Documentation
¶
Index ¶
- type AuthUser
- type Cache
- type CreateAdminUserParams
- type DBTX
- type IncrementCacheCounterParams
- type IncrementCacheCounterRow
- type NullRoleType
- type Queries
- func (q *Queries) CreateAdminUser(ctx context.Context, arg CreateAdminUserParams) error
- func (q *Queries) DeleteCacheEntries(ctx context.Context, keys []string) error
- func (q *Queries) DeleteCacheEntriesByPattern(ctx context.Context, pattern string) error
- func (q *Queries) GetCacheEntry(ctx context.Context, key string) (json.RawMessage, error)
- func (q *Queries) GetUser(ctx context.Context, email string) (AuthUser, error)
- func (q *Queries) GetUserDetails(ctx context.Context, email string) (AuthUser, error)
- func (q *Queries) IncrementCacheCounter(ctx context.Context, arg IncrementCacheCounterParams) (IncrementCacheCounterRow, error)
- func (q *Queries) ListCacheKeysByPattern(ctx context.Context, pattern string) ([]string, error)
- func (q *Queries) PurgeExpiredCacheEntries(ctx context.Context) (int64, error)
- func (q *Queries) SetCacheEntry(ctx context.Context, arg SetCacheEntryParams) error
- func (q *Queries) UpdateVerification(ctx context.Context, arg UpdateVerificationParams) (int64, error)
- func (q *Queries) WithTx(tx pgx.Tx) *Queries
- type RoleType
- type SetCacheEntryParams
- type UpdateVerificationParams
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type AuthUser ¶
type AuthUser struct {
ID int64 `json:"id"`
Email string `json:"email"`
EmailVerified bool `json:"email_verified"`
Phone string `json:"phone"`
PhoneVerified bool `json:"phone_verified"`
Password string `json:"password"`
Role RoleType `json:"role"`
CreatedAt pgtype.Timestamptz `json:"created_at"`
UpdatedAt pgtype.Timestamptz `json:"updated_at"`
}
type Cache ¶
type Cache struct {
// Opaque namespaced key. Rate-limit keys embed a sha256 digest of the identifier, never a raw email or IP.
Key string `json:"key"`
Value json.RawMessage `json:"value"`
// NULL means the entry never expires. Expired rows stay readable-as-absent until the purge job reaps them.
ExpiresAt pgtype.Timestamptz `json:"expires_at"`
CreatedAt pgtype.Timestamptz `json:"created_at"`
}
Shared UNLOGGED key/value cache and fixed-window rate-limit counters.
type CreateAdminUserParams ¶
type IncrementCacheCounterRow ¶
type IncrementCacheCounterRow struct {
Hits int32 `json:"hits"`
ExpiresAt pgtype.Timestamptz `json:"expires_at"`
}
type NullRoleType ¶
type NullRoleType struct {
RoleType RoleType `json:"role_type"`
Valid bool `json:"valid"` // Valid is true if RoleType is not NULL
}
func (*NullRoleType) Scan ¶
func (ns *NullRoleType) Scan(value interface{}) error
Scan implements the Scanner interface.
type Queries ¶
type Queries struct {
// contains filtered or unexported fields
}
func (*Queries) CreateAdminUser ¶
func (q *Queries) CreateAdminUser(ctx context.Context, arg CreateAdminUserParams) error
func (*Queries) DeleteCacheEntries ¶
func (*Queries) DeleteCacheEntriesByPattern ¶
DeleteCacheEntriesByPattern takes a SQL LIKE pattern; callers translate the glob-style '*' they use elsewhere into '%'.
func (*Queries) GetCacheEntry ¶
Queries for the shared UNLOGGED `cache` table. Every one of them treats an expired row as absent rather than deleting it inline; reaping is the purge job's business. GetCacheEntry reads a live entry. An expired row matches no predicate here, so a caller can never observe a stale value even before the purge runs.
func (*Queries) GetUserDetails ¶
func (*Queries) IncrementCacheCounter ¶
func (q *Queries) IncrementCacheCounter(ctx context.Context, arg IncrementCacheCounterParams) (IncrementCacheCounterRow, error)
IncrementCacheCounter bumps a fixed-window counter and returns its new value together with the instant the window closes.
The upsert and the conditional window reset are ONE statement on purpose. A read-then-write loses increments under concurrency — two callers both read N and both write N+1 — which is precisely the failure a rate limiter must not have. Here the ON CONFLICT path takes a row lock, so concurrent callers are serialized by Postgres and every hit is counted exactly once.
The first hit, or a hit arriving after the window lapsed, restarts the window at 1. A hit inside a live window increments and leaves expires_at alone, so a blocked caller cannot extend their own penalty window by retrying.
func (*Queries) ListCacheKeysByPattern ¶
func (*Queries) PurgeExpiredCacheEntries ¶
PurgeExpiredCacheEntries reaps rows the reads already ignore. Without it the table grows forever, since a lapsed rate-limit window is never revisited.
func (*Queries) SetCacheEntry ¶
func (q *Queries) SetCacheEntry(ctx context.Context, arg SetCacheEntryParams) error
SetCacheEntry writes or replaces an entry. A ttl_seconds of 0 stores an entry that never expires; created_at is refreshed because a replaced value is a new entry, not an update to the old one.
func (*Queries) UpdateVerification ¶
type SetCacheEntryParams ¶
type SetCacheEntryParams struct {
Key string `json:"key"`
Value json.RawMessage `json:"value"`
TtlSeconds int32 `json:"ttl_seconds"`
}