Skip to content

Bump acts_as_tenant from 1.0.1 to 2.0.0 - #8

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/bundler/acts_as_tenant-2.0.0
Closed

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/bundler/acts_as_tenant-2.0.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 24, 2026 •

Copy link
Copy Markdown

Bumps acts_as_tenant from 1.0.1 to 2.0.0.

Release notes

Sourced from acts_as_tenant's releases.

v2.0.0

Security

  • Fix models with polymorphic tenants allowing records to be created for another tenant while a tenant is set, for example by passing the polymorphic type and id in form params. Records assigned to a tenant other than the current one now fail validation. #378

Upgrading

These changes can make previously passing code or tests fail:

  • When no tenant is set, a belongs_to association to a record from a different tenant than the record itself now fails validation. This affects admin tools, scripts and test factories that build records for mismatched tenants. #367
  • belongs_to associations declared after acts_as_tenant are now validated against the current tenant, so assigning another tenant's record to them fails validation. #363
  • ActiveJob resolves the tenant when the job is performed instead of when it's deserialized, and restores the previous tenant afterwards. #358
  • with_tenant and without_tenant restore current_tenant to exactly what it was, without copying test_tenant or default_tenant into it. #337
  • Polymorphic tenant types are written with polymorphic_name. For STI tenants this is the base class instead of the subclass. Existing rows are still found, but can be updated with Comment.where(commentable_type: "FeaturedArticle").update_all(commentable_type: "Article"). Matching the old class name will be removed in 3.0. #369
  • mutable_tenant! is stored per request or job in ActsAsTenant::Current instead of globally, so calling ActsAsTenant.mutable_tenant!(true) once (e.g. in an initializer) no longer makes tenants mutable everywhere. Use ActsAsTenant.with_mutable_tenant { ... } instead. #368
  • When a tenant is set, creating a record for a different tenant now fails validation. Previously the tenant was silently replaced with the current tenant, or kept for polymorphic tenants, which let records be written to another tenant. Create records for another tenant inside ActsAsTenant.with_tenant(other_tenant) { ... }. #329
  • config.require_tenant callables are only called when no tenant is set and the query isn't inside without_tenant, instead of on every query. #370

Changes

  • Validate that records belong to the current tenant when a tenant is set, and only assign the current tenant to new records that don't have one. This also prevents polymorphic tenants from creating records for another tenant. #329

  • Document avoiding NoTenantSet when ActiveStorage generates previews and variants. #330

  • Document that tests lose the current tenant after jobs are performed inline. #335

  • Document using CurrentAttributes to access the request in a require_tenant lambda. #299

  • Document which queries aren't scoped to the current tenant. #354

  • Document setting the tenant in sidekiq_retries_exhausted, and remove the Sidekiq middleware check for RetryJobs, which was removed in Sidekiq 5. #356

  • Fix validates_uniqueness_to_tenant using the tenant of whichever model last called acts_as_tenant, which raised NoMethodError or scoped by the wrong column when models use different tenant names, e.g. when it's called in a subclass. #372

  • Fix validates_uniqueness_to_tenant raising TypeError when given multiple fields, like validates_uniqueness_to_tenant :email, :username. #292

  • Fix belongs_to validation looking up the associated record by the owner's primary key instead of the associated model's, which failed when either used a primary key other than id. #370

  • with_tenant, without_tenant and with_mutable_tenant no longer clear the current tenant when called without a block. They still raise ArgumentError. #370

  • Validate that belongs_to associations belong to the record's tenant when no current tenant is set. #367

  • Store polymorphic tenant types with polymorphic_name, matching Rails, so STI tenants can find their records through has_many associations. Records saved with the tenant's class name are still scoped to the tenant. #369

  • with_mutable_tenant is now thread-safe and restores the previous mutability when nested. #368

  • Fix polymorphic tenant id being set to the tenant's class name (saved as 0) for records built before the current tenant was set. #365

  • Document setting the current tenant in ActionCable with around_command. #366

  • with_tenant and without_tenant no longer copy test_tenant or default_tenant into current_tenant when restoring it. #337

  • Validate belongs_to associations declared after acts_as_tenant. Previously these were not checked for cross-tenant records. #363

  • config.require_tenant callables can accept the relation being queried as an argument. #362

    ActsAsTenant.configure do |config|
      config.require_tenant = lambda do |relation|
        relation.klass.name != "User"
      end
    end
  • Add support for Rails 7.2, 8.0, 8.1 and Sidekiq 8. #361

  • Resolve the tenant when performing a job instead of when deserializing it. #358

... (truncated)

Changelog

Sourced from acts_as_tenant's changelog.

2.0.0

Security

  • Fix models with polymorphic tenants allowing records to be created for another tenant while a tenant is set, for example by passing the polymorphic type and id in form params. Records assigned to a tenant other than the current one now fail validation. #378

Upgrading

These changes can make previously passing code or tests fail:

  • When no tenant is set, a belongs_to association to a record from a different tenant than the record itself now fails validation. This affects admin tools, scripts and test factories that build records for mismatched tenants. #367
  • belongs_to associations declared after acts_as_tenant are now validated against the current tenant, so assigning another tenant's record to them fails validation. #363
  • ActiveJob resolves the tenant when the job is performed instead of when it's deserialized, and restores the previous tenant afterwards. #358
  • with_tenant and without_tenant restore current_tenant to exactly what it was, without copying test_tenant or default_tenant into it. #337
  • Polymorphic tenant types are written with polymorphic_name. For STI tenants this is the base class instead of the subclass. Existing rows are still found, but can be updated with Comment.where(commentable_type: "FeaturedArticle").update_all(commentable_type: "Article"). Matching the old class name will be removed in 3.0. #369
  • mutable_tenant! is stored per request or job in ActsAsTenant::Current instead of globally, so calling ActsAsTenant.mutable_tenant!(true) once (e.g. in an initializer) no longer makes tenants mutable everywhere. Use ActsAsTenant.with_mutable_tenant { ... } instead. #368
  • When a tenant is set, creating a record for a different tenant now fails validation. Previously the tenant was silently replaced with the current tenant, or kept for polymorphic tenants, which let records be written to another tenant. Create records for another tenant inside ActsAsTenant.with_tenant(other_tenant) { ... }. #329
  • config.require_tenant callables are only called when no tenant is set and the query isn't inside without_tenant, instead of on every query. #370

Changes

  • Validate that records belong to the current tenant when a tenant is set, and only assign the current tenant to new records that don't have one. This also prevents polymorphic tenants from creating records for another tenant. #329

  • Document avoiding NoTenantSet when ActiveStorage generates previews and variants. #330

  • Document that tests lose the current tenant after jobs are performed inline. #335

  • Document using CurrentAttributes to access the request in a require_tenant lambda. #299

  • Document which queries aren't scoped to the current tenant. #354

  • Document setting the tenant in sidekiq_retries_exhausted, and remove the Sidekiq middleware check for RetryJobs, which was removed in Sidekiq 5. #356

  • Fix validates_uniqueness_to_tenant using the tenant of whichever model last called acts_as_tenant, which raised NoMethodError or scoped by the wrong column when models use different tenant names, e.g. when it's called in a subclass. #372

  • Fix validates_uniqueness_to_tenant raising TypeError when given multiple fields, like validates_uniqueness_to_tenant :email, :username. #292

  • Fix belongs_to validation looking up the associated record by the owner's primary key instead of the associated model's, which failed when either used a primary key other than id. #370

  • with_tenant, without_tenant and with_mutable_tenant no longer clear the current tenant when called without a block. They still raise ArgumentError. #370

  • Validate that belongs_to associations belong to the record's tenant when no current tenant is set. #367

  • Store polymorphic tenant types with polymorphic_name, matching Rails, so STI tenants can find their records through has_many associations. Records saved with the tenant's class name are still scoped to the tenant. #369

  • with_mutable_tenant is now thread-safe and restores the previous mutability when nested. #368

  • Fix polymorphic tenant id being set to the tenant's class name (saved as 0) for records built before the current tenant was set. #365

  • Document setting the current tenant in ActionCable with around_command. #366

  • with_tenant and without_tenant no longer copy test_tenant or default_tenant into current_tenant when restoring it. #337

  • Validate belongs_to associations declared after acts_as_tenant. Previously these were not checked for cross-tenant records. #363

  • config.require_tenant callables can accept the relation being queried as an argument. #362

    ActsAsTenant.configure do |config|
      config.require_tenant = lambda do |relation|
        relation.klass.name != "User"
      end
    end
  • Add support for Rails 7.2, 8.0, 8.1 and Sidekiq 8. #361

... (truncated)

Commits
  • bd1bf44 Version bump (#379)
  • 92163e5 Validate that records belong to the current tenant (#378)
  • 63bd103 Document avoiding NoTenantSet in ActiveStorage previews (#377)
  • cfdc5d7 Document tests losing the tenant after jobs are performed inline (#376)
  • d6bfd78 Document accessing the request in a require_tenant lambda (#375)
  • 2c2f4a3 Document which queries aren't scoped to the current tenant (#374)
  • 0605c7b Document setting the tenant in sidekiq_retries_exhausted (#373)
  • c142d88 Use the model's own tenant in validates_uniqueness_to_tenant (#372)
  • d38fc64 Support multiple fields in validates_uniqueness_to_tenant (#371)
  • 0c3c983 Reset tenant_change_hook when Current resets, and simplify (#370)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code labels Sep 24, 2026
Bumps [acts_as_tenant](https://github.com/ErwinM/acts_as_tenant) from 1.0.1 to 2.0.0.
- [Release notes](https://github.com/ErwinM/acts_as_tenant/releases)
- [Changelog](https://github.com/ErwinM/acts_as_tenant/blob/master/CHANGELOG.md)
- [Commits](ErwinM/acts_as_tenant@v1.0.1...v2.0.0)

---
updated-dependencies:
- dependency-name: acts_as_tenant
  dependency-version: 2.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/bundler/acts_as_tenant-2.0.0 branch from 8209050 to d489c64 Compare September 28, 2026 16:24
@dependabot @github

dependabot Bot commented on behalf of github Sep 30, 2026

Copy link
Copy Markdown
Author

Superseded by #12.

@dependabot dependabot Bot closed this Sep 30, 2026
@dependabot
dependabot Bot deleted the dependabot/bundler/acts_as_tenant-2.0.0 branch September 30, 2026 11:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file ruby Pull requests that update ruby code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants