Skip to content

Design recovery-safe database enforcement for lab result projections #298

Description

@evangauer

Risk

lab_results is a mutable current-state projection over append-only lab_result_events. The application service writes both in one transaction and this branch narrows the application role to only the lifecycle/follow-up projection columns, but PostgreSQL does not yet prove at commit that every projection transition has a matching immutable event.

A future SQL path with the allowed role could therefore update status, review attribution, result values, or follow-up state without appending corresponding evidence.

Required design

  • enforce projection/event agreement at transaction commit, not between the service's two legitimate statements
  • preserve idempotent retries and the existing operation-id/payload-hash contract
  • remain compatible with ordered portable restore, recovery hold, and explicit owner-only ledger maintenance
  • cover completed, reviewed, follow-up assignment/reassignment, and follow-up completion transitions
  • fail safely for direct projection-only writes in disposable PostgreSQL tests
  • define how legacy rows with truthful current projections but incomplete event history are reconciled without fabricating actors or timestamps

Do not add a blanket immediate trigger that breaks the existing atomic service transaction or restore ordering. This remains a release gate after the privilege narrowing in the lab-integrity branch.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions