cache

package
v0.27.0-rc.8 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 4, 2026 License: Apache-2.0 Imports: 10 Imported by: 8

Documentation

Index

Constants

View Source
const SystemKey = "system"

SystemKey caches the instance's singleton system row.

It is deliberately shared across editions and layers: the Community API service reads it, the Cloud/Enterprise service reads it, and the cloud store deletes it when an administrator reconfigures authentication. Those live in three packages and two repositories, so the name has to be defined once — a second literal spelling of it silently stops invalidating.

Variables

View Source
var ErrGetNotFound = errors.New("failed to find the value on the cache")

ErrGetNotFound is returned when a key is absent. A miss is an error here rather than a zero value, so a caller cannot mistake "nothing cached" for "cached nothing".

Functions

func Get added in v0.17.0

func Get[T any](ctx context.Context, cache Cache, key string) (*T, error)

Get reads a key and decodes it into T, saving the caller a variable to pass by address. It returns ErrGetNotFound when the key is absent.

Types

type Cache

type Cache interface {
	Get(ctx context.Context, key string, value any) error
	Set(ctx context.Context, key string, value any, ttl time.Duration) error
	Delete(ctx context.Context, key string) error

	// SetNX atomically sets key to value with the given ttl only if the key does
	// not already exist, and reports whether it was set. It is the building block
	// for single-use reservations (e.g. a pairing code claimed by exactly one
	// device even under concurrent requests), which Get+Set cannot do race-free.
	SetNX(ctx context.Context, key string, value any, ttl time.Duration) (bool, error)

	// HasAccountLockout reports whether the source is currently blocked from attempting to
	// log in to a user with the specified userID. It returns the absolute Unix timestamp
	// in seconds representing the end of the lockout, or 0 if no lockout was found; the
	// attempt number and an error if any.
	HasAccountLockout(ctx context.Context, source, userID string) (lockout int64, attempt int, err error)

	// StoreLoginAttempt stores a login attempt from source to the user with the specified userID.
	// If the attempt number equals or exceeds 3, it sets a lockout for future login attempts.
	//
	// The lockout duration is calculated based on the number of attempts made, increasing exponentially
	// by a factor of 4 after the third attempt. Attempts must last for half of the double lockout duration.
	//
	// This means that a user who was locked out for 4 minutes must have the attempts stored for 10
	// minutes (or 6 minutes after the timeout). Any wrong attempt within this time will increase the
	// lockout once again. After this, the attempts will be reset, and new wrong attempts will start the
	// attempt counter from 0.
	//
	// The following equations are used to calculate both lockout and attempt duration, with 'x' representing
	// the lockout duration and 'y' the attempt duration:
	//
	//	F(x) = min(4^(a - 3), M)
	//	F(y) = min(x * 2.5, M)
	//
	// Where:
	//
	//	x is the lockout duration in minutes.
	//	y is the attempt duration in minutes.
	//	a is the attempt number.
	//	M is the maximum duration value, specified by the "SHELLHUB_MAXIMUM_ACCOUNT_LOCKOUT" environment variable.
	//
	// Examples for M = 32768 (15 days) and a = n:
	//
	//	n    = 3 | 4  | 5  | 8    | 11
	//	_________________________________
	//	F(x) = 1 | 4  | 16 | 1024 | 32768
	//	F(y) = 3 | 10 | 40 | 2560 | 32768
	//
	// It returns the absolute Unix timestamp in seconds representing the end of the lockout, or 0 if no
	// lockout was found; the attempt number and an error if any.
	StoreLoginAttempt(ctx context.Context, source, userID string) (lockout int64, attempt int, err error)

	// ResetLoginAttempts resets the login attempts and associated lockout from the source to
	// the user with the specified userID.
	ResetLoginAttempts(ctx context.Context, source, userID string) error
}

Cache is the key/value store the services cache in. Implementations must be safe for concurrent use; NewNullCache is the no-op one, which is what an instance without Redis runs.

func NewNullCache

func NewNullCache() Cache

NewNullCache returns a cache that stores nothing and reports every read as a miss. It is what an instance without Redis runs, so a missing cache degrades to recomputing rather than to failing.

func NewRedisCache

func NewRedisCache(uri string, pool int) (Cache, error)

NewRedisCache connects to Redis and returns a cache backed by it. It fails rather than falling back: a misconfigured URI should surface at startup, not as silent cache misses forever.

Directories

Path Synopsis

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL