elsa-core/doc/migrations
Sipke Schoorstra 7e8e7aa012
docs(secrets): document null-tenant index gaps and the MySql TFM pin (#7998)
* docs(secrets): document null-tenant index gaps and the MySql TFM pin

The per-tenant unique indexes only backstop rows whose TenantId is non-null,
so single-tenant deployments and pre-upgrade rows fall back to the pre-save
existence checks for name uniqueness. Recorded in secrets-tenancy.md and the
authorization-model guide, with a comment at the EFCore secret repository's
write path.

Also documents why Elsa.Secrets.Persistence.EFCore.MySql stays pinned to
net8.0/net9.0: Pomelo.EntityFrameworkCore.MySql tops out at EF Core 9, and
the project references Elsa.Persistence.EFCore.MySql which carries the same
pin. Comment-only csproj change; no behavior changes anywhere in this commit.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* docs(secrets): say plainly that the null-tenant backfill is not a fix

The guide implied backfilling TenantId to "" restored the uniqueness
guarantee in single-tenant mode. It does not: disabled-mode writes keep
persisting null, so new rows still land outside the index and two
concurrent creates can still commit the same name.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-08-27 11:45:49 +02:00
..
authorization-model.md docs(secrets): document null-tenant index gaps and the MySql TFM pin (#7998) 2026-08-27 11:45:49 +02:00
external-authentication-persistence.md feat(auth)!: structured authorization model, phases 1-6 (#7980) 2026-08-24 23:44:55 +02:00
external-authentication.md feat(auth)!: structured authorization model, phases 1-6 (#7980) 2026-08-24 23:44:55 +02:00
secrets-tenancy.md docs(secrets): document null-tenant index gaps and the MySql TFM pin (#7998) 2026-08-27 11:45:49 +02:00