The provisioning pass enumerated users through the default (soft-delete-aware) query, so trashed users got no personal space and their accounts, transactions, categories, etc. kept a null space_id — an incomplete backfill that would block a NOT NULL constraint and hide a restored account's data under space-scoped reads. Include trashed users in the pass (the row-stamping already covers their rows). Verified on a prod-scale copy: 0 rows left unstamped afterwards. |
||
|---|---|---|
| .. | ||
| Commands | ||