Skip to content

Bump acts_as_tenant from 1.0.1 to 2.0.1 - #12

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/bundler/acts_as_tenant-2.0.1
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/bundler/acts_as_tenant-2.0.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 30, 2026

Copy link
Copy Markdown

Bumps acts_as_tenant from 1.0.1 to 2.0.1.

Release notes

Sourced from acts_as_tenant's releases.

v2.0.1

  • Fix with_tenant, without_tenant and with_mutable_tenant passing ActsAsTenant::Current to the block on Rails 7.2+, which raised ArgumentError for lambdas passed with &. The block is called with no arguments again, as in 1.x. #381
  • Fix belongs_to validation evaluating an association scope that takes the owner (->(record) { ... }) with the associated class instead of the record, which raised NoMethodError or silently rejected valid records. The scope now receives the record, as it does in Rails. #380

v2.0.0

Security

  • Fix models with polymorphic tenants allowing records to be created for another tenant while a tenant is set, for example by passing the polymorphic type and id in form params. Records assigned to a tenant other than the current one now fail validation. #378

Upgrading

These changes can make previously passing code or tests fail:

  • When no tenant is set, a belongs_to association to a record from a different tenant than the record itself now fails validation. This affects admin tools, scripts and test factories that build records for mismatched tenants. #367
  • belongs_to associations declared after acts_as_tenant are now validated against the current tenant, so assigning another tenant's record to them fails validation. #363
  • ActiveJob resolves the tenant when the job is performed instead of when it's deserialized, and restores the previous tenant afterwards. #358
  • with_tenant and without_tenant restore current_tenant to exactly what it was, without copying test_tenant or default_tenant into it. #337
  • Polymorphic tenant types are written with polymorphic_name. For STI tenants this is the base class instead of the subclass. Existing rows are still found, but can be updated with Comment.where(commentable_type: "FeaturedArticle").update_all(commentable_type: "Article"). Matching the old class name will be removed in 3.0. #369
  • mutable_tenant! is stored per request or job in ActsAsTenant::Current instead of globally, so calling ActsAsTenant.mutable_tenant!(true) once (e.g. in an initializer) no longer makes tenants mutable everywhere. Use ActsAsTenant.with_mutable_tenant { ... } instead. #368
  • When a tenant is set, creating a record for a different tenant now fails validation. Previously the tenant was silently replaced with the current tenant, or kept for polymorphic tenants, which let records be written to another tenant. Create records for another tenant inside ActsAsTenant.with_tenant(other_tenant) { ... }. #329
  • config.require_tenant callables are only called when no tenant is set and the query isn't inside without_tenant, instead of on every query. #370

Changes

  • Validate that records belong to the current tenant when a tenant is set, and only assign the current tenant to new records that don't have one. This also prevents polymorphic tenants from creating records for another tenant. #329

  • Document avoiding NoTenantSet when ActiveStorage generates previews and variants. #330

  • Document that tests lose the current tenant after jobs are performed inline. #335

  • Document using CurrentAttributes to access the request in a require_tenant lambda. #299

  • Document which queries aren't scoped to the current tenant. #354

  • Document setting the tenant in sidekiq_retries_exhausted, and remove the Sidekiq middleware check for RetryJobs, which was removed in Sidekiq 5. #356

  • Fix validates_uniqueness_to_tenant using the tenant of whichever model last called acts_as_tenant, which raised NoMethodError or scoped by the wrong column when models use different tenant names, e.g. when it's called in a subclass. #372

  • Fix validates_uniqueness_to_tenant raising TypeError when given multiple fields, like validates_uniqueness_to_tenant :email, :username. #292

  • Fix belongs_to validation looking up the associated record by the owner's primary key instead of the associated model's, which failed when either used a primary key other than id. #370

  • with_tenant, without_tenant and with_mutable_tenant no longer clear the current tenant when called without a block. They still raise ArgumentError. #370

  • Validate that belongs_to associations belong to the record's tenant when no current tenant is set. #367

  • Store polymorphic tenant types with polymorphic_name, matching Rails, so STI tenants can find their records through has_many associations. Records saved with the tenant's class name are still scoped to the tenant. #369

  • with_mutable_tenant is now thread-safe and restores the previous mutability when nested. #368

  • Fix polymorphic tenant id being set to the tenant's class name (saved as 0) for records built before the current tenant was set. #365

  • Document setting the current tenant in ActionCable with around_command. #366

  • with_tenant and without_tenant no longer copy test_tenant or default_tenant into current_tenant when restoring it. #337

  • Validate belongs_to associations declared after acts_as_tenant. Previously these were not checked for cross-tenant records. #363

  • config.require_tenant callables can accept the relation being queried as an argument. #362

    ActsAsTenant.configure do |config|
      config.require_tenant = lambda do |relation|
        relation.klass.name != "User"
      end
    end

... (truncated)

Changelog

Sourced from acts_as_tenant's changelog.

2.0.1

  • Fix with_tenant, without_tenant and with_mutable_tenant passing ActsAsTenant::Current to the block on Rails 7.2+, which raised ArgumentError for lambdas passed with &. The block is called with no arguments again, as in 1.x. #381
  • Fix belongs_to validation evaluating an association scope that takes the owner (->(record) { ... }) with the associated class instead of the record, which raised NoMethodError or silently rejected valid records. The scope now receives the record, as it does in Rails. #380

2.0.0

Security

  • Fix models with polymorphic tenants allowing records to be created for another tenant while a tenant is set, for example by passing the polymorphic type and id in form params. Records assigned to a tenant other than the current one now fail validation. #378

Upgrading

These changes can make previously passing code or tests fail:

  • When no tenant is set, a belongs_to association to a record from a different tenant than the record itself now fails validation. This affects admin tools, scripts and test factories that build records for mismatched tenants. #367
  • belongs_to associations declared after acts_as_tenant are now validated against the current tenant, so assigning another tenant's record to them fails validation. #363
  • ActiveJob resolves the tenant when the job is performed instead of when it's deserialized, and restores the previous tenant afterwards. #358
  • with_tenant and without_tenant restore current_tenant to exactly what it was, without copying test_tenant or default_tenant into it. #337
  • Polymorphic tenant types are written with polymorphic_name. For STI tenants this is the base class instead of the subclass. Existing rows are still found, but can be updated with Comment.where(commentable_type: "FeaturedArticle").update_all(commentable_type: "Article"). Matching the old class name will be removed in 3.0. #369
  • mutable_tenant! is stored per request or job in ActsAsTenant::Current instead of globally, so calling ActsAsTenant.mutable_tenant!(true) once (e.g. in an initializer) no longer makes tenants mutable everywhere. Use ActsAsTenant.with_mutable_tenant { ... } instead. #368
  • When a tenant is set, creating a record for a different tenant now fails validation. Previously the tenant was silently replaced with the current tenant, or kept for polymorphic tenants, which let records be written to another tenant. Create records for another tenant inside ActsAsTenant.with_tenant(other_tenant) { ... }. #329
  • config.require_tenant callables are only called when no tenant is set and the query isn't inside without_tenant, instead of on every query. #370

Changes

  • Validate that records belong to the current tenant when a tenant is set, and only assign the current tenant to new records that don't have one. This also prevents polymorphic tenants from creating records for another tenant. #329

  • Document avoiding NoTenantSet when ActiveStorage generates previews and variants. #330

  • Document that tests lose the current tenant after jobs are performed inline. #335

  • Document using CurrentAttributes to access the request in a require_tenant lambda. #299

  • Document which queries aren't scoped to the current tenant. #354

  • Document setting the tenant in sidekiq_retries_exhausted, and remove the Sidekiq middleware check for RetryJobs, which was removed in Sidekiq 5. #356

  • Fix validates_uniqueness_to_tenant using the tenant of whichever model last called acts_as_tenant, which raised NoMethodError or scoped by the wrong column when models use different tenant names, e.g. when it's called in a subclass. #372

  • Fix validates_uniqueness_to_tenant raising TypeError when given multiple fields, like validates_uniqueness_to_tenant :email, :username. #292

  • Fix belongs_to validation looking up the associated record by the owner's primary key instead of the associated model's, which failed when either used a primary key other than id. #370

  • with_tenant, without_tenant and with_mutable_tenant no longer clear the current tenant when called without a block. They still raise ArgumentError. #370

  • Validate that belongs_to associations belong to the record's tenant when no current tenant is set. #367

  • Store polymorphic tenant types with polymorphic_name, matching Rails, so STI tenants can find their records through has_many associations. Records saved with the tenant's class name are still scoped to the tenant. #369

  • with_mutable_tenant is now thread-safe and restores the previous mutability when nested. #368

  • Fix polymorphic tenant id being set to the tenant's class name (saved as 0) for records built before the current tenant was set. #365

  • Document setting the current tenant in ActionCable with around_command. #366

  • with_tenant and without_tenant no longer copy test_tenant or default_tenant into current_tenant when restoring it. #337

  • Validate belongs_to associations declared after acts_as_tenant. Previously these were not checked for cross-tenant records. #363

  • config.require_tenant callables can accept the relation being queried as an argument. #362

    ActsAsTenant.configure do |config|
      config.require_tenant = lambda do |relation|

... (truncated)

Commits
  • 0cffbc2 Version bump (#383)
  • 714e912 Don't pass Current to with_tenant and without_tenant blocks (#382)
  • ed0ee27 Pass the record to belongs_to scopes when validating associations (#380)
  • bd1bf44 Version bump (#379)
  • 92163e5 Validate that records belong to the current tenant (#378)
  • 63bd103 Document avoiding NoTenantSet in ActiveStorage previews (#377)
  • cfdc5d7 Document tests losing the tenant after jobs are performed inline (#376)
  • d6bfd78 Document accessing the request in a require_tenant lambda (#375)
  • 2c2f4a3 Document which queries aren't scoped to the current tenant (#374)
  • 0605c7b Document setting the tenant in sidekiq_retries_exhausted (#373)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [acts_as_tenant](https://github.com/ErwinM/acts_as_tenant) from 1.0.1 to 2.0.1.
- [Release notes](https://github.com/ErwinM/acts_as_tenant/releases)
- [Changelog](https://github.com/ErwinM/acts_as_tenant/blob/master/CHANGELOG.md)
- [Commits](ErwinM/acts_as_tenant@v1.0.1...v2.0.1)

---
updated-dependencies:
- dependency-name: acts_as_tenant
  dependency-version: 2.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code labels Sep 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants