https://sonarly.com/issue/39738?type=bug
Cross-upgrade from 2.4.0 to 2.7.3 can abort in workspace cache recomputation before 2.6 migrations run. The crash blocks upgrade completion and leaves the workspace unusable in the upgraded runtime.
Fix: Implemented a surgical fix in the role-permission cache path to handle cross-upgrade transitional data safely.
### What changed
1. **Restored null-safe fallback in cache permission check**
- File: `packages/twenty-server/src/engine/metadata-modules/role/services/workspace-roles-permissions-cache.service.ts`
- In `hasSettingsGatedObjectPermissions(...)`, replaced unsafe direct dereference:
- `rolePermissionFlag.permissionFlag.universalIdentifier`
- With upgrade-safe fallback:
- `(rolePermissionFlag.permissionFlag?.universalIdentifier ?? SystemPermissionFlag[rolePermissionFlag.flag])`
- This prevents null/undefined dereference when upgrade-aware relation stripping removes `permissionFlag` before 2.6 while still correctly resolving permission grants from legacy `flag`.
2. **Added regression test for stripped relation scenario**
- File: `packages/twenty-server/src/engine/metadata-modules/role/services/__tests__/workspace-roles-permissions-cache.service.spec.ts`
- Added test:
- `"should grant all record permissions from legacy flag when permissionFlag relation is unavailable"`
- The test mocks a `RolePermissionFlagEntity` with only legacy `flag` and no `permissionFlag` relation, and asserts workspace-member permissions are granted as expected.
### Existing-fix check performed
- Ran:
- `git log --all --oneline --since='30 days ago' -- packages/twenty-server/src/engine/metadata-modules/role/services/workspace-roles-permissions-cache.service.ts`
- Reviewed recent commits touching this file (including `d13cc7c...`, `db0547f...`, `3c78436...`).
- No newer commit in that window already applying this exact null-safe fallback in the affected cache path.
Authored by Sonarly by autonomous analysis (run 45292).