From 9ee8cb18b1017dce11e7c8c9b7fafad301cb766e Mon Sep 17 00:00:00 2001 From: Anders Betts Date: Sun, 20 Sep 2026 10:36:09 +0200 Subject: db: make attachments append-only (schema v7) --- docs/STATE.md | 13 +++++++------ 1 file changed, 7 insertions(+), 6 deletions(-) (limited to 'docs/STATE.md') diff --git a/docs/STATE.md b/docs/STATE.md index 526c1a6..e210e1c 100644 --- a/docs/STATE.md +++ b/docs/STATE.md @@ -172,9 +172,9 @@ check. and `full:true` re-hashes attachment content; result carries `vouchers_checked`, `unbalanced_vouchers`, `attachments_checked` and the first bad voucher/audit/attachment id. TUI Revision shows both counts and - the bad ids. **Found while testing: `attachments` has no - append-only triggers** (COMPLIANCE.md ยง2 claims it does); content changes - are detected only by `audit.verify full:true`. + the bad ids. Fixed in schema v7: `attachments` now has + `no_update`/`no_delete` triggers; `audit.verify full:true` still detects + on-disk tampering. 5. ~~`report.general_ledger` and `report.voucher_list`~~ implemented (Huvudbok, Verifikationslista) with Kapitas-style TUI tables; the ledger API supports `accounts`/`from`/`to`, the list an optional `series`. @@ -207,7 +207,7 @@ check. ## Environment / how to run -- **Deployed**: `scripts/deploy.sh` (latest `v0.1.44`, healthy on nas). +- **Deployed**: `scripts/deploy.sh` (latest `v0.1.48`, healthy on nas). Live daemon `tls:bokf.makandra.eu:8788`, token `~/.config/bokf/migration-token` (scopes `read,write`; owner-only actions like closing years must be done by the human in the TUI). Git remote @@ -254,8 +254,9 @@ check. - Never commit unless the human asks. - SQLite files must not be backed up live with restic; use `backup.snapshot` (`VACUUM INTO`) and point restic at the snapshots. -- Schema version is 6 (v3 moms rules; v4/v6 year info; v5 org - description/shares + board members); forward migrations are in `db.c`. +- Schema version is 7 (v3 moms rules; v4/v6 year info; v5 org + description/shares + board members; v7 attachments append-only triggers); + forward migrations are in `db.c`. ## Makandra driftstatus (org 2) -- cgit v1.3