): - major publish: approver_ids must be set; an empty list publishes directly, a non-empty list requests approval. - minor publish: approver_ids must be omitted (approvers are ignored). Validate this in PublishDocumentRequest.Validate(), update the console publish dialog and the n8n publish node to honour the contract, document it in the MCP tool spec, and cover it with e2e tests. Signed-off-by: Sacha Al Himdani <sacha@getprobo.com>
This commit is contained in:
@@ -184,6 +184,27 @@ func (req *PublishDocumentRequest) Validate() error {
|
||||
})
|
||||
v.Check(req.Changelog, "changelog", validator.Required(), validator.SafeText(5000))
|
||||
|
||||
// approver_ids must be an explicit choice for a major publish (an empty list
|
||||
// publishes directly without approval, a non-empty list requests approval)
|
||||
// and must be omitted for a minor publish, which ignores approvers.
|
||||
if req.Minor && req.ApproverIDs != nil {
|
||||
v.Check(req.ApproverIDs, "approver_ids", func(any) *validator.ValidationError {
|
||||
return &validator.ValidationError{
|
||||
Code: validator.ErrorCodeCustom,
|
||||
Message: "must not be set when publishing a minor version",
|
||||
}
|
||||
})
|
||||
}
|
||||
|
||||
if !req.Minor && req.ApproverIDs == nil {
|
||||
v.Check(req.ApproverIDs, "approver_ids", func(any) *validator.ValidationError {
|
||||
return &validator.ValidationError{
|
||||
Code: validator.ErrorCodeCustom,
|
||||
Message: "must be set when publishing a major version: provide approver profile IDs to request approval, or an empty list to publish directly without approval",
|
||||
}
|
||||
})
|
||||
}
|
||||
|
||||
return v.Error()
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user