A default change or a reorder lists each organization it could not move with raw database error text #215
Open
opened 2026-10-10 23:59:46 +00:00 by cgalo5758
·
0 comments
Labels
Clear labels
accessibility
area/billing
area/catalog
area/discourse
area/domains
area/entitlements
area/fedwiki
area/identity
area/integrations
area/licensing
area/member-ui
area/meta
area/operator-ui
area/ops
area/testing
duplicate
good-first-issue
invalid
privacy
security
upstream
wontfix
A barrier for people using assistive technology or a keyboard alone.
The Stripe mirror, checkout, subscriptions, invoices, fulfillment.
Products, prices, plan ladders, purchasability.
The Discourse integration.
The domains registry, claims, placements, the certificate ask.
Entitlement sets, rules, grants, pools, provisioning.
The Federated Wiki integration and farm sync.
Sign-in, sessions, persons, organizations, workspaces, roles.
The provider registry, outbox and webhooks in general.
Licenses, the contributor agreement, SPDX headers.
Member pages.
The repository itself, its contributing guide, CI, the tracker and the workflow.
Operator pages, forms, lists, the design system.
Deployment, configuration, migrations, workflows, instance settings.
The test stack, screens, lint, walkthroughs.
Closed because another issue already covers it.
Small, self-contained, and explained enough to be a first contribution.
Closed because it is not a ticket for this repository.
Touches what a person's data reveals.
Touches authentication, authorization, secrets or data exposure.
Waits on another repository or project before it can move.
Closed because it will not be done, with the reason in the last comment.
kind
bug
The software does something other than what it promises; closed when it again does what it promises.
kind
debt
Code, tests or tooling to clean up with nothing visible changing; closed when they are cleaner.
kind
design
A question to settle before work can be defined; closed when the decision is written down.
kind
docs
Documentation that is wrong or missing; closed when it says the right thing.
kind
enhancement
Something the software does not do yet; closed when it does.
priority
critical
Blocks the active milestone or harms members now.
priority
high
Next in line inside the active milestone.
priority
low
Inside the active milestone, when nothing else is left.
priority
medium
Inside the active milestone, after the high ones.
Milestone
No items
No Milestone
Projects
Clear projects
No projects
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: wiki-cafe/member-console#215
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
What happens
Changing an organization type's default ladder moves each organization of the type, one at a time. A tier reorder that changes a default ladder's rank-0 tier does the same. When an organization cannot be moved, the act skips it and lists it with a reason. In five of those reasons the code appends the raw error to the words, so the operator sees Go call chains, the database's error text and SQLSTATE codes. On the org type card:
"Default change committed: 1 failed. Failed organizations were skipped; fix the cause and commit again. Planless: could not initiate the default: reapply-defaults: confer default grant: confer grant: ERROR: confer: product has no entitlement set and confers nothing (SQLSTATE P0001)"
The reorder puts the same text in an error toast and in the alert on the ladder page: " is now the default plan for new organizations: 1 grandfathered, 1 failed. Failed organizations were skipped; fix the cause, re-drop the same order, and commit again: Planless: could not initiate the default: reapply-defaults: …".
The five reasons are "could not initiate the default: ", "could not grandfather: ", "could not end the outgoing default position: ", "could not apply the new default: " and "could not materialize entitlements: ", each followed by
err.Error().The
raw-error-renderlint is meant to catch this and cannot. It flags a line that contains botherr.Error()and a render call. Here the text is stored inOrgTypeChangeFailure.Reasonand rendered later, from a different line.Not every failure here is logged. The materialize failure, and the failures to begin, lock, read and commit, write no log line, so for the materialize step the page is the only place its error appears.
What should happen
As the db-error-presentation spec requires ("Raw database driver text never reaches the UI"), each reason states in words what could not be done, with no error text. The full error is logged on every failure path, including the ones that log nothing today, and the failure list points to the server logs as the other refusals do. A cause the console can state in its own words may be named, such as a product with no entitlement set (#153).
Where
internal/server/operator_org_types.go:enactOrgDisposition, which builds the reasons;CommitOrgTypeDefaultChangeand the org type card render them.internal/server/operator_plan_ladders.go:ReorderPlanLadderTiersjoins them into its toast.internal/lint/lint.go:ruleRawErrorRender. The recorded answers ininternal/server/testdata/plan_acts/default-initiate-fails.json,default-migrate-restore-fails.jsonandreorder-an-organization-fails.jsoncontain the raw text and will change with the fix.Steps
Why it matters
An operator is told to "fix the cause" and is shown a stack of function names and a database code, while the log has no record of the materialize failure at all.