Four things that share a spine, so they arrive together. **Folders.** A hand-picked set of questions, and the fourth thing a grant can name beside exam, discipline and category. Deliberately not `user_collections` with a sharing flag: a library is a consequence of access — you save what you can already see — while a folder is a source of it, and one table holding thousands of private lists beside a handful that confer permission is one mistake away from a leak. Built from the question manager, granted on /access. Membership stays with the owner and moderators so a grantee cannot widen their own reach, and deleting a folder takes its grants with it. Two live constraints had to be rewritten to accept it: `ck_grant_has_a_dimension` and `uq_grant_dimensions` both predate `folder_id`, so a folder-only grant failed the check and two folder grants collided on the unique index. **Per-question feedback.** The learner's half already existed. What was wrong was who could read it: any grant at all let an educator list and delete reports about the whole bank. Reports are now scoped by `question_scope_predicate`, the same predicate that decides which questions that educator can see, and a reply thread makes the report a conversation the learner can follow rather than a form that swallows what they said. **Per-section notes and article feedback.** Two tables on purpose: `article_section_notes` is private to whoever wrote it, `article_feedback` goes to whoever maintains the article. Both point at the section id inside `articles.sections` rather than at `article_section_index`, whose rows are dropped on unpublish — a cascade from there would delete a learner's writing because an educator took an article down for an afternoon. A rename keeps a note attached; a deleted section leaves it marked orphaned under the heading it was written on, for its writer alone to remove. The header's feedback badge covers both, because questions and reading are the same job to whoever is doing it. Migration i9f0a1b2c3d4. 556 backend and 572 frontend tests pass. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01TqXevQJhxFrM7jJg82cgZN
49 lines
2.4 KiB
Python
49 lines
2.4 KiB
Python
from datetime import datetime
|
|
|
|
from sqlalchemy import Column, DateTime, ForeignKey, Integer, String, Text, UniqueConstraint
|
|
|
|
from app.database import Base
|
|
|
|
|
|
class QuestionFolder(Base):
|
|
"""A hand-picked set of questions an educator assembles for someone else.
|
|
|
|
Deliberately not a `user_collections` row with a flag on it. The two look
|
|
alike — both are a named list of questions — but the access arrow runs the
|
|
other way. A library is a *consequence* of access: you can only save what
|
|
the bank predicate already lets you see, and the API says `private: True`
|
|
about every row. A folder is a *source* of access: a grant points at one,
|
|
and holding that grant is how an educator comes to reach the questions
|
|
inside. Putting both in one table would mean thousands of private rows
|
|
sitting beside a handful that confer permission, told apart by a flag —
|
|
and a mistake reading that flag is either a privacy leak or a privilege
|
|
escalation, in a table where the common case is somebody's private list.
|
|
|
|
Membership is the owner's and a moderator's to change, never a grantee's:
|
|
otherwise the holder of a folder grant could add any question to the folder
|
|
and so widen their own grant.
|
|
"""
|
|
|
|
__tablename__ = "question_folders"
|
|
|
|
id = Column(Integer, primary_key=True, index=True)
|
|
name = Column(String(200), nullable=False)
|
|
description = Column(Text, nullable=True)
|
|
# Who assembled it. SET NULL rather than CASCADE: a folder someone was
|
|
# granted must not disappear because the educator who built it left.
|
|
user_id = Column(Integer, ForeignKey("users.id", ondelete="SET NULL"), nullable=True, index=True)
|
|
created_at = Column(DateTime, default=datetime.utcnow)
|
|
updated_at = Column(DateTime, default=datetime.utcnow, onupdate=datetime.utcnow)
|
|
|
|
|
|
class QuestionFolderQuestion(Base):
|
|
__tablename__ = "question_folder_questions"
|
|
__table_args__ = (UniqueConstraint("folder_id", "question_id", name="uq_folder_question"),)
|
|
|
|
id = Column(Integer, primary_key=True, index=True)
|
|
folder_id = Column(Integer, ForeignKey("question_folders.id", ondelete="CASCADE"),
|
|
nullable=False, index=True)
|
|
question_id = Column(Integer, ForeignKey("questions.id", ondelete="CASCADE"),
|
|
nullable=False, index=True)
|
|
added_by = Column(Integer, ForeignKey("users.id", ondelete="SET NULL"), nullable=True)
|
|
added_at = Column(DateTime, default=datetime.utcnow)
|