mirror of
https://github.com/Termix-SSH/Termix.git
synced 2026-08-29 10:21:34 +00:00
release-2.6.1 (#1161)
* fix: preserve remote sync references (#1092) * fix: centralize outbound address validation (#1093) * fix: preserve architecture in unpacked ASAR path (#1094) * fix: allow sharing empty folders (#1096) * fix: preserve WoL broadcast address (#1097) * fix: deduplicate shared hosts (#1098) * fix snippet execution result handling (#1099) * fix SSH login alert delivery (#1100) * fix outbound DNS lookup callback shape (#1101) * fix OIDC verification for JWKs without alg (#1102) * fix file manager navigation after permission errors (#1103) * fix database persistence during container shutdown (#1104) * fix: persist host command history setting (#1107) * fix: recognize Windows terminal Tab events (#1109) * fix: recognize Windows terminal Tab events * style: format terminal key event test * fix: export repository user record (#1111) * fix: keep localhost database export same-origin (#1112) * fix: support Tailscale auth in tmux monitor (#1113) * fix: forward Android hardware keyboard keys (#1114) * fix: expose jump tunnels to guacd (#1115) * fix OIDC login with unverifiable ID tokens (#1117) verifyOIDCToken passed the raw id_token straight to jose's jwtVerify, which throws JWSInvalid when the token is not a three-segment compact JWS. Authentik issues an encrypted JWE id_token when the provider has an encryption key set, so the callback threw and every OIDC login failed with 'Invalid Compact JWS'. 2.5.0 hid this behind a catch-all that decoded the unverified payload; removing that fallback fixed the trust bug but turned the pre-existing verification failure into a hard login failure. Check the segment count before verifying and raise a distinct OIDCTokenFormatError, which the callback treats as 'no usable claims here' and falls through to the userinfo endpoint. Signature and claim failures still reject the login. Fixes Termix-SSH/Support#1016 Fixes Termix-SSH/Support#1018 * refuse to start with an empty database when data exists elsewhere (#1118) When the data directory holds no database, startup treats it as a first run and silently creates an empty one. A deployment that loses DATA_DIR — an .env file the service no longer loads, a volume that did not mount — lands in exactly that state, so the user is asked to register an admin account again while the real database sits untouched one directory over. It is indistinguishable from the upgrade having deleted everything. Check the known data locations before creating a new database and refuse to start when one of them already holds a database, naming both directories. ALLOW_EMPTY_DATA_DIR=true starts anyway for anyone deliberately starting over. This matches how a failed decryption already behaves: it throws rather than falling back to an empty database. Closes Termix-SSH/Support#1006 * stop read-only shared hosts from being dragged into folders (#1119) Shared hosts hide their edit, share and delete actions based on the recipient's permission level, but the sidebar row stays draggable regardless. Dropping one on a folder issues a bulk folder update the server rejects, so a recipient without edit rights gets a failure toast for an action the UI offered them. Gate draggable on canEditHost, and skip hosts the recipient cannot edit in the move handler so a mixed selection moves what it can instead of failing whole. Closes Termix-SSH/Support#1011 * apply the configured RDP resolution to the session (#1120) The host editor stores width and height in guacamoleConfig, and the backend passes them to guacd in the connection token. The renderer then appends its own width and height query parameters measured from the container, which take precedence, so a configured resolution never reached the session — only dpi did, because that was the one display field GuacamoleApp read back. Pass the configured width and height alongside dpi, and skip the container-driven sendSize on connect and on resize when a resolution is pinned. rescaleDisplay still fits the fixed display into the available space. Closes Termix-SSH/Support#1039 * honour per-host recording flags and explain a missing recording (#1121) The session recording section offers a recording path, a filename template and four content toggles, but the backend overwrote five of the six on every connection. A host could set none of them and get no indication why. Location and filename genuinely are not the host's to choose — recordings are indexed by them for playback and the backend refuses to read outside its recordings directory — so drop those two inputs rather than keep pretending they apply. The content flags are a host-level decision, so default them instead of forcing them. That still leaves the reported case, where guacd writes the file somewhere the backend cannot see it. The warning now reports both paths and names the two env vars that align them, which is otherwise guesswork for a split-container setup. Closes Termix-SSH/Support#1041 * route desktop guacd calls to the connected remote server (#1122) resolveConnectionOrigin() pins RDP/VNC/Telnet to "remote" because the embedded desktop backend does not bundle guacd, and the Guacamole websocket already follows that. The status check and both token calls did not: they use the shared authApi, which in Electron is hard-coded to the embedded backend. So the desktop app asked the backend without guacd whether guacd was available, got "disconnected", and refused to connect — while the connected server it would actually have used reports it as connected and serves the same host fine from the web client. Send those three calls through a remote-origin instance in Electron, alongside the existing file-manager, tunnel and stats ones. Closes Termix-SSH/Support#1043 * move the Homebrew cask to where a tap looks for it (#1123) A tap discovers casks in a top-level Casks/ directory. The cask sat in packaging/Casks/, so tapping the repository succeeded and every subsequent brew install --cask termix reported that no cask with that name exists. Move it and repoint the five workflow references. The release job still rewrites the version and checksum in place, and the electron job still copies it into the generated and submission trees. Closes Termix-SSH/Support#1044 * stop highlighting inside a split control string (#1124) A control string (OSC/DCS/APC/PM) carries text that must never be displayed — an OSC 0 title holds the user, host and path, and PROMPT_COMMAND emits one on every prompt. Its opener and its terminator routinely land in different websocket frames, and the continuation frame contains no escape byte at all, so every guard in the highlighter misses it: TUI_SEQUENCE, CONTROL_STRING_SEQUENCE and hasIncompleteAnsiSequence all only look at one chunk. Highlighting that continuation injects an SGR sequence into the middle of the open string, which aborts it early in xterm.js and prints the remainder as ordinary text — the stray ~/path glued to the prompt, and the cursor arithmetic drift behind the duplicate prompts and Ctrl+R corruption. Track the state across chunks the way alternate-screen mode already is, and skip any chunk that starts or ends inside a control string. A trailing lone ESC counts as inside, since its meaning only arrives with the next chunk. Closes Termix-SSH/Support#1025 * stop session-log route test importing the real repository layer (#1125) The test mocks db, logger and AuthManager, but the route module also calls PermissionManager.getInstance() at import time and pulls in the repository factory, which loads the drizzle schema and the better-sqlite3 native binding. Importing that costs seconds when the full suite runs its projects concurrently, and the test times out at 5s. On its own it passes, so it read as flaky rather than as a missing mock. Mock both. None of it is under test here, and the file now imports in milliseconds regardless of load. * fail the guacamole-lite patch when an anchor is gone (#1126) Each patch bails out with a console.log and process.exit(0) when its anchor string is missing. The write-back happens at the end of the file, so an upstream release that moves any one anchor drops every patch, exits successfully, and leaves postinstall reporting nothing wrong. Termix then builds and starts normally and drops VNC/RDP sessions at runtime — with no signal pointing at the patch. Every patch here is required for correctness: protocol negotiation, the guacd 1.6.0 name handshake, dynamic argument answering, UTF-8 tokens, read-only joins. A missing anchor means the patch no longer applies, so exit non-zero and say which one and what to do. Unchanged: a missing guacamole-lite still skips quietly, and an already-patched tree still exits 0. * fix: clarify desktop local profile (#1095) * fix: clarify desktop local profile * cover the AccordionSection hidden branch The desktop build hides the Security section because the embedded profile signs in automatically and has no login password, so the controls there would imply a protection that does not exist. Nothing asserted that hidden actually keeps the children out of the DOM rather than merely collapsing them. Export the component and cover both states, including that an expanded hidden section still renders nothing. * fix: show remote sync account identity (#1110) * fix: show remote sync account identity * cover getRemoteSyncUserInfo and make its null contract hold Nothing asserted the renderer-side gate: browser builds must not reach for the IPC bridge, and a missing bridge, an unconfigured server, an expired JWT or a failed channel all have to degrade to no identity rather than throw. Writing that turned up a mismatch — with no preload bridge the optional chain resolved to undefined while the signature promises null. The only caller uses ??, so nothing is broken today, but the type was not telling the truth. The main-process half (token expiry, /users/me, the roles fallback) stays uncovered: remote-sync.cjs requires electron at load, so exercising it means stubbing safeStorage and the filesystem, which is a bigger change than this PR warrants. * improve settings navigation and legal disclosure (#1105) * fix desktop preference synchronization (#1106) * fix: use jump host SOCKS proxy settings (#1116) * ci(deps): bump the github-actions group with 2 updates (#1086) Bumps the github-actions group with 2 updates: [actions/setup-node](https://github.com/actions/setup-node) and [useblacksmith/setup-docker-builder](https://github.com/useblacksmith/setup-docker-builder). Updates `actions/setup-node` from 6 to 7 - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](https://github.com/actions/setup-node/compare/v6...v7) Updates `useblacksmith/setup-docker-builder` from 1 to 2 - [Release notes](https://github.com/useblacksmith/setup-docker-builder/releases) - [Commits](https://github.com/useblacksmith/setup-docker-builder/compare/v1...v2) --- updated-dependencies: - dependency-name: actions/setup-node dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: useblacksmith/setup-docker-builder dependency-version: '2' dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps-dev): bump the dev-patch-updates group with 23 updates (#1087) Bumps the dev-patch-updates group with 23 updates: | Package | From | To | | --- | --- | --- | | [@biomejs/biome](https://github.com/biomejs/biome/tree/HEAD/packages/@biomejs/biome) | `2.5.4` | `2.5.5` | | [@radix-ui/react-accordion](https://github.com/radix-ui/primitives/tree/HEAD/packages/react/accordion) | `1.2.17` | `1.2.20` | | [@radix-ui/react-alert-dialog](https://github.com/radix-ui/primitives/tree/HEAD/packages/react/alert-dialog) | `1.1.20` | `1.1.23` | | [@radix-ui/react-checkbox](https://github.com/radix-ui/primitives/tree/HEAD/packages/react/checkbox) | `1.3.8` | `1.3.11` | | [@radix-ui/react-dialog](https://github.com/radix-ui/primitives/tree/HEAD/packages/react/dialog) | `1.1.20` | `1.1.23` | | [@radix-ui/react-dropdown-menu](https://github.com/radix-ui/primitives/tree/HEAD/packages/react/dropdown-menu) | `2.1.21` | `2.1.24` | | [@radix-ui/react-label](https://github.com/radix-ui/primitives/tree/HEAD/packages/react/label) | `2.1.12` | `2.1.15` | | [@radix-ui/react-popover](https://github.com/radix-ui/primitives/tree/HEAD/packages/react/popover) | `1.1.20` | `1.1.23` | | [@radix-ui/react-progress](https://github.com/radix-ui/primitives/tree/HEAD/packages/react/progress) | `1.1.13` | `1.1.16` | | [@radix-ui/react-scroll-area](https://github.com/radix-ui/primitives/tree/HEAD/packages/react/scroll-area) | `1.2.15` | `1.2.18` | | [@radix-ui/react-select](https://github.com/radix-ui/primitives/tree/HEAD/packages/react/select) | `2.3.4` | `2.3.7` | | [@radix-ui/react-separator](https://github.com/radix-ui/primitives/tree/HEAD/packages/react/separator) | `1.1.12` | `1.1.15` | | [@radix-ui/react-slider](https://github.com/radix-ui/primitives/tree/HEAD/packages/react/slider) | `1.4.4` | `1.4.7` | | [@radix-ui/react-slot](https://github.com/radix-ui/primitives/tree/HEAD/packages/react/slot) | `1.3.0` | `1.3.3` | | [@radix-ui/react-switch](https://github.com/radix-ui/primitives/tree/HEAD/packages/react/switch) | `1.3.4` | `1.3.7` | | [@radix-ui/react-tabs](https://github.com/radix-ui/primitives/tree/HEAD/packages/react/tabs) | `1.1.18` | `1.1.21` | | [@radix-ui/react-tooltip](https://github.com/radix-ui/primitives/tree/HEAD/packages/react/tooltip) | `1.2.13` | `1.2.16` | | [@vitejs/plugin-react](https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react) | `6.0.3` | `6.0.4` | | [concurrently](https://github.com/open-cli-tools/concurrently) | `10.0.3` | `10.0.4` | | [radix-ui](https://github.com/radix-ui/primitives/tree/HEAD/packages/react/radix-ui) | `1.6.3` | `1.6.7` | | [react](https://github.com/react/react/tree/HEAD/packages/react) | `19.2.7` | `19.2.8` | | [react-dom](https://github.com/react/react/tree/HEAD/packages/react-dom) | `19.2.7` | `19.2.8` | | [react-i18next](https://github.com/i18next/react-i18next) | `17.0.10` | `17.0.11` | Updates `@biomejs/biome` from 2.5.4 to 2.5.5 - [Release notes](https://github.com/biomejs/biome/releases) - [Changelog](https://github.com/biomejs/biome/blob/main/packages/@biomejs/biome/CHANGELOG.md) - [Commits](https://github.com/biomejs/biome/commits/@biomejs/biome@2.5.5/packages/@biomejs/biome) Updates `@radix-ui/react-accordion` from 1.2.17 to 1.2.20 - [Changelog](https://github.com/radix-ui/primitives/blob/main/packages/react/accordion/CHANGELOG.md) - [Commits](https://github.com/radix-ui/primitives/commits/HEAD/packages/react/accordion) Updates `@radix-ui/react-alert-dialog` from 1.1.20 to 1.1.23 - [Changelog](https://github.com/radix-ui/primitives/blob/main/packages/react/alert-dialog/CHANGELOG.md) - [Commits](https://github.com/radix-ui/primitives/commits/HEAD/packages/react/alert-dialog) Updates `@radix-ui/react-checkbox` from 1.3.8 to 1.3.11 - [Changelog](https://github.com/radix-ui/primitives/blob/main/packages/react/checkbox/CHANGELOG.md) - [Commits](https://github.com/radix-ui/primitives/commits/HEAD/packages/react/checkbox) Updates `@radix-ui/react-dialog` from 1.1.20 to 1.1.23 - [Changelog](https://github.com/radix-ui/primitives/blob/main/packages/react/dialog/CHANGELOG.md) - [Commits](https://github.com/radix-ui/primitives/commits/HEAD/packages/react/dialog) Updates `@radix-ui/react-dropdown-menu` from 2.1.21 to 2.1.24 - [Changelog](https://github.com/radix-ui/primitives/blob/main/packages/react/dropdown-menu/CHANGELOG.md) - [Commits](https://github.com/radix-ui/primitives/commits/HEAD/packages/react/dropdown-menu) Updates `@radix-ui/react-label` from 2.1.12 to 2.1.15 - [Changelog](https://github.com/radix-ui/primitives/blob/main/packages/react/label/CHANGELOG.md) - [Commits](https://github.com/radix-ui/primitives/commits/HEAD/packages/react/label) Updates `@radix-ui/react-popover` from 1.1.20 to 1.1.23 - [Changelog](https://github.com/radix-ui/primitives/blob/main/packages/react/popover/CHANGELOG.md) - [Commits](https://github.com/radix-ui/primitives/commits/HEAD/packages/react/popover) Updates `@radix-ui/react-progress` from 1.1.13 to 1.1.16 - [Changelog](https://github.com/radix-ui/primitives/blob/main/packages/react/progress/CHANGELOG.md) - [Commits](https://github.com/radix-ui/primitives/commits/HEAD/packages/react/progress) Updates `@radix-ui/react-scroll-area` from 1.2.15 to 1.2.18 - [Changelog](https://github.com/radix-ui/primitives/blob/main/packages/react/scroll-area/CHANGELOG.md) - [Commits](https://github.com/radix-ui/primitives/commits/HEAD/packages/react/scroll-area) Updates `@radix-ui/react-select` from 2.3.4 to 2.3.7 - [Changelog](https://github.com/radix-ui/primitives/blob/main/packages/react/select/CHANGELOG.md) - [Commits](https://github.com/radix-ui/primitives/commits/HEAD/packages/react/select) Updates `@radix-ui/react-separator` from 1.1.12 to 1.1.15 - [Changelog](https://github.com/radix-ui/primitives/blob/main/packages/react/separator/CHANGELOG.md) - [Commits](https://github.com/radix-ui/primitives/commits/HEAD/packages/react/separator) Updates `@radix-ui/react-slider` from 1.4.4 to 1.4.7 - [Changelog](https://github.com/radix-ui/primitives/blob/main/packages/react/slider/CHANGELOG.md) - [Commits](https://github.com/radix-ui/primitives/commits/HEAD/packages/react/slider) Updates `@radix-ui/react-slot` from 1.3.0 to 1.3.3 - [Changelog](https://github.com/radix-ui/primitives/blob/main/packages/react/slot/CHANGELOG.md) - [Commits](https://github.com/radix-ui/primitives/commits/HEAD/packages/react/slot) Updates `@radix-ui/react-switch` from 1.3.4 to 1.3.7 - [Changelog](https://github.com/radix-ui/primitives/blob/main/packages/react/switch/CHANGELOG.md) - [Commits](https://github.com/radix-ui/primitives/commits/HEAD/packages/react/switch) Updates `@radix-ui/react-tabs` from 1.1.18 to 1.1.21 - [Changelog](https://github.com/radix-ui/primitives/blob/main/packages/react/tabs/CHANGELOG.md) - [Commits](https://github.com/radix-ui/primitives/commits/HEAD/packages/react/tabs) Updates `@radix-ui/react-tooltip` from 1.2.13 to 1.2.16 - [Changelog](https://github.com/radix-ui/primitives/blob/main/packages/react/tooltip/CHANGELOG.md) - [Commits](https://github.com/radix-ui/primitives/commits/HEAD/packages/react/tooltip) Updates `@vitejs/plugin-react` from 6.0.3 to 6.0.4 - [Release notes](https://github.com/vitejs/vite-plugin-react/releases) - [Changelog](https://github.com/vitejs/vite-plugin-react/blob/main/packages/plugin-react/CHANGELOG.md) - [Commits](https://github.com/vitejs/vite-plugin-react/commits/plugin-react@6.0.4/packages/plugin-react) Updates `concurrently` from 10.0.3 to 10.0.4 - [Release notes](https://github.com/open-cli-tools/concurrently/releases) - [Commits](https://github.com/open-cli-tools/concurrently/compare/v10.0.3...v10.0.4) Updates `radix-ui` from 1.6.3 to 1.6.7 - [Changelog](https://github.com/radix-ui/primitives/blob/main/packages/react/radix-ui/CHANGELOG.md) - [Commits](https://github.com/radix-ui/primitives/commits/1.6.7/packages/react/radix-ui) Updates `react` from 19.2.7 to 19.2.8 - [Release notes](https://github.com/react/react/releases) - [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md) - [Commits](https://github.com/react/react/commits/v19.2.8/packages/react) Updates `react-dom` from 19.2.7 to 19.2.8 - [Release notes](https://github.com/react/react/releases) - [Changelog](https://github.com/react/react/blob/main/CHANGELOG.md) - [Commits](https://github.com/react/react/commits/v19.2.8/packages/react-dom) Updates `react-i18next` from 17.0.10 to 17.0.11 - [Changelog](https://github.com/i18next/react-i18next/blob/master/CHANGELOG.md) - [Commits](https://github.com/i18next/react-i18next/compare/v17.0.10...v17.0.11) --- updated-dependencies: - dependency-name: "@biomejs/biome" dependency-version: 2.5.5 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-patch-updates - dependency-name: "@radix-ui/react-accordion" dependency-version: 1.2.20 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-patch-updates - dependency-name: "@radix-ui/react-alert-dialog" dependency-version: 1.1.23 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-patch-updates - dependency-name: "@radix-ui/react-checkbox" dependency-version: 1.3.11 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-patch-updates - dependency-name: "@radix-ui/react-dialog" dependency-version: 1.1.23 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-patch-updates - dependency-name: "@radix-ui/react-dropdown-menu" dependency-version: 2.1.24 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-patch-updates - dependency-name: "@radix-ui/react-label" dependency-version: 2.1.15 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-patch-updates - dependency-name: "@radix-ui/react-popover" dependency-version: 1.1.23 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-patch-updates - dependency-name: "@radix-ui/react-progress" dependency-version: 1.1.16 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-patch-updates - dependency-name: "@radix-ui/react-scroll-area" dependency-version: 1.2.18 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-patch-updates - dependency-name: "@radix-ui/react-select" dependency-version: 2.3.7 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-patch-updates - dependency-name: "@radix-ui/react-separator" dependency-version: 1.1.15 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-patch-updates - dependency-name: "@radix-ui/react-slider" dependency-version: 1.4.7 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-patch-updates - dependency-name: "@radix-ui/react-slot" dependency-version: 1.3.3 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-patch-updates - dependency-name: "@radix-ui/react-switch" dependency-version: 1.3.7 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-patch-updates - dependency-name: "@radix-ui/react-tabs" dependency-version: 1.1.21 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-patch-updates - dependency-name: "@radix-ui/react-tooltip" dependency-version: 1.2.16 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-patch-updates - dependency-name: "@vitejs/plugin-react" dependency-version: 6.0.4 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-patch-updates - dependency-name: concurrently dependency-version: 10.0.4 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-patch-updates - dependency-name: radix-ui dependency-version: 1.6.7 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-patch-updates - dependency-name: react dependency-version: 19.2.8 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-patch-updates - dependency-name: react-dom dependency-version: 19.2.8 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-patch-updates - dependency-name: react-i18next dependency-version: 17.0.11 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: dev-patch-updates ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump the prod-patch-updates group with 3 updates (#1088) Bumps the prod-patch-updates group with 3 updates: [@tanstack/react-virtual](https://github.com/TanStack/virtual/tree/HEAD/packages/react-virtual), [jose](https://github.com/panva/jose) and [js-yaml](https://github.com/nodeca/js-yaml). Updates `@tanstack/react-virtual` from 3.14.6 to 3.14.8 - [Release notes](https://github.com/TanStack/virtual/releases) - [Changelog](https://github.com/TanStack/virtual/blob/main/packages/react-virtual/CHANGELOG.md) - [Commits](https://github.com/TanStack/virtual/commits/@tanstack/react-virtual@3.14.8/packages/react-virtual) Updates `jose` from 6.2.3 to 6.2.4 - [Release notes](https://github.com/panva/jose/releases) - [Changelog](https://github.com/panva/jose/blob/main/CHANGELOG.md) - [Commits](https://github.com/panva/jose/compare/v6.2.3...v6.2.4) Updates `js-yaml` from 5.2.1 to 5.2.2 - [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md) - [Commits](https://github.com/nodeca/js-yaml/compare/5.2.1...5.2.2) --- updated-dependencies: - dependency-name: "@tanstack/react-virtual" dependency-version: 3.14.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: prod-patch-updates - dependency-name: jose dependency-version: 6.2.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: prod-patch-updates - dependency-name: js-yaml dependency-version: 5.2.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: prod-patch-updates ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump undici in the prod-minor-updates group (#1089) Bumps the prod-minor-updates group with 1 update: [undici](https://github.com/nodejs/undici). Updates `undici` from 8.7.0 to 8.9.0 - [Release notes](https://github.com/nodejs/undici/releases) - [Commits](https://github.com/nodejs/undici/compare/v8.7.0...v8.9.0) --- updated-dependencies: - dependency-name: undici dependency-version: 8.9.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: prod-minor-updates ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump the major-updates group with 4 updates (#1090) Bumps the major-updates group with 4 updates: [better-sqlite3](https://github.com/WiseLibs/better-sqlite3), [chalk](https://github.com/chalk/chalk), [@testing-library/jest-dom](https://github.com/testing-library/jest-dom) and [typescript](https://github.com/microsoft/TypeScript). Updates `better-sqlite3` from 12.11.1 to 13.0.1 - [Release notes](https://github.com/WiseLibs/better-sqlite3/releases) - [Commits](https://github.com/WiseLibs/better-sqlite3/compare/v12.11.1...v13.0.1) Updates `chalk` from 5.6.2 to 6.0.0 - [Release notes](https://github.com/chalk/chalk/releases) - [Commits](https://github.com/chalk/chalk/compare/v5.6.2...v6.0.0) Updates `@testing-library/jest-dom` from 6.9.1 to 7.0.0 - [Release notes](https://github.com/testing-library/jest-dom/releases) - [Changelog](https://github.com/testing-library/jest-dom/blob/main/CHANGELOG.md) - [Commits](https://github.com/testing-library/jest-dom/compare/v6.9.1...v7.0.0) Updates `typescript` from 6.0.3 to 7.0.2 - [Release notes](https://github.com/microsoft/TypeScript/releases) - [Commits](https://github.com/microsoft/TypeScript/commits) --- updated-dependencies: - dependency-name: better-sqlite3 dependency-version: 13.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: major-updates - dependency-name: chalk dependency-version: 6.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: major-updates - dependency-name: "@testing-library/jest-dom" dependency-version: 7.0.0 dependency-type: direct:development update-type: version-update:semver-major dependency-group: major-updates - dependency-name: typescript dependency-version: 7.0.2 dependency-type: direct:development update-type: version-update:semver-major dependency-group: major-updates ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * restore lint by pinning typescript below 7 (#1131) #1090 bumped typescript to 7.0.2. typescript-eslint declares `typescript: >=4.8.4 <6.1.0`, and TypeScript 7 removed `ts.Extension`, which @typescript-eslint/typescript-estree dereferences at import time: node_modules/@typescript-eslint/typescript-estree/dist/create-program/shared.js:59 ts.Extension.Cjs, TypeError: Cannot read properties of undefined (reading 'Cjs') ESLint hits that while loading eslint.config.mjs, so `npm run lint` fails before linting anything. Node reports it as ERR_INTERNAL_ASSERTION, which hides the cause. Every open PR fails this check, not just new ones. Even the latest typescript-eslint prerelease still caps at <6.1.0, so there is nothing to upgrade to yet. Pin back to ~6.0.3 and tell dependabot to hold major typescript bumps until the ecosystem catches up. Also fixes biome.json pointing vcs.defaultBranch at dev-2.5.0, a branch that no longer exists. * make the repository layer engine-agnostic (#1127) DatabaseContext handed every repository a raw better-sqlite3 handle alongside drizzle, and three of them used it for retention queries built on datetime('now', ?) — a SQLite-only function. That handle is the one thing standing between the repository layer and a second engine. Drop it. The two time-based prunes compute their cutoff in JS against the CURRENT_TIMESTAMP text format, which every engine writes the same way and which compares correctly as a string; the health-history prune becomes a select of the rows to keep followed by a NOT IN delete. All three turn async, so their two callers await them. Name the dialect rather than repeating a string literal, so adding an engine is one edit instead of a search. Tests built their schema through context.sqlite?.exec(). Optional chaining meant removing the field type-checked cleanly and then silently created no tables, so the fixture now owns exec() and a raw handle for direct assertions — schema setup belongs to the test harness, not to the interface repositories consume. No behaviour change, and no Postgres yet: this only removes the coupling that would have to be undone first. * keep audit trails and recordings when a user is deleted (#1128) audit_logs and session_recordings both referenced users with ON DELETE CASCADE, so removing an account erased everything it had ever done. An audit trail that disappears with the account it recorded cannot answer the question it exists for, and a recording is evidence about a host as much as about a person. Both foreign keys become ON DELETE SET NULL. audit_logs already denormalises username, so an entry still names who acted once the reference is gone. session_recordings did not, so the column is added and backfilled first — otherwise relaxing the constraint would only trade deleted evidence for anonymous evidence. SQLite cannot alter a foreign key in place, so existing databases are migrated by copy-and-swap, guarded by a PRAGMA check that makes it idempotent. Fresh databases are created in the target shape and skip it. Recordings still cascade from their host. * audit the remaining remote access paths (#1129) Only SSH terminal sessions were audited. Opening a file manager session, an RDP, VNC or Telnet desktop, a Docker session or an SSH tunnel left no audit entry at all — which covers most of the ways data leaves a host or a foothold is established. Each of those four now writes an entry when the session is established, matching the existing ssh_connect: who, which host, from what address, and for tunnels the endpoint and local port being forwarded. Audit writes are fire-and-forget so they cannot delay or fail the connection, consistent with logAudit already swallowing its own errors. getAuditUsername was defined identically in two route files and is needed in four more, so it moves next to logAudit. * fix: honor lookupOptions.all in custom DNS lookup hook (#1084) Node's happy-eyeballs autoSelectFamily calls custom dns lookup functions with all:true and expects the full address array back. Always replying with a single (address, family) pair corrupted net's internal state, surfacing as "Invalid IP address: undefined" instead of a real connect error, breaking outbound notification delivery (webhook/ntfy). Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> Co-authored-by: ZacharyZcR <zacharyzcr1984@gmail.com> * fix: SSH-login alerts silently dropped (channel load + auth middleware ordering) (#1083) * fix: load notification channels on mount in AlertsPanel Channels only loaded when the Channels tab was visited, so opening Edit Alert Rule before ever switching to that tab showed the channel picker as empty even when channels existed. (cherry picked from commit caed913ee91990a853f5a048849c67ed3f7c329e) * fix: register login-alert route before auth middleware Global JWT auth middleware ran before this internal service-to-service route, rejecting it with 401 before its own IP+token check ever ran — silently dropped every SSH-login alert. Also surface non-OK responses instead of swallowing them. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * test: add coverage for alert-notification fixes Channel-load-on-mount, login-alert non-OK handling, and a source-order guard for the route/auth-middleware regression. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> * format AlertsPanel test with prettier --------- Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> Co-authored-by: ZacharyZcR <zacharyzcr1984@gmail.com> * stop deleting audit trails, and say when they are dropped (#1132) Two ways audit evidence still disappeared silently. Deleting an account removed its audit entries and session recordings outright. #1128 relaxed those foreign keys to ON DELETE SET NULL, but deleteUserAndRelatedData deletes the rows explicitly, so the schema change had no effect on the path that actually matters. Both repositories gain anonymizeByUserId, which nulls the reference and leaves the row; username is already denormalised on both tables, so entries stay attributable to whoever acted. Separately, the log pruned itself at a hard-coded 10000 rows with no signal. Entries well inside any retention window were discarded and nothing recorded it. Retention is now configurable by age via AUDIT_LOG_RETENTION_DAYS, the row cap via AUDIT_LOG_MAX_ENTRIES, and the two are reported differently: expiring an old entry is routine and logged at info, while hitting the cap means the ceiling is too low for how much this install audits and is logged at warn, naming the range discarded and how to stop it. * let the audit log leave the box (#1133) Retention became configurable in #1132, which only helps if entries can be moved somewhere before they expire. Until now the only way out was two GET endpoints built for the UI. Adds GET /audit-logs/export, taking the same filters as the list endpoint and streaming the whole matching set as CSV or NDJSON in batches, so an export is not bounded by the 200-row page cap and does not buffer the result set. Reading the entire trail is itself recorded as export_audit_logs. CSV fields starting with =, +, - or @ are prefixed with a quote. Audit rows carry attacker-influenced values like resource names, and spreadsheet software treats those as formulas on open. Adds optional live forwarding to a collector via AUDIT_LOG_FORWARD_URL, with an optional bearer token. Delivery goes through safeOutboundFetch so a misconfigured URL cannot be turned into an internal network probe, and it is fire-and-forget: the local write stays the source of truth and a dead SIEM must never delay or fail the operation being audited. Repeated failures are reported five times and then suppressed until delivery recovers, so an outage does not bury the logs it is supposed to appear in. * encrypt SSO secrets instead of base64-encoding them (#1135) The OIDC client secret and LDAP bind password were stored behind an encoded: prefix that is base64, not encryption. Anyone reading the database read the secrets. A second path wrote the same thing behind an encrypted: prefix, which was also base64 — and the reader even documented that it could not decrypt it. These belong to the installation rather than to a user: sso_providers has no userId, and the values must be readable during login, before anyone has authenticated, so the per-user DEK used elsewhere does not apply. They are now sealed with AES-256-GCM under the system encryption key, which already protects other installation-level material. Reading handles both legacy prefixes so an existing install is not locked out of SSO login, and a legacy value is upgraded the next time the provider is saved. The three scattered encode/decode sites are replaced by one module. * remove the unwired field encryption boundary (#1136) FieldEncryptionBoundary declared a full sensitive/plaintext policy for six tables and was referenced only by its own test. Nothing in production used it. Its policy is byte-for-byte the same as FieldCrypto.ENCRYPTED_FIELDS, which is the copy that actually runs, so nothing is lost by deleting it. Keeping a second list is the real risk: someone adds a field to this one, sees it classified as sensitive, and ships something that was never encrypted. The one apparent improvement it had — requiring an explicit recordId instead of DataCrypto's temp-${Date.now()} fallback — turns out to guard against nothing. decryptField derives its context from the recordId stored inside the ciphertext, not from the argument, so a temporary id at encryption time still decrypts. * load the database file when encryption is off (#1137) * Groundwork for Postgres and MySQL backends (#1134) * groundwork for postgres and mysql backends #1127 made the repository layer dialect-agnostic. This adds the pieces needed to actually target a second engine, as a foundation only — nothing is wired up and sqlite remains the sole runtime path. - DatabaseDialect covers sqlite, postgres and mysql, resolved from DATABASE_DIALECT and defaulting to sqlite so nothing changes for existing deployments or the desktop build - a column kit holding the per-dialect type choices in one file: booleans are integers on sqlite and native elsewhere, autoincrement differs three ways, and MySQL cannot index unbounded TEXT so key columns need varchar - settings and users declared for all three dialects as a proof slice, chosen because between them they use every construct the real schema does - pg and mysql2 added as dependencies The tests build real queries for all three engines without a server, asserting identifier quoting, placeholder style and boolean storage, so the property the repositories depend on is verified rather than assumed. * verify foreign keys and unique constraints port across dialects The first slice only covered plain columns. The real schema also has 92 foreign keys (80 cascade, 12 set null) and 14 unique columns, so the approach is only viable if those survive the port. Adds audit_logs and ssh_folders to the proof slice: one nullable reference with ON DELETE SET NULL, one required reference with ON DELETE CASCADE, a unique column, and an autoincrement surrogate key — which is spelled three different ways underneath (integer primary key autoincrement, serial, int auto_increment). All of it holds. Worth noting for whoever picks this up: getTableConfig is dialect-specific and silently fails on a table from another dialect, so the test uses each engine's own. * generate the postgres and mysql schemas instead of hand-writing them The proof slice showed the constructs port, but left the maintenance question open. Three hand-written copies of 52 tables is the wrong answer: with foreign keys the copies cross-reference each other, so a renamed table has to land in three places consistently or a key silently points at the wrong one. The mapping is mechanical, so a script does it. schema.ts stays the single source of truth and schema.pg.ts / schema.mysql.ts are derived, covering all 52 tables — the column kit and the two-table portable slice are gone, since the generator now holds those decisions. The transforms are the ones the kit enumerated: integer-backed booleans become native, autoincrement keys become serial or int auto_increment, real becomes double precision or double, and any column that is a primary key, is unique, or sits on either end of a foreign key becomes varchar because MySQL cannot index unbounded TEXT. > termix@2.6.0 lint > node scripts/generate-dialect-schema.cjs --check && eslint . /mnt/c/Users/29037/WebstormProjects/Termix/src/backend/database/routes/homepage-favicon-routes.ts 99:12 warning 'err' is defined but never used unused-imports/no-unused-vars /mnt/c/Users/29037/WebstormProjects/Termix/src/backend/database/routes/homepage-ping-routes.ts 123:12 warning 'err' is defined but never used unused-imports/no-unused-vars /mnt/c/Users/29037/WebstormProjects/Termix/src/backend/database/routes/homepage-rss-routes.ts 144:12 warning 'err' is defined but never used unused-imports/no-unused-vars /mnt/c/Users/29037/WebstormProjects/Termix/src/backend/database/routes/session-log-routes.ts 46:16 warning 'canAccessRecording' is defined but never used. Allowed unused vars must match /^_/u unused-imports/no-unused-vars /mnt/c/Users/29037/WebstormProjects/Termix/src/backend/hosts/vault-signer-core.ts 55:12 warning Unexpected any. Specify a different type @typescript-eslint/no-explicit-any 75:13 warning Unexpected any. Specify a different type @typescript-eslint/no-explicit-any /mnt/c/Users/29037/WebstormProjects/Termix/src/backend/tests/hosts/auth-manager.test.ts 18:73 warning Unexpected any. Specify a different type @typescript-eslint/no-explicit-any /mnt/c/Users/29037/WebstormProjects/Termix/src/backend/tests/utils/shared-host-secrets-manager.test.ts 7:6 warning 'SecretRow' is defined but never used. Allowed unused vars must match /^_/u unused-imports/no-unused-vars /mnt/c/Users/29037/WebstormProjects/Termix/src/backend/utils/auth-manager.ts 510:13 warning 'affectedUsers' is assigned a value but never used. Allowed unused vars must match /^_/u unused-imports/no-unused-vars /mnt/c/Users/29037/WebstormProjects/Termix/src/backend/utils/notification-sender.ts 48:12 warning 'firstErr' is defined but never used unused-imports/no-unused-vars /mnt/c/Users/29037/WebstormProjects/Termix/src/ui/api/ssh-file-operations-api.ts 35:10 warning 'buildFileManagerUrl' is defined but never used. Allowed unused vars must match /^_/u unused-imports/no-unused-vars /mnt/c/Users/29037/WebstormProjects/Termix/src/ui/components/folder-style.tsx 61:14 warning Fast refresh only works when a file only exports components. Use a new file to share constants or functions between components react-refresh/only-export-components 116:14 warning Fast refresh only works when a file only exports components. Use a new file to share constants or functions between components react-refresh/only-export-components 121:14 warning Fast refresh only works when a file only exports components. Use a new file to share constants or functions between components react-refresh/only-export-components 149:17 warning Fast refresh only works when a file only exports components. Use a new file to share constants or functions between components react-refresh/only-export-components /mnt/c/Users/29037/WebstormProjects/Termix/src/ui/components/proxmox/ProxmoxDiscoverDialog.tsx 109:19 warning Unexpected any. Specify a different type @typescript-eslint/no-explicit-any 190:19 warning Unexpected any. Specify a different type @typescript-eslint/no-explicit-any /mnt/c/Users/29037/WebstormProjects/Termix/src/ui/features/homepage/HomepageCanvas.tsx 345:15 warning Empty block statement no-empty 388:15 warning Empty block statement no-empty 415:15 warning Empty block statement no-empty /mnt/c/Users/29037/WebstormProjects/Termix/src/ui/features/homepage/dialogs/SingleHostEditForm.tsx 24:6 warning React Hook useEffect has a missing dependency: 'filter'. Either include it or remove the dependency array. If 'setHosts' needs the current value of 'filter', you can also switch to useReducer instead of useState and read 'filter' in the reducer react-hooks/exhaustive-deps /mnt/c/Users/29037/WebstormProjects/Termix/src/ui/features/homepage/widgets/AlertFeedWidget.tsx 93:6 warning React Hook useEffect has a missing dependency: 'fetchData'. Either include it or remove the dependency array react-hooks/exhaustive-deps /mnt/c/Users/29037/WebstormProjects/Termix/src/ui/features/homepage/widgets/CustomApiWidget.tsx 77:6 warning React Hook useEffect has a missing dependency: 'fetchData'. Either include it or remove the dependency array react-hooks/exhaustive-deps /mnt/c/Users/29037/WebstormProjects/Termix/src/ui/features/homepage/widgets/DockerActivityWidget.tsx 50:6 warning React Hook useEffect has a missing dependency: 'fetchData'. Either include it or remove the dependency array react-hooks/exhaustive-deps /mnt/c/Users/29037/WebstormProjects/Termix/src/ui/features/homepage/widgets/DockerWidget.tsx 16:10 warning Fast refresh only works when a file has exports. Move your component(s) to a separate file react-refresh/only-export-components /mnt/c/Users/29037/WebstormProjects/Termix/src/ui/features/homepage/widgets/FileManagerWidget.tsx 16:10 warning Fast refresh only works when a file has exports. Move your component(s) to a separate file react-refresh/only-export-components /mnt/c/Users/29037/WebstormProjects/Termix/src/ui/features/homepage/widgets/HostGridWidget.tsx 61:6 warning React Hook useCallback has a missing dependency: 'hostIds'. Either include it or remove the dependency array react-hooks/exhaustive-deps 61:7 warning React Hook useCallback has a complex expression in the dependency array. Extract it to a separate variable so it can be statically checked react-hooks/exhaustive-deps /mnt/c/Users/29037/WebstormProjects/Termix/src/ui/features/homepage/widgets/MetricsChartWidget.tsx 168:6 warning React Hook useEffect has a missing dependency: 'fetchData'. Either include it or remove the dependency array react-hooks/exhaustive-deps /mnt/c/Users/29037/WebstormProjects/Termix/src/ui/features/homepage/widgets/PingStatusWidget.tsx 79:6 warning React Hook useEffect has a missing dependency: 'fetchAll'. Either include it or remove the dependency array react-hooks/exhaustive-deps 79:7 warning React Hook useEffect has a complex expression in the dependency array. Extract it to a separate variable so it can be statically checked react-hooks/exhaustive-deps /mnt/c/Users/29037/WebstormProjects/Termix/src/ui/features/homepage/widgets/QuickConnectWidget.tsx 64:10 warning Fast refresh only works when a file has exports. Move your component(s) to a separate file react-refresh/only-export-components /mnt/c/Users/29037/WebstormProjects/Termix/src/ui/features/homepage/widgets/RecentActivityWidget.tsx 82:6 warning React Hook useEffect has a missing dependency: 'fetchData'. Either include it or remove the dependency array react-hooks/exhaustive-deps 82:17 warning React Hook useEffect has a complex expression in the dependency array. Extract it to a separate variable so it can be statically checked react-hooks/exhaustive-deps /mnt/c/Users/29037/WebstormProjects/Termix/src/ui/features/homepage/widgets/SshQuickConnectWidget.tsx 67:6 warning React Hook useCallback has a missing dependency: 'hostIds'. Either include it or remove the dependency array react-hooks/exhaustive-deps 67:7 warning React Hook useCallback has a complex expression in the dependency array. Extract it to a separate variable so it can be statically checked react-hooks/exhaustive-deps 99:17 warning 'online' is assigned a value but never used. Allowed unused vars must match /^_/u unused-imports/no-unused-vars /mnt/c/Users/29037/WebstormProjects/Termix/src/ui/features/homepage/widgets/SshTerminalWidget.tsx 17:10 warning Fast refresh only works when a file has exports. Move your component(s) to a separate file react-refresh/only-export-components /mnt/c/Users/29037/WebstormProjects/Termix/src/ui/features/homepage/widgets/SystemOverviewWidget.tsx 72:6 warning React Hook useEffect has a missing dependency: 'fetchData'. Either include it or remove the dependency array react-hooks/exhaustive-deps /mnt/c/Users/29037/WebstormProjects/Termix/src/ui/features/homepage/widgets/TunnelWidget.tsx 15:10 warning Fast refresh only works when a file has exports. Move your component(s) to a separate file react-refresh/only-export-components /mnt/c/Users/29037/WebstormProjects/Termix/src/ui/features/host-metrics/cards/CpuCard.tsx 14:10 warning 'computeChartData' is defined but never used. Allowed unused vars must match /^_/u unused-imports/no-unused-vars /mnt/c/Users/29037/WebstormProjects/Termix/src/ui/sidebar/FolderPathPicker.tsx 15:17 warning Fast refresh only works when a file only exports components. Use a new file to share constants or functions between components react-refresh/only-export-components 22:17 warning Fast refresh only works when a file only exports components. Use a new file to share constants or functions between components react-refresh/only-export-components /mnt/c/Users/29037/WebstormProjects/Termix/src/ui/sidebar/HostsPanel.tsx 601:52 warning Unexpected any. Specify a different type @typescript-eslint/no-explicit-any ✖ 44 problems (0 errors, 44 warnings) now fails if the generated files are out of date, so editing the schema without regenerating cannot reach main. * select durability behaviour per dialect, and document the backends The onWrite hook every repository receives exists to serialise the in-memory SQLite database back to its encrypted file. On a client-server engine a committed write is already durable and there is nothing to flush, so the factory now installs no hook at all rather than one that does nothing. Repositories call it as this.onWrite?.(), so none of the 43 of them change. Also adds docs/database-backends.md, mostly to be explicit about encryption, which is the part most likely to be misread. Field-level encryption is identical on all three engines and covers every credential. Whole-file encryption has no equivalent on Postgres or MySQL, so host names, snippet contents, audit entries and backups are only as protected as the storage underneath them — that is the operator's responsibility and the docs should not imply otherwise. * generate DDL with drizzle-kit, and give settings a synchronous path Two of the three remaining blockers. DDL: db/index.ts hand-writes 67 CREATE TABLE statements and 122 ADD COLUMN migrations, all in SQLite dialect. Rather than port them, drizzle-kit now generates migrations from the schema modules — 817 lines for Postgres, 869 for MySQL, with the type mapping already correct because the schemas it reads are themselves generated. > termix@2.6.0 schema:migrations > drizzle-kit generate --config=drizzle.config.pg.ts && drizzle-kit generate --config=drizzle.config.mysql.ts Reading config file '/mnt/c/Users/29037/WebstormProjects/Termix/drizzle.config.pg.ts' 52 tables alert_firings 11 columns 0 indexes 2 fks alert_rule_channels 3 columns 0 indexes 2 fks alert_rules 11 columns 0 indexes 2 fks api_keys 9 columns 0 indexes 1 fks audit_logs 13 columns 0 indexes 1 fks c2s_tunnel_presets 8 columns 0 indexes 1 fks command_history 5 columns 0 indexes 2 fks dashboard_service_links 8 columns 0 indexes 1 fks dismissed_alerts 4 columns 0 indexes 1 fks file_manager_pinned 6 columns 0 indexes 2 fks file_manager_recent 6 columns 0 indexes 2 fks file_manager_shortcuts 6 columns 0 indexes 2 fks homepage_items 9 columns 0 indexes 1 fks homepage_layouts 4 columns 0 indexes 1 fks host_access 11 columns 0 indexes 5 fks host_health_checks 7 columns 0 indexes 2 fks host_health_history 8 columns 0 indexes 2 fks host_metrics_history 8 columns 0 indexes 1 fks host_metrics_preferences 6 columns 0 indexes 2 fks ssh_data 94 columns 0 indexes 6 fks network_topology 5 columns 0 indexes 1 fks notification_channels 7 columns 0 indexes 1 fks opkssh_tokens 12 columns 0 indexes 2 fks recent_activity 6 columns 0 indexes 2 fks roles 8 columns 0 indexes 0 fks session_recordings 15 columns 0 indexes 3 fks session_share_participants 6 columns 0 indexes 2 fks session_shares 15 columns 0 indexes 3 fks sessions 11 columns 0 indexes 1 fks settings 2 columns 0 indexes 0 fks shared_host_secrets 15 columns 0 indexes 3 fks snippet_access 8 columns 0 indexes 4 fks snippet_folders 8 columns 0 indexes 1 fks snippets 11 columns 0 indexes 1 fks ssh_credential_usage 5 columns 0 indexes 3 fks ssh_credentials 21 columns 0 indexes 1 fks ssh_folders 9 columns 0 indexes 2 fks sso_providers 8 columns 0 indexes 0 fks sync_tombstones 5 columns 0 indexes 1 fks termix_identities 6 columns 0 indexes 1 fks termix_identity_ca 8 columns 0 indexes 2 fks termix_identity_keys 12 columns 0 indexes 3 fks tmux_session_tags 6 columns 0 indexes 2 fks transfer_recent 7 columns 0 indexes 3 fks trusted_devices 8 columns 0 indexes 1 fks user_open_tabs 9 columns 0 indexes 2 fks user_preferences 23 columns 0 indexes 1 fks user_roles 5 columns 0 indexes 3 fks users 20 columns 0 indexes 0 fks vault_profiles 18 columns 0 indexes 1 fks vault_tokens 8 columns 0 indexes 2 fks webauthn_credentials 12 columns 0 indexes 1 fks No schema changes, nothing to migrate 😴 Reading config file '/mnt/c/Users/29037/WebstormProjects/Termix/drizzle.config.mysql.ts' Reading schema files: /mnt/c/Users/29037/WebstormProjects/Termix/src/backend/database/db/schema.mysql.ts 52 tables alert_firings 11 columns 0 indexes 2 fks alert_rule_channels 3 columns 0 indexes 2 fks alert_rules 11 columns 0 indexes 2 fks api_keys 9 columns 0 indexes 1 fks audit_logs 13 columns 0 indexes 1 fks c2s_tunnel_presets 8 columns 0 indexes 1 fks command_history 5 columns 0 indexes 2 fks dashboard_service_links 8 columns 0 indexes 1 fks dismissed_alerts 4 columns 0 indexes 1 fks file_manager_pinned 6 columns 0 indexes 2 fks file_manager_recent 6 columns 0 indexes 2 fks file_manager_shortcuts 6 columns 0 indexes 2 fks homepage_items 9 columns 0 indexes 1 fks homepage_layouts 4 columns 0 indexes 1 fks host_access 11 columns 0 indexes 5 fks host_health_checks 7 columns 0 indexes 2 fks host_health_history 8 columns 0 indexes 2 fks host_metrics_history 8 columns 0 indexes 1 fks host_metrics_preferences 6 columns 0 indexes 2 fks ssh_data 94 columns 0 indexes 6 fks network_topology 5 columns 0 indexes 1 fks notification_channels 7 columns 0 indexes 1 fks opkssh_tokens 12 columns 0 indexes 2 fks recent_activity 6 columns 0 indexes 2 fks roles 8 columns 0 indexes 0 fks session_recordings 15 columns 0 indexes 3 fks session_share_participants 6 columns 0 indexes 2 fks session_shares 15 columns 0 indexes 3 fks sessions 11 columns 0 indexes 1 fks settings 2 columns 0 indexes 0 fks shared_host_secrets 15 columns 0 indexes 3 fks snippet_access 8 columns 0 indexes 4 fks snippet_folders 8 columns 0 indexes 1 fks snippets 11 columns 0 indexes 1 fks ssh_credential_usage 5 columns 0 indexes 3 fks ssh_credentials 21 columns 0 indexes 1 fks ssh_folders 9 columns 0 indexes 2 fks sso_providers 8 columns 0 indexes 0 fks sync_tombstones 5 columns 0 indexes 1 fks termix_identities 6 columns 0 indexes 1 fks termix_identity_ca 8 columns 0 indexes 2 fks termix_identity_keys 12 columns 0 indexes 3 fks tmux_session_tags 6 columns 0 indexes 2 fks transfer_recent 7 columns 0 indexes 3 fks trusted_devices 8 columns 0 indexes 1 fks user_open_tabs 9 columns 0 indexes 2 fks user_preferences 23 columns 0 indexes 1 fks user_roles 5 columns 0 indexes 3 fks users 20 columns 0 indexes 0 fks vault_profiles 18 columns 0 indexes 1 fks vault_tokens 8 columns 0 indexes 2 fks webauthn_credentials 12 columns 0 indexes 1 fks No schema changes, nothing to migrate 😴 regenerates both. Settings: 27 call sites read settings synchronously, during startup and inside request handlers. better-sqlite3 can do that; Postgres and MySQL cannot, and making all 27 async would push await through code that has no reason to be asynchronous. Settings are a handful of rarely-changing rows read constantly, so they are cached in full — primed at startup, kept in step by SettingsRepository on every set/delete/deleteLike. SQLite keeps reading the database directly and stays authoritative; only the other engines use the cache. Opening a connection is still not done. DatabaseContext.drizzle is typed as BetterSQLite3Database and 43 repositories depend on that inference; the three drizzle instance types are not interchangeable, so widening it is a design decision rather than a mechanical change. * exclude drizzle-kit output from prettier The generated migrations and snapshots are tool output; their formatting is drizzle-kit's to decide, and prettier cannot parse the .sql files at all. * absorb the RETURNING gap so mysql stays reachable MySQL has no RETURNING clause and drizzle's mysql-core does not expose the method, while 156 call sites here read the result of a write. That is the real blocker for MySQL, not the connection layer. Classifying those call sites showed the split is favourable: 92 of them only read .length, which every engine reports — as a returned array on sqlite and postgres, as affectedRows on MySQL. rowsAffected() reads both shapes, so those sites need no change in query shape. insertedId() does the same for the autoincrement key, which MySQL reports as insertId. What is left is the ~34 sites that genuinely consume the returned rows. Those cannot be emulated without reading first, which needs a transaction to stay correct under concurrency, so they will be handled individually rather than behind a helper that quietly adds a round trip. supportsReturning() is the seam for that. Identifying the mysql2 result by its own fields rather than by array shape matters: it hands back [ResultSetHeader, fields], which is an array, so shape alone cannot tell it apart from a returning() result. * name the portable database type, and open remote connections Two pieces of the connection layer. drizzle's three Database classes share no base class and their signatures are incompatible, so there is no honest type that covers all three: a union is not callable and a generic would have to be threaded through 43 repositories and every method on them. DatabaseContext.drizzle is now PortableDatabase, still the SQLite type underneath, but named and documented as the deliberate approximation it is. What makes it safe is that the equivalence is asserted in multi-dialect.test.ts rather than assumed, and the one place the surfaces truly differ — RETURNING — is handled explicitly in mutation-result.ts. connect.ts opens Postgres and MySQL from DATABASE_URL, with the schema module and driver imported lazily so neither is loaded on a SQLite deployment. The URL scheme is checked against the configured dialect first: a postgres:// URL with DATABASE_DIALECT=mysql otherwise surfaces as a driver error deep in a stack that never mentions the actual misconfiguration. * open postgres and mysql at startup * count writes without RETURNING * read affected rows without RETURNING on mysql * insert without RETURNING, and split the sync transactions * stop pretending the generated schemas are used at runtime * run the dialect checks in CI * mysql rejects a bare CURRENT_TIMESTAMP default on text * make the read-back mismatch loud, and stop the next bare returning() * run the repository tests on the real schema * skip the byte-level assertions off sqlite * move generated ids past the seeded ones * keep the export order the same on every engine * stop reading better-sqlite3 fields off every write * read counts as numbers, not whatever the driver returns * make the fixture usable against a live server * upsert on the engine that has no ON CONFLICT * run the repository suite on all three engines in CI * mysql cannot index a text column without a length * document how to actually run on postgres or mysql * keep the sqlite-era migrations off the other engines * concat strings in a way mysql agrees with * run every repository test on every engine * bound how long replicas can disagree about settings * generate the sqlite migrations alongside the others * Bump version from 2.6.0 to 2.6.1 * resolve the dialect in the repository factory instead of assuming sqlite (#1143) createCurrentRepositoryContext() hardcoded `dialect: "sqlite"` while the runtime already carried all three engines. That field is not decoration: returning.ts reads it to decide whether it can ask for RETURNING, and whether an upsert spells itself onConflictDoUpdate or onDuplicateKeyUpdate. Reporting sqlite while connected to MySQL means the first upsert calls onConflictDoUpdate on a mysql2 insert builder, which does not have it -- a TypeError, not a rejected query, as the note in returning.ts warned. So MySQL never worked outside the tests, and Postgres worked only because it also supports RETURNING and shares the conflict syntax. Three things were supposed to catch this and none could. The repository suite builds its own DatabaseContext in test-support.ts, verify-dialects.mjs builds its own, and the CI matrix runs both against real Postgres and MySQL containers -- all of them bypassing the one function the application calls. Green on three engines, broken on two. Resolve it from the environment, and test the factory itself rather than a hand-built context: the default, each configured dialect, the write hook it installs only for sqlite, and that an unsupported value throws rather than falling back. Reverting the fix fails two of them. Fixes Termix-SSH/Support#282 * fix remote sync stalling after the first pass and never propagating deletions (#1140) The incremental cursor never matched. updated_at/deleted_at are TEXT columns written by CURRENT_TIMESTAMP ("2026-07-29 10:11:21"), while the client sends an ISO 8601 since ("2026-07-29T10:06:55.172Z"). Both comparisons are lexical and ' ' sorts below 'T', so a newer row lost at position 10 and every ?since= query came back empty. Pass 1 syncs everything (since is null) and persists a cursor; every pass after it returns nothing with lastError: null and reports success. Normalize since into the stored shape on the way in, leaving an already-normalized value alone -- parsing that would treat it as local time and, west of UTC, push the cursor past unsynced rows. POST /sync/tombstones was unreachable. It was registered after POST /:entityType, and "tombstones" is a valid :entityType, so the wildcard answered it with 400 "Unknown entity type" and the handler never ran. The pass has no per-entity error handling, so that 400 also discarded the state of every entity type already synced in the same pass. Move it ahead of the wildcards. The tombstone guard consulted the incremental window. A row deleted on one side and untouched on the other -- the shape every ordinary deletion takes once the two sides converge -- is not in that window, so the tombstone was skipped, and skipped again on each later pass as it slid out of its own window. The guard cannot just be dropped: recording a tombstone for a row that was already gone hands the sender a fresh one to push back, and the two trade the same deletion forever. So only a delete that removed something records a tombstone, which makes the endpoint idempotent and lets the client push every tombstone unconditionally. Deletions missed while the cursor was broken stay missed -- their tombstones predate the persisted cursor. Ordinary edits do come through, since the row's updatedAt is still newer than it. Fixes Termix-SSH/Support#1050 Fixes Termix-SSH/Support#1051 * report why every JWKS fetch failed instead of swallowing the reason (#1142) An OIDC login that cannot reach the provider's keys ends in "Failed to fetch JWKS from any URL" and nothing else. Getting there discards everything worth knowing: a non-2xx response hit an empty else branch, a thrown request hit a bare `continue`, and discovery only logged when it threw -- a 404 or a document without jwks_uri passed in silence. An administrator cannot tell an issuer URL typo from a proxy, a private CA, or an outage at the provider, and neither can anyone reading the report. Collect each attempt with its reason and put them in the thrown error. It reaches the log through the existing "OIDC callback failed" handler; the browser still gets the same generic message it did before. Unwrapping the cause is the part that matters: undici reports every transport failure as "fetch failed" and hangs the real reason -- ENOTFOUND, ECONNREFUSED, a certificate that will not verify -- off error.cause. An attempt list built from the outer messages would be as useless as the single line it replaces. Also require jwks_uri to be a string before using it, so a malformed discovery document is reported as such rather than as a failed fetch of "[object Object]". Refs Termix-SSH/Support#1047 * restore the closing quote on the version string (#1147) "Bump version from 2.6.0 to 2.6.1" (2a66775) wrote "version": "2.6.1, dropping the closing quote, so package.json has not been valid JSON since. Anything that parses it fails: npm install, npm run build, and every CI run on this branch -- vitest cannot even load its config, because vite reads package.json before it gets to the test files. 2.6.1 cannot be built or released until this is fixed, which is why it goes in on its own rather than riding along with anything else. * Revert "fix remote sync stalling after the first pass and never propagating deletions (#1140)" (#1146) This reverts commitca7abf8426. Reverted for process, not for content. Both defects were reported by @kacperpietrzyk in Support#1050 and Support#1051, and he opened #1138 and #1139 fixing them 4.5 hours before #1140 was filed. Merging #1140 made two PRs from the person who found and diagnosed the bugs redundant. #1138 and #1139 stand on their own: the same root-cause analysis, complete regression tests, and a tombstone guard that only pays for its extra lookup on a pass that actually carries a deletion. There is no technical reason to prefer the reverted commit over them. The sync fixes land through those two PRs instead. * fix: make sync deletions reach the other side (#1139) * fix: apply sync tombstones to rows outside the incremental window Deletions never reached the other side. `syncEntity` decides whether to apply a tombstone by looking the row up in `localBySyncId` / `remoteBySyncId`, which are built from `pullSide(..., since)` -- the incremental window. A row deleted on one side and untouched on the other is by definition absent from that window, which is the shape every ordinary deletion takes once the two sides have converged, so the tombstone was silently skipped and never retried. The guard cannot simply be dropped. `POST /sync/tombstones` records a tombstone on the receiving side, so an unconditional push would give the other side a fresh tombstone to push back on the following pass, and the two would trade deletions forever. Instead ask the receiving side what it still holds, ignoring the window, and only when there is a deletion to apply -- so an ordinary pass costs nothing extra, and a pass carrying a deletion costs one additional list per affected entity type. Once the row is gone the push stops, so nothing ping-pongs. Note this only becomes observable together with the cursor fix in Termix-SSH/Support#1050: while that defect is present the tombstone endpoint returns nothing at all, so there is no tombstone to apply in the first place. Refs Termix-SSH/Support#1034 * fix: make the sync tombstone endpoint reachable `POST /sync/tombstones` was registered after `POST /:entityType`, and Express matches in registration order, so every deletion push was swallowed by the wildcard: "tombstones" is a perfectly good value for :entityType, fails isValidEntityType, and comes back as 400 "Unknown entity type". The handler below it has never run. Registering the literal path before the parameterised one restores it. The regression test reads the router stack rather than the source, so a future re-order fails the test rather than silently disabling deletions again. The GET pair is unaffected -- "/:entityType/tombstones" and "/:entityType" have different segment counts, so they cannot shadow each other. * feat: add host export dialog with host and field selection (#1108) * fix: compare sync cursors independently of timestamp layout (#1138) * fix: compare sync cursors independently of timestamp layout Incremental sync returned nothing after its first pass. `GET /sync/:entityType` filters with `gt(table.updatedAt, since)` on a TEXT column, and the tombstone endpoint does the same through `listSince`, but the two sides of that comparison are written in different layouts: the columns default to `CURRENT_TIMESTAMP` ("2026-07-29 10:11:21") while the desktop engine sends `new Date().toISOString()` ("2026-07-29T10:06:55.172Z"). Text comparison is decided at position 10, where ' ' (0x20) sorts below 'T' (0x54), so the predicate answers on layout rather than on time and is false for every CURRENT_TIMESTAMP row however new it is. The engine only sends a cursor from the second pass onward, so pass 1 synced everything and passes 2..n pulled zero rows and zero tombstones while reporting success -- edits and deletions silently stopped propagating in both directions. This was masked until now: before the reference fix in #1092 the loop threw before persisting state, so the cursor never advanced past null and every cycle was a full sync. Comparing "YYYY-MM-DD HH:MM:SS" on both sides is layout-independent. `replace` and `substr` are used rather than `datetime()` to keep the expression portable across engines, since the repository layer is deliberately drizzle-only. The comparison is `>=` because normalising truncates sub-second precision, and a strict `>` would permanently skip rows written in the cursor's own second; the re-sent boundary rows are a no-op, as the engine pushes only when one side is strictly newer. `updatedAt` is written in both layouts across the codebase (14 sites use toISOString, 11 use CURRENT_TIMESTAMP), so the tests cover rows of each kind. Closes Termix-SSH/Support#1050 * test: seed the cursor tests against the migrated schema #1134 moved schema creation into the repository test harness, so the hand-written CREATE TABLE blocks here collided with tables that already existed. Seeding into the real tables instead surfaced two constraints the local definitions had papered over: the harness enables foreign keys and both `sync_tombstones.user_id` and `ssh_credentials.user_id` reference `users`, so the owning row has to be seeded first; and `auth_type` is NOT NULL with no default, unlike the local copy. `exec` is awaited, since it only returns synchronously on SQLite. The assertions are unchanged. * Make Proxmox guest discovery and import reliable over a jump host (#1144) * fix: repair unterminated version string in package.json The version field on dev-2.6.1 reads "2.6.1, (no closing quote), which makes package.json invalid JSON and breaks every npm invocation on the branch. Close the string so the branch builds. * fix(proxmox): reliable guest discovery and import over jump hosts Importing Proxmox guests from a node reachable only through a jump host (with the guests behind the same jump) failed in a chain of small ways. - Discovery timed out intermittently: execCommand capped every pvesh call at 8s, but a single call over a jump measured ~8.3s. Raised to 25s for core calls and 12s for best-effort agent/interface lookups. - No IPs were resolved (so nothing imported): resolveIp fanned out 6 concurrent pvesh calls; on a small node they contend (3 concurrent already exceeded the timeout), so every IP came back empty. Lowered CONCURRENCY to 2. - RDP guests aborted the whole sync via NOT NULL on ssh_data.username; use "" instead of null (matches the normal create path). - Guests without a resolvable IP (e.g. QEMU with no guest agent) were skipped entirely; they now import with a 0.0.0.0 placeholder, and re-sync preserves any manually entered IP (guest.ip || existing.ip). - Manual import did not inherit the source host's jump chain or credential (guests ended up unreachable with authType "none"). The discovery result now carries the source jumpHosts, and resolveProxmoxImportAuth uses an available credential even under the default "password" authType (explicit secretless choices still win). - Long discoveries had no feedback and fought client/proxy timeouts; added an SSE endpoint GET /proxmox/discover/stream (heartbeat + n/N progress), keeping POST /discover as a fallback. Also always render the IP cell in the discovery table so IP-less rows stay aligned. Adds a unit test for resolveProxmoxImportAuth covering the credential inheritance behaviour. * test(proxmox): lock resolveProxmoxImportAuth matrix on both copies; fix agent secretless drift - extract the backend decision into src/backend/database/routes/proxmox-import-auth.ts (leaf module mirroring the UI copy) so it is unit-testable without pulling the whole backend module graph into the test env - add src/backend/tests/database/routes/proxmox-import-auth.test.ts asserting the shared matrix (lifted from #1141, thanks @ZacharyZcR) - consolidate the UI test into src/ui/tests/components/proxmox/proxmox-import-auth.test.ts and drop the duplicate src/ui/tests/proxmox/ copy - add 'agent' to the UI SECRETLESS_AUTH_TYPES: the one real auth type where the two copies still diverged (UI -> credential, backend -> passthrough) * fix(hosts): parse portKnockSequence JSON in host-resolver (#1149) host-resolver JSON-parses jumpHosts/tunnelConnections/statsConfig/ terminalConfig/socks5ProxyChain/quickActions but NOT portKnockSequence. Empty knock is stored as the string "[]" (UI save of empty array); the terminal code then checks portKnockSequence.length > 0 on the STRING, so "[]".length === 2 is truthy -> logs 'Loaded 2 port knock(s)' and attempts a bogus knock. Real knock sequences (JSON string) are likewise never parsed to the Array<{port,...}> that performPortKnocking expects, so a genuine knock would never fire. Parse portKnockSequence like the other JSON columns: '[]' -> [] (length 0, no knock), real seq -> array. Adds unit tests for both cases. Co-authored-by: XtraLarge <xtralarge@users.noreply.github.com> * Feature request map OIDC provider groups to RBAC roles (#1148) * Bump version from 2.6.0 to 2.6.1 in package-lock.json * Fix formatting issue in package-lock.json * Feature request map OIDC provider groups to RBAC roles Group membership from an OIDC provider currently drives only a single boolean: OIDC_ADMIN_GROUP toggles isAdmin and switches the user between the built-in `admin` and `user` roles. There is no way to map a provider group onto a custom role, so deployments that use host_access grants for environment-scoped access (e.g. a role that can reach staging hosts and another that can reach production) have to assign those roles by hand for every user. Add OIDC_ROLE_MAP, a comma- or newline-separated list of `group:role` pairs, reconciled against the user's roles on each OIDC login: OIDC_ROLE_MAP=devops-interns:devops-intern,devops-seniors:devops-senior Only roles named in the map are ever added or removed. Roles assigned by hand, and the admin/user pair maintained by the existing admin-group sync, are deliberately left untouched so the two mechanisms don't fight each other. Group names are matched case-insensitively with leading slashes stripped, so providers that emit full group paths (Keycloak's "Full group path" option) work without extra configuration. Reuses the existing extractOidcGroups claim handling, so custom claim paths via OIDC_GROUP_CLAIM are supported too, and invalidates the permission cache when roles change so new grants apply to the session that triggered the sync. Malformed map entries are skipped and a failed sync is logged but non-fatal — neither can block a valid login. Adds unit tests for the parser and resolver covering full group paths, multi-group membership, colons in group names and malformed input. --------- Co-authored-by: Luke Gustafson <88517757+LukeGus@users.noreply.github.com> * feat: support for overriding shared host ssh credentials (#1145) * Bump version from 2.6.0 to 2.6.1 in package-lock.json * Fix formatting issue in package-lock.json * feat: support for overriding ssh credentials --------- Co-authored-by: Luke Gustafson <88517757+LukeGus@users.noreply.github.com> * ci(deps): bump the github-actions group with 2 updates (#1150) * Bump version from 2.6.0 to 2.6.1 in package-lock.json * Fix formatting issue in package-lock.json * Update README to remove Tailscale and add Ginernet Removed Tailscale logo and link from the README. Added Ginernet logo and link. * Update README.md * ci(deps): bump the github-actions group with 2 updates Bumps the github-actions group with 2 updates: [actions/setup-node](https://github.com/actions/setup-node) and [useblacksmith/setup-docker-builder](https://github.com/useblacksmith/setup-docker-builder). Updates `actions/setup-node` from 6 to 7 - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](https://github.com/actions/setup-node/compare/v6...v7) Updates `useblacksmith/setup-docker-builder` from 1 to 2 - [Release notes](https://github.com/useblacksmith/setup-docker-builder/releases) - [Commits](https://github.com/useblacksmith/setup-docker-builder/compare/v1...v2) --- updated-dependencies: - dependency-name: actions/setup-node dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: useblacksmith/setup-docker-builder dependency-version: '2' dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com> --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: Luke Gustafson <88517757+LukeGus@users.noreply.github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * chore(deps): bump the prod-minor-updates group with 3 updates (#1154) * Bump version from 2.6.0 to 2.6.1 in package-lock.json * Fix formatting issue in package-lock.json * Update README to remove Tailscale and add Ginernet Removed Tailscale logo and link from the README. Added Ginernet logo and link. * Update README.md * chore(deps): bump the prod-minor-updates group with 3 updates Bumps the prod-minor-updates group with 3 updates: [axios](https://github.com/axios/axios), [motion](https://github.com/motiondivision/motion) and [undici](https://github.com/nodejs/undici). Updates `axios` from 1.18.1 to 1.19.0 - [Release notes](https://github.com/axios/axios/releases) - [Changelog](https://github.com/axios/axios/blob/v1.x/CHANGELOG.md) - [Commits](https://github.com/axios/axios/compare/v1.18.1...v1.19.0) Updates `motion` from 12.42.2 to 12.43.0 - [Changelog](https://github.com/motiondivision/motion/blob/main/CHANGELOG.md) - [Commits](https://github.com/motiondivision/motion/compare/v12.42.2...v12.43.0) Updates `undici` from 8.7.0 to 8.9.0 - [Release notes](https://github.com/nodejs/undici/releases) - [Commits](https://github.com/nodejs/undici/compare/v8.7.0...v8.9.0) --- updated-dependencies: - dependency-name: axios dependency-version: 1.19.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: prod-minor-updates - dependency-name: motion dependency-version: 12.43.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: prod-minor-updates - dependency-name: undici dependency-version: 8.9.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: prod-minor-updates ... Signed-off-by: dependabot[bot] <support@github.com> --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: Luke Gustafson <88517757+LukeGus@users.noreply.github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> * fix: data guard test failure * chore(deps): bump 23 dependencies and fix dialect-unsafe queries Applies the non-major updates from the open dependabot PRs directly, since dependabot rebases against main and could not resolve its lockfiles against this branch. Holds back typescript 7 and jsdom 30; those majors need their own pass. Reformats with prettier 3.9.6, which collapses short union types onto one line. Formatting only: the compiled backend output is byte for byte identical. Also fixes two lint errors in the shared host auth override repository, where onConflictDoUpdate and .returning() are SQLite-only and broke the Postgres and MySQL builds, and drops unused imports left over from the shared host auth override merge. * chore: reversal of legal work * feat: improve pin side rail button position and added env var for telemetrics * Add Ctrl+F terminal search (#1156) * Bump version from 2.6.0 to 2.6.1 in package-lock.json * Fix formatting issue in package-lock.json * Update README to remove Tailscale and add Ginernet Removed Tailscale logo and link from the README. Added Ginernet logo and link. * Update README.md * Add Ctrl+F terminal search --------- Co-authored-by: Luke Gustafson <88517757+LukeGus@users.noreply.github.com> Co-authored-by: LukeGus <bugattiguy527@gmail.com> * fix: host export dialog using incorrect widths * fix: made logger display expanded errors * feat: added support for multi disk usage in file manager and host metrics * chore: harden nginx headers and improve static asset caching * chore: format * chore: update release notes * fix: default font size to md instead of lg * feat: support Tailscale SSH check mode * chore: sync Crowdin translations for 2.6.1 --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: ZacharyZcR <zacharyzcr1984@gmail.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Brennan Neoh <497569+brennanneoh@users.noreply.github.com> Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com> Co-authored-by: kacperpietrzyk <105545577+kacperpietrzyk@users.noreply.github.com> Co-authored-by: Max <50905012+maxiwolleb@users.noreply.github.com> Co-authored-by: XtraLarge <eMail@WilliWerres.de> Co-authored-by: XtraLarge <xtralarge@users.noreply.github.com> Co-authored-by: Devin Dissanayaka <dsdissanayaka2002@gmail.com> Co-authored-by: Peter Cinibulk <petercinibulk@gmail.com> Co-authored-by: Med Ali Ezzeddine <47082236+xDaly@users.noreply.github.com>
This commit is contained in:
co-authored by
LukeGus
ZacharyZcR
dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Brennan Neoh
Claude Sonnet 5
kacperpietrzyk
Max
XtraLarge
XtraLarge
Devin Dissanayaka
Peter Cinibulk
Med Ali Ezzeddine
parent
188380e8e7
commit
a64c956c5b
@@ -37,6 +37,14 @@ updates:
|
|||||||
major-updates:
|
major-updates:
|
||||||
update-types:
|
update-types:
|
||||||
- "major"
|
- "major"
|
||||||
|
ignore:
|
||||||
|
# typescript-eslint declares `typescript: >=4.8.4 <6.1.0`, and TypeScript 7
|
||||||
|
# removed `ts.Extension`, which @typescript-eslint/typescript-estree reads
|
||||||
|
# at import time. Bumping to 7 makes `eslint .` fail to load its own config,
|
||||||
|
# so `npm run lint` cannot run at all. Drop this once typescript-eslint
|
||||||
|
# supports TypeScript 7.
|
||||||
|
- dependency-name: "typescript"
|
||||||
|
update-types: ["version-update:semver-major"]
|
||||||
|
|
||||||
# Docker base images (docker/Dockerfile + docker-compose / compose-dev)
|
# Docker base images (docker/Dockerfile + docker-compose / compose-dev)
|
||||||
- package-ecosystem: "docker"
|
- package-ecosystem: "docker"
|
||||||
|
|||||||
@@ -157,7 +157,7 @@ jobs:
|
|||||||
|
|
||||||
docker:
|
docker:
|
||||||
needs: [prep, verify, create-release]
|
needs: [prep, verify, create-release]
|
||||||
if: ${{ always() && needs.prep.outputs.dev_branch != '' && (needs.create-release.result == 'success' || needs.create-release.result == 'skipped') }}
|
if: ${{ always() && needs.prep.outputs.dev_branch != '' && needs.verify.result == 'success' && (needs.create-release.result == 'success' || needs.create-release.result == 'skipped') }}
|
||||||
uses: ./.github/workflows/docker.yml
|
uses: ./.github/workflows/docker.yml
|
||||||
with:
|
with:
|
||||||
version: ${{ needs.prep.outputs.beta_version }}
|
version: ${{ needs.prep.outputs.beta_version }}
|
||||||
|
|||||||
@@ -34,7 +34,7 @@ jobs:
|
|||||||
token: ${{ secrets.GHCR_TOKEN }}
|
token: ${{ secrets.GHCR_TOKEN }}
|
||||||
|
|
||||||
- name: Setup Node.js
|
- name: Setup Node.js
|
||||||
uses: actions/setup-node@v6
|
uses: actions/setup-node@v7
|
||||||
with:
|
with:
|
||||||
node-version-file: ".nvmrc"
|
node-version-file: ".nvmrc"
|
||||||
|
|
||||||
|
|||||||
@@ -60,7 +60,7 @@ jobs:
|
|||||||
platforms: linux/amd64,linux/arm64
|
platforms: linux/amd64,linux/arm64
|
||||||
|
|
||||||
- name: Setup Docker Buildx
|
- name: Setup Docker Buildx
|
||||||
uses: useblacksmith/setup-docker-builder@v1
|
uses: useblacksmith/setup-docker-builder@v2
|
||||||
|
|
||||||
- name: Determine tags
|
- name: Determine tags
|
||||||
id: tags
|
id: tags
|
||||||
|
|||||||
@@ -559,7 +559,7 @@ jobs:
|
|||||||
CHECKSUM=$(shasum -a 256 "$DMG_PATH" | awk '{print $1}')
|
CHECKSUM=$(shasum -a 256 "$DMG_PATH" | awk '{print $1}')
|
||||||
|
|
||||||
mkdir -p homebrew-generated
|
mkdir -p homebrew-generated
|
||||||
cp packaging/Casks/termix.rb homebrew-generated/termix.rb
|
cp Casks/termix.rb homebrew-generated/termix.rb
|
||||||
|
|
||||||
sed -i '' "s/VERSION_PLACEHOLDER/$VERSION/g" homebrew-generated/termix.rb
|
sed -i '' "s/VERSION_PLACEHOLDER/$VERSION/g" homebrew-generated/termix.rb
|
||||||
sed -i '' "s/CHECKSUM_PLACEHOLDER/$CHECKSUM/g" homebrew-generated/termix.rb
|
sed -i '' "s/CHECKSUM_PLACEHOLDER/$CHECKSUM/g" homebrew-generated/termix.rb
|
||||||
@@ -894,7 +894,7 @@ jobs:
|
|||||||
|
|
||||||
mkdir -p homebrew-submission/Casks/t
|
mkdir -p homebrew-submission/Casks/t
|
||||||
|
|
||||||
cp packaging/Casks/termix.rb homebrew-submission/Casks/t/termix.rb
|
cp Casks/termix.rb homebrew-submission/Casks/t/termix.rb
|
||||||
|
|
||||||
sed -i '' "s/VERSION_PLACEHOLDER/$VERSION/g" homebrew-submission/Casks/t/termix.rb
|
sed -i '' "s/VERSION_PLACEHOLDER/$VERSION/g" homebrew-submission/Casks/t/termix.rb
|
||||||
sed -i '' "s/CHECKSUM_PLACEHOLDER/$CHECKSUM/g" homebrew-submission/Casks/t/termix.rb
|
sed -i '' "s/CHECKSUM_PLACEHOLDER/$CHECKSUM/g" homebrew-submission/Casks/t/termix.rb
|
||||||
|
|||||||
@@ -24,8 +24,10 @@ jobs:
|
|||||||
- name: Install dependencies
|
- name: Install dependencies
|
||||||
run: npm ci
|
run: npm ci
|
||||||
|
|
||||||
- name: Run ESLint
|
- name: Lint
|
||||||
run: npx eslint .
|
# npm run lint, not npx eslint — the script also checks that the
|
||||||
|
# generated dialect schemas match schema.ts, which eslint cannot see.
|
||||||
|
run: npm run lint
|
||||||
|
|
||||||
- name: Run Prettier check
|
- name: Run Prettier check
|
||||||
run: npx prettier --check .
|
run: npx prettier --check .
|
||||||
@@ -35,3 +37,76 @@ jobs:
|
|||||||
|
|
||||||
- name: Build
|
- name: Build
|
||||||
run: npm run build
|
run: npm run build
|
||||||
|
|
||||||
|
database-dialects:
|
||||||
|
name: Postgres and MySQL
|
||||||
|
runs-on: blacksmith-2vcpu-ubuntu-2404
|
||||||
|
|
||||||
|
# The test suite only ever sees SQLite. Everything that differs per engine —
|
||||||
|
# the RETURNING replacements, the read-then-write transactions, the
|
||||||
|
# migrations themselves — is only covered here, against real servers.
|
||||||
|
services:
|
||||||
|
postgres:
|
||||||
|
image: postgres:16
|
||||||
|
env:
|
||||||
|
POSTGRES_USER: termix
|
||||||
|
POSTGRES_PASSWORD: termix
|
||||||
|
POSTGRES_DB: termix_test
|
||||||
|
ports:
|
||||||
|
- 5432:5432
|
||||||
|
options: >-
|
||||||
|
--health-cmd pg_isready
|
||||||
|
--health-interval 10s
|
||||||
|
--health-timeout 5s
|
||||||
|
--health-retries 5
|
||||||
|
|
||||||
|
mysql:
|
||||||
|
image: mysql:8
|
||||||
|
env:
|
||||||
|
MYSQL_ROOT_PASSWORD: termix
|
||||||
|
MYSQL_DATABASE: termix_test
|
||||||
|
MYSQL_USER: termix
|
||||||
|
MYSQL_PASSWORD: termix
|
||||||
|
ports:
|
||||||
|
- 3306:3306
|
||||||
|
options: >-
|
||||||
|
--health-cmd "mysqladmin ping -h 127.0.0.1 -ptermix"
|
||||||
|
--health-interval 10s
|
||||||
|
--health-timeout 5s
|
||||||
|
--health-retries 10
|
||||||
|
|
||||||
|
steps:
|
||||||
|
- name: Checkout code
|
||||||
|
uses: actions/checkout@v7
|
||||||
|
|
||||||
|
- name: Setup Node.js
|
||||||
|
uses: actions/setup-node@v7
|
||||||
|
with:
|
||||||
|
node-version-file: ".nvmrc"
|
||||||
|
cache: "npm"
|
||||||
|
|
||||||
|
- name: Install dependencies
|
||||||
|
run: npm ci
|
||||||
|
|
||||||
|
# Each run applies the migrations to an empty database first, so a
|
||||||
|
# migration that does not apply cleanly fails the build.
|
||||||
|
- name: Verify Postgres
|
||||||
|
run: npm run verify:dialect -- postgres://termix:termix@127.0.0.1:5432/termix_test
|
||||||
|
|
||||||
|
- name: Verify MySQL
|
||||||
|
run: npm run verify:dialect -- mysql://termix:termix@127.0.0.1:3306/termix_test
|
||||||
|
|
||||||
|
# The same repository suite the SQLite run executes, pointed at each
|
||||||
|
# engine. This is where a dialect difference in a query shows up as a
|
||||||
|
# failing assertion rather than as a bug report.
|
||||||
|
- name: Repository tests on Postgres
|
||||||
|
env:
|
||||||
|
TEST_DIALECT: postgres
|
||||||
|
TEST_DATABASE_URL: postgres://termix:termix@127.0.0.1:5432/termix_test
|
||||||
|
run: npx vitest run src/backend/tests/database/repositories --no-file-parallelism
|
||||||
|
|
||||||
|
- name: Repository tests on MySQL
|
||||||
|
env:
|
||||||
|
TEST_DIALECT: mysql
|
||||||
|
TEST_DATABASE_URL: mysql://termix:termix@127.0.0.1:3306/termix_test
|
||||||
|
run: npx vitest run src/backend/tests/database/repositories --no-file-parallelism
|
||||||
|
|||||||
@@ -395,10 +395,10 @@ jobs:
|
|||||||
git fetch origin main
|
git fetch origin main
|
||||||
git checkout -B main origin/main
|
git checkout -B main origin/main
|
||||||
|
|
||||||
sed -i "s|version \".*\"|version \"$VERSION\"|g" packaging/Casks/termix.rb
|
sed -i "s|version \".*\"|version \"$VERSION\"|g" Casks/termix.rb
|
||||||
sed -i "s|sha256 \".*\"|sha256 \"$DMG_SHA256\"|g" packaging/Casks/termix.rb
|
sed -i "s|sha256 \".*\"|sha256 \"$DMG_SHA256\"|g" Casks/termix.rb
|
||||||
|
|
||||||
git add packaging/Casks/termix.rb
|
git add Casks/termix.rb
|
||||||
if git diff --cached --quiet; then
|
if git diff --cached --quiet; then
|
||||||
echo "Cask already up to date."
|
echo "Cask already up to date."
|
||||||
exit 0
|
exit 0
|
||||||
|
|||||||
@@ -17,3 +17,6 @@ db
|
|||||||
*.min.js
|
*.min.js
|
||||||
*.min.css
|
*.min.css
|
||||||
openapi.json
|
openapi.json
|
||||||
|
|
||||||
|
# Generated by drizzle-kit; formatting is the tool's own
|
||||||
|
drizzle/
|
||||||
|
|||||||
@@ -317,7 +317,7 @@ You can also run the Termix server on a cloud VPS instead of inside your own net
|
|||||||
|
|
||||||
Termix sends a small anonymous usage ping once every 24 hours to help understand how many instances are running and which features are actually used. This only includes a randomly generated instance ID, a count of users and hosts, the app version, and whether certain features (terminal, file manager, tunnels, docker, etc.) were used in the last 24 hours. It never includes usernames, hostnames, IP addresses, credentials, or any other identifying or connection data.
|
Termix sends a small anonymous usage ping once every 24 hours to help understand how many instances are running and which features are actually used. This only includes a randomly generated instance ID, a count of users and hosts, the app version, and whether certain features (terminal, file manager, tunnels, docker, etc.) were used in the last 24 hours. It never includes usernames, hostnames, IP addresses, credentials, or any other identifying or connection data.
|
||||||
|
|
||||||
This is opt-out and enabled by default. You can disable it at any time in Admin Settings under **General**.
|
This is opt-out and enabled by default. You can disable it at any time in Admin Settings under General, or set `ENABLE_TELEMETRY=false` to turn it off before you ever spin-up Termix.
|
||||||
|
|
||||||
<br />
|
<br />
|
||||||
|
|
||||||
|
|||||||
+51
-54
@@ -12,62 +12,59 @@ https://youtu.be/g0QjNdV3YYY
|
|||||||
|
|
||||||
<!-- UPDATE_LOG -->
|
<!-- UPDATE_LOG -->
|
||||||
|
|
||||||
- Added simple telemetrics to PostHog (user count, total hosts across users, and version metrics).
|
- Added support for multi disk usage in file manager/host metrics
|
||||||
- Reworked Electron desktop app to run standalone-first with a now optional sync to a remote Termix server.
|
- Added better Ctrl + F terminal search
|
||||||
- Added support for starting connections locally or from the remote server on desktop app.
|
- Added right click menu on app rail to pin sidebar faster
|
||||||
- Added support for custom key shortcuts.
|
- Support for overriding shared SSH credential
|
||||||
- Added support for more MFA types (SSH-only).
|
- Added mapping for OIDC provider groups to RBAC roles
|
||||||
- Added multiplayer/shared sessions for terminals and remote desktop (share via link or user).
|
- Added host export dialog for more customizable host exporting
|
||||||
- Added support for logging into SSH hosts that require multi-factor authentication (like Duo or JumpCloud push/TOTP prompts).
|
- Initial groundwork for supporting more database types (postgres and mysql)
|
||||||
- Added the option to convert a Quick Connect session into a saved host after connecting.
|
- Added audit log export (CSV/NDJSON) and optional live forwarding to a SIEM
|
||||||
- Added an export option for sharing host entries without credentials, so a host list can be shared without leaking passwords or keys.
|
- Added configurable audit log retention by age and row count
|
||||||
- Unified the folder picker across hosts, credentials, and snippets so they all use the same searchable, create-in-place selector.
|
- Audit entries for file manager, RDP/VNC/Telnet, Docker and tunnel sessions
|
||||||
- Allowed pasting into the key recording field from the clipboard.
|
- Encrypted SSO secrets instead of BASE64 encoding them
|
||||||
- Allowed sharing hosts that use authentication type "none".
|
- Added support for Tailscale SSH check mode with in-terminal browser authentication
|
||||||
- Allowed setting authentication type "none" on RDP hosts.
|
|
||||||
- Added the option to show two or more sidebar panels open at the same time.
|
|
||||||
- Added global custom themes that can be applied across all hosts instead of per host.
|
|
||||||
- Added a button to quickly create a Credentials entry from a host's existing authentication details.
|
|
||||||
- Added persistent split screen, so your layout and assigned tabs are restored after closing and reopening the app.
|
|
||||||
- Added tag matching to host search, so searching now matches tags as well as hostnames.
|
|
||||||
- Brought back the ability to collapse snippets.
|
|
||||||
- Added the ability to assign login credentials to an entire folder of hosts instead of one at a time.
|
|
||||||
- Added the ability to share terminal, VNC, and RDP sessions with other users, including read-only and read-write modes.
|
|
||||||
- Added the ability to share entire folders of hosts with other users instead of sharing hosts one by one.
|
|
||||||
- Added the ability to make folders of hosts available to specific users instead of everyone recreating them.
|
|
||||||
- Reworked SSH credentials to support both a password and an SSH key on the same credential, with an option to auto fill the password when prompted.
|
|
||||||
- Added a custom group claim option for OIDC login, useful for identity providers like Zitadel that don't use a plain "groups" claim.
|
|
||||||
<!-- /UPDATE_LOG -->
|
<!-- /UPDATE_LOG -->
|
||||||
|
|
||||||
<!-- BUG_FIXES -->
|
<!-- BUG_FIXES -->
|
||||||
|
|
||||||
- Fixed the Add Channel dialog failing with "config is required" when adding Webhook or ntfy alert channels.
|
- Hardened nginx headers/asset caching
|
||||||
- Fixed font size and UI scaling being too small even at the largest setting on high resolution displays.
|
- Deleting an account no longer deletes its audit entries and session recordings
|
||||||
- Fixed the Docker integration not working on hosts using authentication type "none".
|
- Made logger display expanded error messages
|
||||||
- Fixed the latest Russian translation updates from Crowdin not being included in the app.
|
- Removed phantom port knocking
|
||||||
- Fixed missing Nerd Font symbol support in the Android app.
|
- Fixed Proxmox guest discovery failures over jump host
|
||||||
- Fixed credential changes on RDP hosts not saving properly.
|
- Compare sync cursors independently of timestamp layout
|
||||||
- Fixed credential folders not showing up in the folder dropdown when editing a credential.
|
- Fixed sync deleting not reaching other side
|
||||||
- Fixed RDP hosts not using their stored credential and falling back to a direct connection.
|
- Remote sync stalling after first pass and never propagating deletions
|
||||||
- Fixed Cmd + scroll on Mac resizing the terminal instead of scrolling.
|
- DB_FILE_ENCRYPTION variable loading DB file as empty
|
||||||
- Fixed text repeating itself in the terminal when typing with a wireless keyboard on Android.
|
- Removed unneeded field encryption boundaries
|
||||||
- Fixed RDP connections failing when going through a jump host.
|
- SSH login alerts being dropped silently
|
||||||
- Fixed SSH connections failing when going through a jump host in some setups.
|
- Honor lookupOptions.all in custom DNS lookup hook
|
||||||
- Fixed OIDC login failing with a database error when the identity provider didn't return a client ID.
|
- Jump host SOCKS proxy settings being ignored
|
||||||
- Fixed SSH client-to-server tunnels failing with an authentication error.
|
- Jump host tunnels not reachable by guacd
|
||||||
- Fixed Host Metrics disk usage only showing the root filesystem and ignoring other mounted disks.
|
- Per-host RDP/VNC recording flags being ignored
|
||||||
- Fixed Android navigation buttons covering the terminal's top bar keys.
|
- RDP sessions not using the configured resolution
|
||||||
- Fixed Proxmox discovery importing DHCP LXC containers with an IP of 0.0.0.0 instead of their real address.
|
- OIDC login failing with unverifiable ID tokens or JWKs without alg
|
||||||
- Fixed VNC connections to macOS Screen Sharing hanging after the handshake instead of connecting.
|
- Refuse to start with an empty database when data exists elsewhere
|
||||||
- Fixed File Manager delete still failing on Windows hosts running PowerShell 5.1.
|
- Database not persisting during container shutdown
|
||||||
- Fixed the terminal dropping characters while typing on iOS.
|
- Host command history setting not saving
|
||||||
- Fixed SSH lines like "[username@host]" being wrongly highlighted as a log level and breaking output formatting.
|
- Desktop preference sync and remote sync account identity
|
||||||
- Fixed RDP touch mode on Android not registering taps as clicks.
|
- Desktop guacd calls not routed to the connected remote server
|
||||||
- Fixed VNC connections still failing due to a guacd protocol version mismatch.
|
- File manager navigation getting stuck after permission errors
|
||||||
- Guacamole tab showing "connecting" instead of rendering the desktop.
|
- Read-only shared hosts could be dragged into folders
|
||||||
- Fixed tmux not using Tailscale when starting connections.
|
- Terminal highlighting breaking inside split control strings
|
||||||
- Fixed an invalid websocket frame from causing code 10006 crash triggering restart loop.
|
- Windows terminal Tab key and Android hardware keyboard keys
|
||||||
- Remove chacha20-poly1305 without native ssh2 binding.
|
- tmux monitor failing on Tailscale-authenticated hosts
|
||||||
- Corrected SSRF blocklist from false-positive on all IPv4.
|
- Database export not staying same-origin on localhost
|
||||||
- Fixed terminal background image incorrectly displaying.
|
- Snippet execution results not reported correctly
|
||||||
|
- Shared hosts appearing twice
|
||||||
|
- Wake-on-LAN broadcast address being dropped
|
||||||
|
- Sharing an empty folder was rejected
|
||||||
|
- Remote sync losing references between linked records
|
||||||
|
- Desktop app failing to find its backend on some architectures
|
||||||
|
- Centralized outbound address validation for homepage proxy requests
|
||||||
|
- Default font size to medium instead of large
|
||||||
|
- Tailscale hosts hanging on connect when the tailnet ACL requires a periodic check
|
||||||
|
|
||||||
<!-- /BUG_FIXES -->
|
<!-- /BUG_FIXES -->
|
||||||
|
|||||||
+1
-1
@@ -4,7 +4,7 @@
|
|||||||
"enabled": true,
|
"enabled": true,
|
||||||
"clientKind": "git",
|
"clientKind": "git",
|
||||||
"useIgnoreFile": true,
|
"useIgnoreFile": true,
|
||||||
"defaultBranch": "dev-2.5.0"
|
"defaultBranch": "dev-2.6.1"
|
||||||
},
|
},
|
||||||
"files": {
|
"files": {
|
||||||
"ignoreUnknown": true,
|
"ignoreUnknown": true,
|
||||||
|
|||||||
@@ -76,6 +76,9 @@ COPY --chown=node:node --from=frontend-builder /app/dist /app/html
|
|||||||
COPY --chown=node:node --from=production-deps /app/node_modules /app/node_modules
|
COPY --chown=node:node --from=production-deps /app/node_modules /app/node_modules
|
||||||
COPY --chown=node:node --from=backend-builder /app/dist/backend ./dist/backend
|
COPY --chown=node:node --from=backend-builder /app/dist/backend ./dist/backend
|
||||||
COPY --chown=node:node package.json ./
|
COPY --chown=node:node package.json ./
|
||||||
|
# Schema for Postgres and MySQL. Unused by the default SQLite deployment, which
|
||||||
|
# builds its tables at startup instead.
|
||||||
|
COPY --chown=node:node drizzle ./drizzle
|
||||||
|
|
||||||
VOLUME ["/app/data"]
|
VOLUME ["/app/data"]
|
||||||
|
|
||||||
|
|||||||
@@ -13,6 +13,7 @@ services:
|
|||||||
PORT: "8080"
|
PORT: "8080"
|
||||||
NODE_ENV: development
|
NODE_ENV: development
|
||||||
GUACD_HOST: "guacd-dev"
|
GUACD_HOST: "guacd-dev"
|
||||||
|
GUACD_TUNNEL_HOST: "termix-dev"
|
||||||
GUACD_RECORDING_PATH: "/termix-data/session_recordings/guacamole"
|
GUACD_RECORDING_PATH: "/termix-data/session_recordings/guacamole"
|
||||||
depends_on:
|
depends_on:
|
||||||
- guacd-dev
|
- guacd-dev
|
||||||
|
|||||||
@@ -10,6 +10,7 @@ services:
|
|||||||
environment:
|
environment:
|
||||||
PORT: "8080"
|
PORT: "8080"
|
||||||
GUACD_HOST: "guacd"
|
GUACD_HOST: "guacd"
|
||||||
|
GUACD_TUNNEL_HOST: "termix"
|
||||||
GUACD_RECORDING_PATH: "/termix-data/session_recordings/guacamole"
|
GUACD_RECORDING_PATH: "/termix-data/session_recordings/guacamole"
|
||||||
depends_on:
|
depends_on:
|
||||||
- guacd
|
- guacd
|
||||||
|
|||||||
@@ -163,8 +163,4 @@ else
|
|||||||
echo "Warning: package.json not found"
|
echo "Warning: package.json not found"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
node dist/backend/backend/starter.js
|
exec node dist/backend/backend/starter.js
|
||||||
|
|
||||||
echo "All services started"
|
|
||||||
|
|
||||||
tail -f /dev/null
|
|
||||||
|
|||||||
+55
-10
@@ -11,6 +11,8 @@ http {
|
|||||||
include /etc/nginx/mime.types;
|
include /etc/nginx/mime.types;
|
||||||
default_type application/octet-stream;
|
default_type application/octet-stream;
|
||||||
|
|
||||||
|
server_tokens off;
|
||||||
|
|
||||||
access_log /tmp/nginx/access.log;
|
access_log /tmp/nginx/access.log;
|
||||||
|
|
||||||
client_body_temp_path /tmp/nginx/client_body;
|
client_body_temp_path /tmp/nginx/client_body;
|
||||||
@@ -69,7 +71,6 @@ http {
|
|||||||
|
|
||||||
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
|
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
|
||||||
add_header X-Content-Type-Options nosniff always;
|
add_header X-Content-Type-Options nosniff always;
|
||||||
add_header X-XSS-Protection "1; mode=block" always;
|
|
||||||
|
|
||||||
location ^~ /.well-known/acme-challenge/ {
|
location ^~ /.well-known/acme-challenge/ {
|
||||||
root /app/data/acme-webroot;
|
root /app/data/acme-webroot;
|
||||||
@@ -80,6 +81,8 @@ http {
|
|||||||
location = /sw.js {
|
location = /sw.js {
|
||||||
root /app/html;
|
root /app/html;
|
||||||
expires off;
|
expires off;
|
||||||
|
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
|
||||||
|
add_header X-Content-Type-Options nosniff always;
|
||||||
add_header Cache-Control "no-store, no-cache, must-revalidate, proxy-revalidate, max-age=0" always;
|
add_header Cache-Control "no-store, no-cache, must-revalidate, proxy-revalidate, max-age=0" always;
|
||||||
try_files $uri =404;
|
try_files $uri =404;
|
||||||
}
|
}
|
||||||
@@ -87,31 +90,64 @@ http {
|
|||||||
location = /manifest.json {
|
location = /manifest.json {
|
||||||
root /app/html;
|
root /app/html;
|
||||||
expires off;
|
expires off;
|
||||||
|
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
|
||||||
|
add_header X-Content-Type-Options nosniff always;
|
||||||
add_header Cache-Control "no-store, no-cache, must-revalidate, proxy-revalidate, max-age=0" always;
|
add_header Cache-Control "no-store, no-cache, must-revalidate, proxy-revalidate, max-age=0" always;
|
||||||
try_files $uri =404;
|
try_files $uri =404;
|
||||||
}
|
}
|
||||||
|
|
||||||
location ~* \.(js|css|png|jpg|jpeg|gif|ico|svg|woff|woff2|ttf|eot)$ {
|
location ^~ /assets/ {
|
||||||
root /app/html;
|
root /app/html;
|
||||||
expires 1y;
|
expires 1y;
|
||||||
|
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
|
||||||
|
add_header X-Content-Type-Options nosniff always;
|
||||||
add_header Cache-Control "public, max-age=31536000, immutable" always;
|
add_header Cache-Control "public, max-age=31536000, immutable" always;
|
||||||
try_files $uri =404;
|
try_files $uri =404;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
location ^~ /fonts/ {
|
||||||
|
root /app/html;
|
||||||
|
expires 1y;
|
||||||
|
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
|
||||||
|
add_header X-Content-Type-Options nosniff always;
|
||||||
|
add_header Cache-Control "public, max-age=31536000, immutable" always;
|
||||||
|
try_files $uri =404;
|
||||||
|
}
|
||||||
|
|
||||||
|
location ^~ /icons/ {
|
||||||
|
root /app/html;
|
||||||
|
expires 30d;
|
||||||
|
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
