Skip to content

feat(postgres): import key metadata for SELECT-only roles with catalog access - #1709

Open
vtulus wants to merge 9 commits into
datacontract:mainfrom
vtulus:feature/postgres-key-metadata
Open

vtulus wants to merge 9 commits into
datacontract:mainfrom
vtulus:feature/postgres-key-metadata

Conversation

@vtulus

@vtulus vtulus commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Extends #1423 with PostgreSQL catalog-backed key metadata for read-only imports.

PostgreSQL hides constraint metadata from roles that have only application-table SELECT, forcing users to supplement imports manually even when catalog reads
are available.

Postgres import
  tables and columns  <- information_schema (required)
  primary keys        <- pg_catalog, else information_schema
  foreign keys        <- pg_catalog, else omitted

  complete constraints only
    one-column FK     -> property relationship
    composite FK      -> schema relationship

Catalog access is optional: a role with full-table SELECT, schema USAGE, and catalog read access imports primary and foreign keys. If catalog access is denied, table/column import still succeeds; primary keys fall back to information_schema and foreign keys are omitted. Relationships are retained only when both complete endpoints are included in the selected schema.

Evidence

  • Before: Add Postgres import #1423 read primary keys through information_schema; a SELECT-only role could receive a usable contract without primary keys, and PostgreSQL foreign keys were not imported.

  • After: Reads declared primary and foreign keys from pg_catalog when available; primary keys fall back to information_schema and foreign keys are omitted when catalog access is denied.

    • uv run --extra dev pytest tests/test_import_postgres.py tests/test_test_relationships.py passes (36 tests), covering the PostgreSQL 16 SELECT-only role, composite-key atomicity, selected-table and cross-schema cases, plus relationship-test regression coverage.

Merge Danger

The change is limited to PostgreSQL import output.

Blast Radius: PostgreSQL

Imported contracts may gain declared primary keys and relationships when the role can read PostgreSQL catalogs; restricted catalog access continues to degrade gracefully.

  • Tests pass (uv run pytest)
  • Code formatted (uv run ruff check --fix && uv run ruff format)
  • Docs updated (if relevant)
  • CHANGELOG.md entry added

@jschoedl jschoedl left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you for the PR!

Comment thread datacontract/imports/postgres_importer.py
Comment thread datacontract/imports/postgres_importer.py Outdated
Comment thread datacontract/imports/postgres_importer.py Outdated
Comment thread tests/test_import_postgres.py Outdated
Comment thread docs/docs/imports/postgres.md
Comment thread datacontract/imports/postgres_importer.py Outdated
@vtulus
vtulus requested a review from jschoedl October 9, 2026 11:13

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants