A default change or a reorder lists each organization it could not move with raw database error text #215

Open
opened 2026-10-10 23:59:46 +00:00 by cgalo5758 · 0 comments
Owner

What happens

Changing an organization type's default ladder moves each organization of the type, one at a time. A tier reorder that changes a default ladder's rank-0 tier does the same. When an organization cannot be moved, the act skips it and lists it with a reason. In five of those reasons the code appends the raw error to the words, so the operator sees Go call chains, the database's error text and SQLSTATE codes. On the org type card:

"Default change committed: 1 failed. Failed organizations were skipped; fix the cause and commit again. Planless: could not initiate the default: reapply-defaults: confer default grant: confer grant: ERROR: confer: product has no entitlement set and confers nothing (SQLSTATE P0001)"

The reorder puts the same text in an error toast and in the alert on the ladder page: " is now the default plan for new organizations: 1 grandfathered, 1 failed. Failed organizations were skipped; fix the cause, re-drop the same order, and commit again: Planless: could not initiate the default: reapply-defaults: …".

The five reasons are "could not initiate the default: ", "could not grandfather: ", "could not end the outgoing default position: ", "could not apply the new default: " and "could not materialize entitlements: ", each followed by err.Error().

The raw-error-render lint is meant to catch this and cannot. It flags a line that contains both err.Error() and a render call. Here the text is stored in OrgTypeChangeFailure.Reason and rendered later, from a different line.

Not every failure here is logged. The materialize failure, and the failures to begin, lock, read and commit, write no log line, so for the materialize step the page is the only place its error appears.

What should happen

As the db-error-presentation spec requires ("Raw database driver text never reaches the UI"), each reason states in words what could not be done, with no error text. The full error is logged on every failure path, including the ones that log nothing today, and the failure list points to the server logs as the other refusals do. A cause the console can state in its own words may be named, such as a product with no entitlement set (#153).

Where

internal/server/operator_org_types.go: enactOrgDisposition, which builds the reasons; CommitOrgTypeDefaultChange and the org type card render them. internal/server/operator_plan_ladders.go: ReorderPlanLadderTiers joins them into its toast. internal/lint/lint.go: ruleRawErrorRender. The recorded answers in internal/server/testdata/plan_acts/default-initiate-fails.json, default-migrate-restore-fails.json and reorder-an-organization-fails.json contain the raw text and will change with the fix.

Steps

  1. Make a ladder whose only tier is a product with no entitlement set (#153 shows that the default control accepts it).
  2. Make it the default of an organization type that has an organization with no plan.
  3. The org type card lists that organization with the error quoted above.

Why it matters

An operator is told to "fix the cause" and is shown a stack of function names and a database code, while the log has no record of the materialize failure at all.

### What happens Changing an organization type's default ladder moves each organization of the type, one at a time. A tier reorder that changes a default ladder's rank-0 tier does the same. When an organization cannot be moved, the act skips it and lists it with a reason. In five of those reasons the code appends the raw error to the words, so the operator sees Go call chains, the database's error text and SQLSTATE codes. On the org type card: "Default change committed: 1 failed. Failed organizations were skipped; fix the cause and commit again. Planless: could not initiate the default: reapply-defaults: confer default grant: confer grant: ERROR: confer: product <product id> has no entitlement set and confers nothing (SQLSTATE P0001)" The reorder puts the same text in an error toast and in the alert on the ladder page: "<product> is now the default plan for new <type> organizations: 1 grandfathered, 1 failed. Failed organizations were skipped; fix the cause, re-drop the same order, and commit again: Planless: could not initiate the default: reapply-defaults: …". The five reasons are "could not initiate the default: ", "could not grandfather: ", "could not end the outgoing default position: ", "could not apply the new default: " and "could not materialize entitlements: ", each followed by `err.Error()`. The `raw-error-render` lint is meant to catch this and cannot. It flags a line that contains both `err.Error()` and a render call. Here the text is stored in `OrgTypeChangeFailure.Reason` and rendered later, from a different line. Not every failure here is logged. The materialize failure, and the failures to begin, lock, read and commit, write no log line, so for the materialize step the page is the only place its error appears. ### What should happen As the db-error-presentation spec requires ("Raw database driver text never reaches the UI"), each reason states in words what could not be done, with no error text. The full error is logged on every failure path, including the ones that log nothing today, and the failure list points to the server logs as the other refusals do. A cause the console can state in its own words may be named, such as a product with no entitlement set (#153). ### Where `internal/server/operator_org_types.go`: `enactOrgDisposition`, which builds the reasons; `CommitOrgTypeDefaultChange` and the org type card render them. `internal/server/operator_plan_ladders.go`: `ReorderPlanLadderTiers` joins them into its toast. `internal/lint/lint.go`: `ruleRawErrorRender`. The recorded answers in `internal/server/testdata/plan_acts/default-initiate-fails.json`, `default-migrate-restore-fails.json` and `reorder-an-organization-fails.json` contain the raw text and will change with the fix. ### Steps 1. Make a ladder whose only tier is a product with no entitlement set (#153 shows that the default control accepts it). 2. Make it the default of an organization type that has an organization with no plan. 3. The org type card lists that organization with the error quoted above. ### Why it matters An operator is told to "fix the cause" and is shown a stack of function names and a database code, while the log has no record of the materialize failure at all.
cgalo5758 added the
kind
bug
area/catalogarea/operator-ui
labels 2026-10-10 23:59:46 +00:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: wiki-cafe/member-console#215