exec

package
v0.2.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Jul 21, 2026 License: MIT Imports: 19 Imported by: 0

Documentation

Overview

Package exec owns the request lifecycle: parse/validate, depth and cost limits, per-operation transactions, RLS role switching + claims via set_config, execution of compiled statements, and PG->GraphQL error mapping.

Introspection resolves the __schema / __type / __typename meta fields in Go against the built *ast.Schema. These fields have no SQL mapping, so they are answered before compilation; everything needed is already in memory.

Index

Constants

View Source
const IntrospectionQuery = `` /* 1012-byte string literal not displayed */

IntrospectionQuery is the standard full introspection document (the shape graphql-js getIntrospectionQuery() produces). It is resolved entirely in memory, so it works on an executor with a nil pool — `pdbq schema print --json` relies on that.

Variables

This section is empty.

Functions

func ClaimsFromContext

func ClaimsFromContext(ctx context.Context) map[string]any

ClaimsFromContext returns the verified request claims, or nil outside a request. Shorthand for OperationFromContext(ctx).Claims.

func WithOperation

func WithOperation(ctx context.Context, op *Operation) context.Context

WithOperation attaches the in-flight operation to the context. The executor does this before running RequestHooks and compiling, so CompileHook plugins (whose compile.Func only receives a context) can reach the verified claims, role, and operation metadata.

Types

type Executor

type Executor struct {
	Pool    *pgxpool.Pool
	Built   *schema.Built
	Compile compile.Func
	Hooks   []RequestHook
	Opts    Options
}

Executor executes GraphQL requests against a pool.

func New

func New(pool *pgxpool.Pool, built *schema.Built, compileFn compile.Func, hooks []RequestHook, opts Options) *Executor

func (*Executor) Execute

func (e *Executor) Execute(ctx context.Context, req Request) *Result

Execute runs one GraphQL request end to end.

type MintOptions

type MintOptions struct {
	Schema   string // pg schema of the composite, e.g. "public"
	Type     string // composite type name, e.g. "jwt"
	Secret   string
	Issuer   string
	Audience string
}

MintOptions turns function results of one composite type into signed JWTs (PostGraphile's pgJwtType). A function returning schema.type yields an HS256 token string whose claims are the composite's fields; an exp field becomes the token expiry.

func (MintOptions) Enabled

func (m MintOptions) Enabled() bool

type Operation

type Operation struct {
	Name       string
	Type       ast.Operation
	Document   *ast.QueryDocument
	Definition *ast.OperationDefinition
	Vars       map[string]any
	// Claims are the verified request claims exposed to RLS policies.
	Claims map[string]any
	// Role is the database role this operation runs as ("" = no switch).
	Role string
	// ForceTx forces a transaction even when the global policy would skip it.
	ForceTx bool
}

Operation is one GraphQL operation in flight; RequestHook plugins can read and mutate it (notably ForceTx).

func OperationFromContext

func OperationFromContext(ctx context.Context) *Operation

OperationFromContext returns the in-flight operation attached by the executor, or nil when called outside a request (e.g. schema build).

type Options

type Options struct {
	MaxDepth int
	MaxCost  int
	// MaxPageSize caps first/last and is the default page size when neither
	// is given.
	MaxPageSize int
	// TxMutations wraps every mutation in a transaction.
	TxMutations bool
	// TxPerRequest wraps the entire request (queries included) in one
	// transaction, so every root field reads a single snapshot.
	TxPerRequest bool
	// TxRetries re-runs a transactional operation after a serialization
	// failure or deadlock (SQLSTATE 40001/40P01); safe because the failed
	// attempt rolled back completely.
	TxRetries int
	Isolation pgx.TxIsoLevel
	// RLS enables SET LOCAL ROLE + claims set_config per operation.
	RLS          bool
	ClaimsPrefix string
	// DevErrors exposes full PG error details in GraphQL errors.
	DevErrors bool
	// Mint signs function results of one composite type into JWTs.
	Mint   MintOptions
	Logger *slog.Logger
}

Options for the executor.

type Request

type Request struct {
	Query         string
	OperationName string
	Variables     map[string]any
	Claims        map[string]any
	Role          string
}

Request is a raw GraphQL HTTP/CLI request.

type RequestHook

type RequestHook interface {
	BeforeOperation(ctx context.Context, op *Operation) (context.Context, error)
	AfterOperation(ctx context.Context, op *Operation, res *Result)
}

RequestHook mirrors plugin.RequestHook (redeclared here to avoid an import cycle; the interfaces are structurally identical).

type Result

type Result struct {
	Data   map[string]json.RawMessage
	Errors gqlerror.List
}

Result is the GraphQL response for one operation.

func (*Result) MarshalJSON

func (r *Result) MarshalJSON() ([]byte, error)

MarshalJSON renders the result as a spec-shaped GraphQL response.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL