feat(suppress): consume per-app suppressions at trigger + route dispatch (§11 tail S3)

The runtime half — suppressions now actually decline inherited templates.

- Triggers (live, per-event): a correlated NOT EXISTS anti-join
  (TRIGGER_SUPPRESSION_ANTIJOIN) appended to all four dispatch match
  queries (list_matching_kv/docs/files + the pubsub fan-out). It excludes a
  group-owned trigger whose handler script name the firing app suppresses;
  `$1` is the firing app (already bound), and the `t.group_id IS NOT NULL`
  guard keeps an app's OWN trigger unsuppressable.
- Routes (rebuild-time): compile_effective_routes takes a
  `suppressed_paths: &HashSet<(AppId, path)>` and drops an inherited
  (`depth > 0`) route at a suppressed path — the binding 404s.
  rebuild_route_table loads the set via a new
  RouteRepository::list_route_suppressions, so every existing rebuild edge
  (route CRUD, apply, tree mutations) already applies it. No new
  invalidation edges; the marker CASCADEs on app delete.

Pinned by tests/template_suppression.rs (live DB): a suppressing app
matches NEITHER the inherited trigger NOR route; a sibling that did not
suppress still inherits both; the app's OWN trigger on the suppressed
handler still fires (suppression is inheritance-only).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
MechaCat02
2026-07-01 07:39:06 +02:00
parent 32cb6c1f1f
commit 4b5bf72a66
6 changed files with 339 additions and 14 deletions

View File

@@ -83,14 +83,17 @@ impl PubsubRepo for PostgresPubsubRepo {
// §11 tail: the chain union picks up the app's own pubsub triggers AND
// ancestor-group pubsub TEMPLATES (live, no materialization). The outbox
// row below stamps the firing `ctx.app_id`, so a template runs under the
// publishing app — the inheriting-app boundary.
// publishing app — the inheriting-app boundary. The suppression
// anti-join drops an inherited template whose handler the app opts out
// of (`$1` = ctx.app_id).
let rows: Vec<PubsubTriggerRow> = sqlx::query_as(&format!(
"{CHAIN_LEVELS_CTE} \
SELECT t.id, t.script_id, d.topic_pattern \
FROM triggers t \
JOIN pubsub_trigger_details d ON d.trigger_id = t.id \
JOIN chain c ON (t.app_id = c.app_owner OR t.group_id = c.group_owner) \
WHERE t.kind = 'pubsub' AND t.enabled = TRUE"
WHERE t.kind = 'pubsub' AND t.enabled = TRUE{ANTIJOIN}",
ANTIJOIN = crate::trigger_repo::TRIGGER_SUPPRESSION_ANTIJOIN,
))
.bind(ctx.app_id.into_inner())
.fetch_all(&mut *tx)