Files
XQKqueue/server/migrations/000008_super_admin_password_rotation.up.sql
2026-07-12 15:53:24 +08:00

18 lines
667 B
PL/PgSQL

CREATE OR REPLACE FUNCTION protect_super_admin() RETURNS trigger AS $$
BEGIN
IF OLD.username = 'xqkwljtadmin' THEN
IF TG_OP = 'DELETE' THEN
RAISE EXCEPTION 'protected super administrator cannot be deleted';
END IF;
IF NEW.username <> OLD.username
OR NEW.role <> OLD.role
OR NEW.active <> OLD.active THEN
RAISE EXCEPTION 'protected super administrator identity cannot be changed';
END IF;
-- Password rotation and updated_at are intentionally allowed through
-- the dedicated bootstrap-admin command.
END IF;
RETURN COALESCE(NEW, OLD);
END;
$$ LANGUAGE plpgsql;