Applied the fixes warranted by the adversarial review of PR #21 (all findings graded in the gadfly store): Store (highest impact): - buildDSN always merges busy_timeout/journal_mode/foreign_keys pragmas into the DSN, even for file: URIs or paths with a query string — the prior passthrough silently disabled FK enforcement for those PANSY_DB values. Also escape '#' in the path and tighten in-memory detection to an exact ':memory:' token or mode=memory param (no substring misfire). - migrate.go: detect duplicate migration versions with a clear error; wrap appliedVersions' rows.Err() with the store: prefix. API: - SetTrustedProxies failure now falls back to trust-none instead of leaving gin's trust-everyone default (X-Forwarded-For spoofing). - SPA: 404 embedded directories (was a directory listing), 404 bare /api, add X-Content-Type-Options: nosniff, cache index.html bytes once at startup, single fs.Stat existence check, shared writeAPIError helper. - Move gin.SetMode out of package init() into New(). Config: validate PANSY_PORT range (fall back to 8080 with a warning). Web: - api.ts: serialize the request body before the fetch try so a JSON.stringify failure isn't misreported as a network error. - AppShell: move state-specific/conflicting utilities into active/inactiveProps so concatenated Tailwind classes don't collide. Tests: added store DSN-pragma/memory-detection cases and SPA directory-404 case. go build/vet/test clean (CGO off); web tsc + build clean; re-verified in a browser (SPA, deep links, /assets 404, nav). Co-Authored-By: Claude Opus 4.8 (1M context) <[email protected]> Claude-Session: https://claude.ai/code/session_01JdQpdYYsTgtkJBxbcpAszi
144 lines
3.9 KiB
Go
144 lines
3.9 KiB
Go
package store
|
|
|
|
import (
|
|
"context"
|
|
"embed"
|
|
"fmt"
|
|
"io/fs"
|
|
"log/slog"
|
|
"sort"
|
|
"strconv"
|
|
"strings"
|
|
)
|
|
|
|
//go:embed migrations/*.sql
|
|
var migrationsFS embed.FS
|
|
|
|
// migration is one numbered SQL file: version parsed from the filename prefix.
|
|
type migration struct {
|
|
version int
|
|
name string
|
|
sql string
|
|
}
|
|
|
|
// Migrate applies every embedded migration whose version has not yet been
|
|
// recorded, in ascending order, each in its own transaction. It is idempotent:
|
|
// a second run with no new files is a no-op. Migration files are named
|
|
// NNNN_description.sql (e.g. 0001_init.sql); NNNN is the version.
|
|
func (d *DB) Migrate(ctx context.Context) error {
|
|
if _, err := d.sql.ExecContext(ctx,
|
|
`CREATE TABLE IF NOT EXISTS schema_migrations (version INTEGER PRIMARY KEY)`,
|
|
); err != nil {
|
|
return fmt.Errorf("store: create schema_migrations: %w", err)
|
|
}
|
|
|
|
applied, err := d.appliedVersions(ctx)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
|
|
migrations, err := loadMigrations()
|
|
if err != nil {
|
|
return err
|
|
}
|
|
|
|
for _, m := range migrations {
|
|
if applied[m.version] {
|
|
continue
|
|
}
|
|
if err := d.applyMigration(ctx, m); err != nil {
|
|
return err
|
|
}
|
|
slog.Info("store: applied migration", "version", m.version, "name", m.name)
|
|
}
|
|
return nil
|
|
}
|
|
|
|
func (d *DB) appliedVersions(ctx context.Context) (map[int]bool, error) {
|
|
rows, err := d.sql.QueryContext(ctx, `SELECT version FROM schema_migrations`)
|
|
if err != nil {
|
|
return nil, fmt.Errorf("store: read schema_migrations: %w", err)
|
|
}
|
|
defer rows.Close()
|
|
|
|
applied := map[int]bool{}
|
|
for rows.Next() {
|
|
var v int
|
|
if err := rows.Scan(&v); err != nil {
|
|
return nil, fmt.Errorf("store: scan schema_migrations: %w", err)
|
|
}
|
|
applied[v] = true
|
|
}
|
|
if err := rows.Err(); err != nil {
|
|
return nil, fmt.Errorf("store: iterate schema_migrations: %w", err)
|
|
}
|
|
return applied, nil
|
|
}
|
|
|
|
func (d *DB) applyMigration(ctx context.Context, m migration) error {
|
|
tx, err := d.sql.BeginTx(ctx, nil)
|
|
if err != nil {
|
|
return fmt.Errorf("store: begin migration %d: %w", m.version, err)
|
|
}
|
|
defer tx.Rollback() //nolint:errcheck // no-op after a successful commit
|
|
|
|
if _, err := tx.ExecContext(ctx, m.sql); err != nil {
|
|
return fmt.Errorf("store: apply migration %d (%s): %w", m.version, m.name, err)
|
|
}
|
|
if _, err := tx.ExecContext(ctx,
|
|
`INSERT INTO schema_migrations (version) VALUES (?)`, m.version,
|
|
); err != nil {
|
|
return fmt.Errorf("store: record migration %d: %w", m.version, err)
|
|
}
|
|
return tx.Commit()
|
|
}
|
|
|
|
// loadMigrations reads and parses every embedded migration file, sorted by
|
|
// version ascending.
|
|
func loadMigrations() ([]migration, error) {
|
|
entries, err := fs.ReadDir(migrationsFS, "migrations")
|
|
if err != nil {
|
|
return nil, fmt.Errorf("store: read migrations dir: %w", err)
|
|
}
|
|
|
|
var migrations []migration
|
|
seen := map[int]string{}
|
|
for _, e := range entries {
|
|
if e.IsDir() || !strings.HasSuffix(e.Name(), ".sql") {
|
|
continue
|
|
}
|
|
version, err := parseVersion(e.Name())
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
if prev, dup := seen[version]; dup {
|
|
return nil, fmt.Errorf("store: duplicate migration version %d: %q and %q", version, prev, e.Name())
|
|
}
|
|
seen[version] = e.Name()
|
|
body, err := fs.ReadFile(migrationsFS, "migrations/"+e.Name())
|
|
if err != nil {
|
|
return nil, fmt.Errorf("store: read migration %s: %w", e.Name(), err)
|
|
}
|
|
migrations = append(migrations, migration{version: version, name: e.Name(), sql: string(body)})
|
|
}
|
|
|
|
sort.Slice(migrations, func(i, j int) bool {
|
|
return migrations[i].version < migrations[j].version
|
|
})
|
|
return migrations, nil
|
|
}
|
|
|
|
// parseVersion extracts the leading integer from a migration filename such as
|
|
// "0001_init.sql".
|
|
func parseVersion(name string) (int, error) {
|
|
prefix, _, ok := strings.Cut(name, "_")
|
|
if !ok {
|
|
return 0, fmt.Errorf("store: migration %q missing NNNN_ prefix", name)
|
|
}
|
|
v, err := strconv.Atoi(prefix)
|
|
if err != nil {
|
|
return 0, fmt.Errorf("store: migration %q has non-numeric version: %w", name, err)
|
|
}
|
|
return v, nil
|
|
}
|