Conformance suites
One list of checks, run by a small app per stack (integrations/<stack>/, each with its own test.sh), in CI on PostgreSQL 16 for each push, and on 17 and 18 every night (PG_MAJOR=17 or 18 runs a suite on another version). Every night they also run on 16 with the app connecting through PgBouncer in transaction mode (POOLER=pgbouncer, pooler.sh; the owner and the change feed stay direct). The tests are numbered after this list.
- Signed in, a list shows only the user's rows.
- Signed out on purpose, only what
anyonemay see. - Not signed in: the strict sign-in error, naming
act_as. - With a pool of one connection, a request as Ann, then one as Bob: Bob never sees Ann's rows.
- Concurrent requests never mix users.
- A refused insert: 403 with the problem body naming the rule.
- An update of a hidden row: 404. Of a visible row the user may not edit: 403, with the reason.
- Insert, then read back, works when the select rule allows it, and is explained when not.
- The generated names type-check, and a wrong permission name doesn't.
- A background job signs in as a service principal.
- A fresh database: migrate, and the policy tests pass. Then the tool's own diff shows no change.
- The framework's test database has the policy (Next.js: a database per Vitest worker; the Python SDK has no helper for it yet).
- The app refuses to start on a connection that skips row-level security.
- After a policy change and a new migration, the app works with the new generated names.
- Next.js only: a signed-in page is never served from a cache to another user, and a signed-in read inside
unstable_cacheor"use cache"fails instead of being cached.
A new stack gets its own folder here, with every check that applies to it.