mirror of
https://github.com/navidrome/navidrome.git
synced 2026-10-08 02:17:25 +02:00
- GrantRepository keeps three deletes: DeleteForUser, DeleteStaleEpochs
(replaces DeleteOtherEpochs and DeleteIfEpoch) and DeleteIdle. Delete(id)
is gone; the idle path in ResolveGrant now calls DeleteIdle, so a grant
renewed by another node between the read and the delete survives.
settleEpoch deletes the user's grants below the snapshot's epoch, which
is safe outside the transaction because epochs only move forward.
- The "dead grants on an older epoch are only deleted when presented"
policy note moves from the repository to core ListGrants.
- SQL trace logging no longer prints the args of property writes (signing
keys) or user password writes, both encrypted with a key that may be the
public default. The SQL statement is still logged.
- The spec gate rejects JSON body keys that differ from a declared property
only in case. kin-openapi validates exact names while encoding/json
decodes case-insensitively, so {"scopes":[],"Scopes":null} minted a
token with every scope and a "Client" key skipped maxLength.
It also rejects data after the first JSON value, which the handlers'
decoder ignores and which let a body skip the alias check.
- The liveness cache trims its eviction log on evict, not only on put, so
evict-only traffic stays bounded; the floor still drops stale fills.
- createAccessToken, login and setupFirstAdmin declare Cache-Control:
no-store on their success responses.
67 lines
2.1 KiB
Go
67 lines
2.1 KiB
Go
package model
|
|
|
|
import (
|
|
"context"
|
|
"database/sql/driver"
|
|
"fmt"
|
|
"strings"
|
|
"time"
|
|
)
|
|
|
|
type Grant struct {
|
|
ID string `structs:"id" json:"id"`
|
|
UserID string `structs:"user_id" json:"userId"`
|
|
Name string `structs:"name" json:"name"`
|
|
Client string `structs:"client" json:"client"`
|
|
ClientVersion string `structs:"client_version" json:"clientVersion"`
|
|
Scopes Scopes `structs:"scopes" json:"scopes"`
|
|
Provider string `structs:"provider" json:"provider"`
|
|
SecretHash string `structs:"secret_hash" json:"-"`
|
|
UserEpoch int `structs:"user_epoch" json:"-"`
|
|
CreatedAt time.Time `structs:"created_at" json:"createdAt"`
|
|
LastUsedAt *time.Time `structs:"last_used_at" json:"lastUsedAt"`
|
|
LastUsedIP string `structs:"last_used_ip" json:"lastUsedIp"`
|
|
}
|
|
|
|
func (g Grant) LastActivity() time.Time {
|
|
if g.LastUsedAt != nil {
|
|
return *g.LastUsedAt
|
|
}
|
|
return g.CreatedAt
|
|
}
|
|
|
|
type Grants []Grant
|
|
|
|
// Scopes is stored as a single space-separated column.
|
|
type Scopes []string
|
|
|
|
func (s Scopes) Value() (driver.Value, error) {
|
|
return strings.Join(s, " "), nil
|
|
}
|
|
|
|
func (s *Scopes) Scan(src any) error {
|
|
switch v := src.(type) {
|
|
case string:
|
|
*s = strings.Fields(v)
|
|
case []byte:
|
|
*s = strings.Fields(string(v))
|
|
case nil:
|
|
*s = nil
|
|
default:
|
|
return fmt.Errorf("cannot scan %T into Scopes", src)
|
|
}
|
|
return nil
|
|
}
|
|
|
|
type GrantRepository interface {
|
|
Put(ctx context.Context, g *Grant) error
|
|
Get(ctx context.Context, id string) (*Grant, error)
|
|
FindBySecretHash(ctx context.Context, hash string) (*Grant, error)
|
|
GetAllForUser(ctx context.Context, userID string, epoch int, idleSince time.Time, offset, limit int) (Grants, error)
|
|
CountForUser(ctx context.Context, userID string, epoch int, idleSince time.Time) (int64, error)
|
|
DeleteForUser(ctx context.Context, userID, id string) error
|
|
DeleteStaleEpochs(ctx context.Context, userID string, currentEpoch int) error
|
|
SetEpoch(ctx context.Context, userID string, fromEpoch, toEpoch int, onlyID string) error
|
|
Touch(ctx context.Context, id, ip string, at, notSince time.Time) error
|
|
DeleteIdle(ctx context.Context, idleSince time.Time) (int64, error)
|
|
}
|