Browse Source

Add revision_date to org policies (#7571)

* Add revision_date to org policies

Org policy JSON responses never included a revisionDate field, unlike
every other synced entity. The official Bitwarden server always sets
it, and current official clients (recently migrated to the WASM SDK's
typed PolicyView) now assume it is always a valid date string. Its
absence deserializes to undefined client-side, which then throws
(RangeError: Invalid time value) when the client formats it, breaking
the whole policy sync pipeline and silently emptying the vault view in
the browser and desktop apps.

Adds a revision_date column (mirroring the existing pattern used by
Send), stamped on creation and bumped on every save.

* Fix migration correctness for org policy revision_date

Caught by review: SQLite rejects non-constant defaults in ALTER TABLE
ADD COLUMN, so the sqlite migration would fail outright on every
existing installation (vaultwarden's default backend) rather than the
postgresql setup this was developed against.

- sqlite/mysql: add the column with a constant placeholder default,
  then backfill via UPDATE, since neither allows a volatile default
  in ALTER TABLE ADD COLUMN (mysql does allow it, but a constant
  keeps the three backends' migrations symmetric).
- mysql: use DATETIME instead of TIMESTAMP, matching this repo's
  existing revision_date columns, and backfill with UTC_TIMESTAMP()
  instead of a session-timezone-dependent CURRENT_TIMESTAMP.
- postgresql: backfill with `now() AT TIME ZONE 'utc'` instead of a
  DEFAULT now(), since assigning timestamptz now() into this naive
  TIMESTAMP column would otherwise cast through the server's TimeZone
  GUC and store local wall-clock instead of UTC on non-UTC servers.
- mysql/postgresql: add a real down.sql (DROP COLUMN) instead of
  leaving it empty.

* Move org policy revision_date migration after the latest one

---------

Co-authored-by: Daniel García <dani-garcia@users.noreply.github.com>
pull/7127/merge
will-lottkowitz-prism 3 days ago
committed by GitHub
parent
commit
d1cbd027cd
No known key found for this signature in database GPG Key ID: B5690EEEBB952194
  1. 1
      migrations/mysql/2026-10-07-120000_add_org_policy_revision_date/down.sql
  2. 7
      migrations/mysql/2026-10-07-120000_add_org_policy_revision_date/up.sql
  3. 1
      migrations/postgresql/2026-10-07-120000_add_org_policy_revision_date/down.sql
  4. 9
      migrations/postgresql/2026-10-07-120000_add_org_policy_revision_date/up.sql
  5. 0
      migrations/sqlite/2026-10-07-120000_add_org_policy_revision_date/down.sql
  6. 6
      migrations/sqlite/2026-10-07-120000_add_org_policy_revision_date/up.sql
  7. 18
      src/db/models/org_policy.rs
  8. 1
      src/db/schema.rs

1
migrations/mysql/2026-10-07-120000_add_org_policy_revision_date/down.sql

@ -0,0 +1 @@
ALTER TABLE org_policies DROP COLUMN revision_date;

7
migrations/mysql/2026-10-07-120000_add_org_policy_revision_date/up.sql

@ -0,0 +1,7 @@
-- DATETIME (not TIMESTAMP) to match this repo's convention for revision_date
-- columns elsewhere, and to avoid MySQL's implicit session-timezone
-- conversion and 2038 range limit on TIMESTAMP.
ALTER TABLE org_policies
ADD COLUMN revision_date DATETIME NOT NULL DEFAULT '1970-01-01 00:00:00';
UPDATE org_policies SET revision_date = UTC_TIMESTAMP();

1
migrations/postgresql/2026-10-07-120000_add_org_policy_revision_date/down.sql

@ -0,0 +1 @@
ALTER TABLE org_policies DROP COLUMN revision_date;

9
migrations/postgresql/2026-10-07-120000_add_org_policy_revision_date/up.sql

@ -0,0 +1,9 @@
-- Backfill via `now() AT TIME ZONE 'utc'` rather than a DEFAULT of now():
-- assigning timestamptz now() into a naive TIMESTAMP column casts through
-- the server's TimeZone GUC, so a DEFAULT now() would store local wall-clock
-- instead of UTC on non-UTC servers, unlike every other naive-UTC timestamp
-- column in this schema.
ALTER TABLE org_policies
ADD COLUMN revision_date TIMESTAMP NOT NULL DEFAULT '1970-01-01 00:00:00';
UPDATE org_policies SET revision_date = (now() AT TIME ZONE 'utc');

0
migrations/sqlite/2026-10-07-120000_add_org_policy_revision_date/down.sql

6
migrations/sqlite/2026-10-07-120000_add_org_policy_revision_date/up.sql

@ -0,0 +1,6 @@
-- SQLite forbids non-constant defaults in ALTER TABLE ... ADD COLUMN, so add
-- the column with a constant placeholder and backfill separately.
ALTER TABLE org_policies
ADD COLUMN revision_date DATETIME NOT NULL DEFAULT '1970-01-01 00:00:00';
UPDATE org_policies SET revision_date = CURRENT_TIMESTAMP;

18
src/db/models/org_policy.rs

@ -1,3 +1,4 @@
use chrono::{NaiveDateTime, Utc};
use derive_more::{AsRef, From}; use derive_more::{AsRef, From};
use diesel::prelude::*; use diesel::prelude::*;
use serde::Deserialize; use serde::Deserialize;
@ -11,6 +12,7 @@ use crate::{
schema::{org_policies, users_organizations}, schema::{org_policies, users_organizations},
}, },
error::MapResult, error::MapResult,
util::format_date,
}; };
use super::{Membership, MembershipId, MembershipStatus, MembershipType, OrganizationId, TwoFactor, UserId}; use super::{Membership, MembershipId, MembershipStatus, MembershipType, OrganizationId, TwoFactor, UserId};
@ -24,6 +26,7 @@ pub struct OrgPolicy {
pub atype: i32, pub atype: i32,
pub enabled: bool, pub enabled: bool,
pub data: String, pub data: String,
pub revision_date: NaiveDateTime,
} }
// https://github.com/bitwarden/server/blob/9ebe16587175b1c0e9208f84397bb75d0d595510/src/Core/AdminConsole/Enums/PolicyType.cs // https://github.com/bitwarden/server/blob/9ebe16587175b1c0e9208f84397bb75d0d595510/src/Core/AdminConsole/Enums/PolicyType.cs
@ -77,6 +80,7 @@ impl OrgPolicy {
atype: atype as i32, atype: atype as i32,
enabled, enabled,
data, data,
revision_date: Utc::now().naive_utc(),
} }
} }
@ -92,7 +96,7 @@ impl OrgPolicy {
"type": self.atype, "type": self.atype,
"data": data_json, "data": data_json,
"enabled": self.enabled, "enabled": self.enabled,
"revisionDate": null, "revisionDate": format_date(&self.revision_date),
"object": "policy", "object": "policy",
}); });
@ -110,11 +114,13 @@ impl OrgPolicy {
/// Database methods /// Database methods
impl OrgPolicy { impl OrgPolicy {
pub async fn save(&self, conn: &DbConn) -> EmptyResult { pub async fn save(&mut self, conn: &DbConn) -> EmptyResult {
self.revision_date = Utc::now().naive_utc();
db_run! { conn: db_run! { conn:
sqlite, mysql { sqlite, mysql {
match diesel::replace_into(org_policies::table) match diesel::replace_into(org_policies::table)
.values(self) .values(&*self)
.execute(conn) .execute(conn)
{ {
Ok(_) => Ok(()), Ok(_) => Ok(()),
@ -122,7 +128,7 @@ impl OrgPolicy {
Err(diesel::result::Error::DatabaseError(diesel::result::DatabaseErrorKind::ForeignKeyViolation, _)) => { Err(diesel::result::Error::DatabaseError(diesel::result::DatabaseErrorKind::ForeignKeyViolation, _)) => {
diesel::update(org_policies::table) diesel::update(org_policies::table)
.filter(org_policies::uuid.eq(&self.uuid)) .filter(org_policies::uuid.eq(&self.uuid))
.set(self) .set(&*self)
.execute(conn) .execute(conn)
.map_res("Error saving org_policy") .map_res("Error saving org_policy")
} }
@ -142,10 +148,10 @@ impl OrgPolicy {
.map_res("Error deleting org_policy for insert")?; .map_res("Error deleting org_policy for insert")?;
diesel::insert_into(org_policies::table) diesel::insert_into(org_policies::table)
.values(self) .values(&*self)
.on_conflict(org_policies::uuid) .on_conflict(org_policies::uuid)
.do_update() .do_update()
.set(self) .set(&*self)
.execute(conn) .execute(conn)
.map_res("Error saving org_policy") .map_res("Error saving org_policy")
} }

1
src/db/schema.rs

@ -116,6 +116,7 @@ table! {
atype -> Integer, atype -> Integer,
enabled -> Bool, enabled -> Bool,
data -> Text, data -> Text,
revision_date -> Timestamp,
} }
} }

Loading…
Cancel
Save