|
||||||
|
add_header X-Content-Type-Options nosniff always;
|
||||||
|
add_header Cache-Control "public, max-age=2592000" always;
|
||||||
|
try_files $uri =404;
|
||||||
|
}
|
||||||
|
|
||||||
|
location ~* ^/[^/]+\.(js|css|png|jpe?g|gif|ico|svg|webp|woff2?|ttf|eot)$ {
|
||||||
|
root /app/html;
|
||||||
|
expires 30d;
|
||||||
|
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
|
||||||
|
add_header X-Content-Type-Options nosniff always;
|
||||||
|
add_header Cache-Control "public, max-age=2592000" always;
|
||||||
|
try_files $uri =404;
|
||||||
|
}
|
||||||
|
|
||||||
|
location ~* \.map$ {
|
||||||
|
access_log off;
|
||||||
|
log_not_found off;
|
||||||
|
return 404;
|
||||||
|
}
|
||||||
|
|
||||||
location / {
|
location / {
|
||||||
root /app/html;
|
root /app/html;
|
||||||
index index.html index.htm;
|
index index.html index.htm;
|
||||||
expires off;
|
expires off;
|
||||||
|
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
|
||||||
|
add_header X-Content-Type-Options nosniff always;
|
||||||
add_header Cache-Control "no-store, no-cache, must-revalidate, proxy-revalidate, max-age=0" always;
|
add_header Cache-Control "no-store, no-cache, must-revalidate, proxy-revalidate, max-age=0" always;
|
||||||
try_files $uri $uri/ /index.html;
|
try_files $uri $uri/ /index.html;
|
||||||
}
|
}
|
||||||
|
|
||||||
location ~* \.map$ {
|
|
||||||
return 404;
|
|
||||||
access_log off;
|
|
||||||
log_not_found off;
|
|
||||||
}
|
|
||||||
|
|
||||||
location ~ ^/users/sessions(/.*)?$ {
|
location ~ ^/users/sessions(/.*)?$ {
|
||||||
proxy_pass http://127.0.0.1:30001;
|
proxy_pass http://127.0.0.1:30001;
|
||||||
proxy_http_version 1.1;
|
proxy_http_version 1.1;
|
||||||
@@ -372,7 +408,9 @@ http {
|
|||||||
|
|
||||||
proxy_cache_bypass 1;
|
proxy_cache_bypass 1;
|
||||||
proxy_no_cache 1;
|
proxy_no_cache 1;
|
||||||
add_header Cache-Control "no-store, no-cache, must-revalidate, proxy-revalidate, max-age=0";
|
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
|
||||||
|
add_header X-Content-Type-Options nosniff always;
|
||||||
|
add_header Cache-Control "no-store, no-cache, must-revalidate, proxy-revalidate, max-age=0" always;
|
||||||
}
|
}
|
||||||
|
|
||||||
location ~ ^/host/opkssh-callback(/.*)?$ {
|
location ~ ^/host/opkssh-callback(/.*)?$ {
|
||||||
@@ -387,7 +425,9 @@ http {
|
|||||||
|
|
||||||
proxy_cache_bypass 1;
|
proxy_cache_bypass 1;
|
||||||
proxy_no_cache 1;
|
proxy_no_cache 1;
|
||||||
add_header Cache-Control "no-store, no-cache, must-revalidate, proxy-revalidate, max-age=0";
|
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
|
||||||
|
add_header X-Content-Type-Options nosniff always;
|
||||||
|
add_header Cache-Control "no-store, no-cache, must-revalidate, proxy-revalidate, max-age=0" always;
|
||||||
}
|
}
|
||||||
|
|
||||||
location /host/ {
|
location /host/ {
|
||||||
@@ -549,6 +589,8 @@ http {
|
|||||||
client_max_body_size 5G;
|
client_max_body_size 5G;
|
||||||
client_body_timeout 300s;
|
client_body_timeout 300s;
|
||||||
|
|
||||||
|
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
|
||||||
|
add_header X-Content-Type-Options nosniff always;
|
||||||
add_header Cache-Control "no-store, no-cache, must-revalidate" always;
|
add_header Cache-Control "no-store, no-cache, must-revalidate" always;
|
||||||
|
|
||||||
proxy_pass http://127.0.0.1:30004;
|
proxy_pass http://127.0.0.1:30004;
|
||||||
@@ -570,6 +612,8 @@ http {
|
|||||||
client_max_body_size 5G;
|
client_max_body_size 5G;
|
||||||
client_body_timeout 300s;
|
client_body_timeout 300s;
|
||||||
|
|
||||||
|
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
|
||||||
|
add_header X-Content-Type-Options nosniff always;
|
||||||
add_header Cache-Control "no-store, no-cache, must-revalidate" always;
|
add_header Cache-Control "no-store, no-cache, must-revalidate" always;
|
||||||
|
|
||||||
proxy_pass http://127.0.0.1:30004;
|
proxy_pass http://127.0.0.1:30004;
|
||||||
@@ -771,6 +815,7 @@ http {
|
|||||||
error_page 500 502 503 504 /50x.html;
|
error_page 500 502 503 504 /50x.html;
|
||||||
location = /50x.html {
|
location = /50x.html {
|
||||||
root /app/html;
|
root /app/html;
|
||||||
|
internal;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
+44
-10
@@ -11,6 +11,8 @@ http {
|
|||||||
include /etc/nginx/mime.types;
|
include /etc/nginx/mime.types;
|
||||||
default_type application/octet-stream;
|
default_type application/octet-stream;
|
||||||
|
|
||||||
|
server_tokens off;
|
||||||
|
|
||||||
access_log /tmp/nginx/access.log;
|
access_log /tmp/nginx/access.log;
|
||||||
|
|
||||||
client_body_temp_path /tmp/nginx/client_body;
|
client_body_temp_path /tmp/nginx/client_body;
|
||||||
@@ -58,7 +60,6 @@ http {
|
|||||||
absolute_redirect off;
|
absolute_redirect off;
|
||||||
|
|
||||||
add_header X-Content-Type-Options nosniff always;
|
add_header X-Content-Type-Options nosniff always;
|
||||||
add_header X-XSS-Protection "1; mode=block" always;
|
|
||||||
|
|
||||||
location ^~ /.well-known/acme-challenge/ {
|
location ^~ /.well-known/acme-challenge/ {
|
||||||
root /app/data/acme-webroot;
|
root /app/data/acme-webroot;
|
||||||
@@ -69,6 +70,7 @@ http {
|
|||||||
location = /sw.js {
|
location = /sw.js {
|
||||||
root /app/html;
|
root /app/html;
|
||||||
expires off;
|
expires off;
|
||||||
|
add_header X-Content-Type-Options nosniff always;
|
||||||
add_header Cache-Control "no-store, no-cache, must-revalidate, proxy-revalidate, max-age=0" always;
|
add_header Cache-Control "no-store, no-cache, must-revalidate, proxy-revalidate, max-age=0" always;
|
||||||
try_files $uri =404;
|
try_files $uri =404;
|
||||||
}
|
}
|
||||||
@@ -76,31 +78,58 @@ http {
|
|||||||
location = /manifest.json {
|
location = /manifest.json {
|
||||||
root /app/html;
|
root /app/html;
|
||||||
expires off;
|
expires off;
|
||||||
|
add_header X-Content-Type-Options nosniff always;
|
||||||
add_header Cache-Control "no-store, no-cache, must-revalidate, proxy-revalidate, max-age=0" always;
|
add_header Cache-Control "no-store, no-cache, must-revalidate, proxy-revalidate, max-age=0" always;
|
||||||
try_files $uri =404;
|
try_files $uri =404;
|
||||||
}
|
}
|
||||||
|
|
||||||
location ~* \.(js|css|png|jpg|jpeg|gif|ico|svg|woff|woff2|ttf|eot)$ {
|
location ^~ /assets/ {
|
||||||
root /app/html;
|
root /app/html;
|
||||||
expires 1y;
|
expires 1y;
|
||||||
|
add_header X-Content-Type-Options nosniff always;
|
||||||
add_header Cache-Control "public, max-age=31536000, immutable" always;
|
add_header Cache-Control "public, max-age=31536000, immutable" always;
|
||||||
try_files $uri =404;
|
try_files $uri =404;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
location ^~ /fonts/ {
|
||||||
|
root /app/html;
|
||||||
|
expires 1y;
|
||||||
|
add_header X-Content-Type-Options nosniff always;
|
||||||
|
add_header Cache-Control "public, max-age=31536000, immutable" always;
|
||||||
|
try_files $uri =404;
|
||||||
|
}
|
||||||
|
|
||||||
|
location ^~ /icons/ {
|
||||||
|
root /app/html;
|
||||||
|
expires 30d;
|
||||||
|
add_header X-Content-Type-Options nosniff always;
|
||||||
|
add_header Cache-Control "public, max-age=2592000" always;
|
||||||
|
try_files $uri =404;
|
||||||
|
}
|
||||||
|
|
||||||
|
location ~* ^/[^/]+\.(js|css|png|jpe?g|gif|ico|svg|webp|woff2?|ttf|eot)$ {
|
||||||
|
root /app/html;
|
||||||
|
expires 30d;
|
||||||
|
add_header X-Content-Type-Options nosniff always;
|
||||||
|
add_header Cache-Control "public, max-age=2592000" always;
|
||||||
|
try_files $uri =404;
|
||||||
|
}
|
||||||
|
|
||||||
|
location ~* \.map$ {
|
||||||
|
access_log off;
|
||||||
|
log_not_found off;
|
||||||
|
return 404;
|
||||||
|
}
|
||||||
|
|
||||||
location / {
|
location / {
|
||||||
root /app/html;
|
root /app/html;
|
||||||
index index.html index.htm;
|
index index.html index.htm;
|
||||||
expires off;
|
expires off;
|
||||||
|
add_header X-Content-Type-Options nosniff always;
|
||||||
add_header Cache-Control "no-store, no-cache, must-revalidate, proxy-revalidate, max-age=0" always;
|
add_header Cache-Control "no-store, no-cache, must-revalidate, proxy-revalidate, max-age=0" always;
|
||||||
try_files $uri $uri/ /index.html;
|
try_files $uri $uri/ /index.html;
|
||||||
}
|
}
|
||||||
|
|
||||||
location ~* \.map$ {
|
|
||||||
return 404;
|
|
||||||
access_log off;
|
|
||||||
log_not_found off;
|
|
||||||
}
|
|
||||||
|
|
||||||
location ~ ^/users/sessions(/.*)?$ {
|
location ~ ^/users/sessions(/.*)?$ {
|
||||||
proxy_pass http://127.0.0.1:30001;
|
proxy_pass http://127.0.0.1:30001;
|
||||||
proxy_http_version 1.1;
|
proxy_http_version 1.1;
|
||||||
@@ -361,7 +390,8 @@ http {
|
|||||||
|
|
||||||
proxy_cache_bypass 1;
|
proxy_cache_bypass 1;
|
||||||
proxy_no_cache 1;
|
proxy_no_cache 1;
|
||||||
add_header Cache-Control "no-store, no-cache, must-revalidate, proxy-revalidate, max-age=0";
|
add_header X-Content-Type-Options nosniff always;
|
||||||
|
add_header Cache-Control "no-store, no-cache, must-revalidate, proxy-revalidate, max-age=0" always;
|
||||||
}
|
}
|
||||||
|
|
||||||
location ~ ^/host/opkssh-callback(/.*)?$ {
|
location ~ ^/host/opkssh-callback(/.*)?$ {
|
||||||
@@ -376,7 +406,8 @@ http {
|
|||||||
|
|
||||||
proxy_cache_bypass 1;
|
proxy_cache_bypass 1;
|
||||||
proxy_no_cache 1;
|
proxy_no_cache 1;
|
||||||
add_header Cache-Control "no-store, no-cache, must-revalidate, proxy-revalidate, max-age=0";
|
add_header X-Content-Type-Options nosniff always;
|
||||||
|
add_header Cache-Control "no-store, no-cache, must-revalidate, proxy-revalidate, max-age=0" always;
|
||||||
}
|
}
|
||||||
|
|
||||||
location /host/ {
|
location /host/ {
|
||||||
@@ -538,6 +569,7 @@ http {
|
|||||||
client_max_body_size 5G;
|
client_max_body_size 5G;
|
||||||
client_body_timeout 300s;
|
client_body_timeout 300s;
|
||||||
|
|
||||||
|
add_header X-Content-Type-Options nosniff always;
|
||||||
add_header Cache-Control "no-store, no-cache, must-revalidate" always;
|
add_header Cache-Control "no-store, no-cache, must-revalidate" always;
|
||||||
|
|
||||||
proxy_pass http://127.0.0.1:30004;
|
proxy_pass http://127.0.0.1:30004;
|
||||||
@@ -559,6 +591,7 @@ http {
|
|||||||
client_max_body_size 5G;
|
client_max_body_size 5G;
|
||||||
client_body_timeout 300s;
|
client_body_timeout 300s;
|
||||||
|
|
||||||
|
add_header X-Content-Type-Options nosniff always;
|
||||||
add_header Cache-Control "no-store, no-cache, must-revalidate" always;
|
add_header Cache-Control "no-store, no-cache, must-revalidate" always;
|
||||||
|
|
||||||
proxy_pass http://127.0.0.1:30004;
|
proxy_pass http://127.0.0.1:30004;
|
||||||
@@ -760,6 +793,7 @@ http {
|
|||||||
error_page 500 502 503 504 /50x.html;
|
error_page 500 502 503 504 /50x.html;
|
||||||
location = /50x.html {
|
location = /50x.html {
|
||||||
root /app/html;
|
root /app/html;
|
||||||
|
internal;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,240 @@
|
|||||||
|
# Database backends
|
||||||
|
|
||||||
|
Termix runs on SQLite by default. Postgres and MySQL are supported for
|
||||||
|
self-hosted deployments; this document records how the three differ, because the
|
||||||
|
differences are not only about SQL.
|
||||||
|
|
||||||
|
## This is multi-backend, not a migration
|
||||||
|
|
||||||
|
SQLite is not going away. The desktop app embeds its own backend and cannot ship
|
||||||
|
a database server, so it will always run on SQLite. Postgres and MySQL exist for
|
||||||
|
self-hosted deployments that need more than one process to reach the data —
|
||||||
|
multiple replicas, an external backup story, or an existing database estate.
|
||||||
|
|
||||||
|
Anything that assumes a single engine is wrong.
|
||||||
|
|
||||||
|
## Where the schema comes from
|
||||||
|
|
||||||
|
`src/backend/database/db/schema.ts` is the single source of truth, written
|
||||||
|
against `drizzle-orm/sqlite-core`.
|
||||||
|
|
||||||
|
`schema.pg.ts` and `schema.mysql.ts` are **generated** from it:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
npm run schema:generate # rewrite the generated modules
|
||||||
|
npm run schema:check # fail if they are out of date (runs as part of lint)
|
||||||
|
```
|
||||||
|
|
||||||
|
Never edit the generated files. `npm run lint` fails if they drift from the
|
||||||
|
source, so a schema change that forgets to regenerate cannot reach main.
|
||||||
|
|
||||||
|
The transforms are mechanical:
|
||||||
|
|
||||||
|
| sqlite | postgres | mysql |
|
||||||
|
| ------------------------------------------------ | ----------------- | ----------------------- |
|
||||||
|
| `integer(…, { mode: "boolean" })` | `boolean` | `boolean` |
|
||||||
|
| `integer(…).primaryKey({ autoIncrement: true })` | `serial` | `int().autoincrement()` |
|
||||||
|
| `integer` | `integer` | `int` |
|
||||||
|
| `real` | `doublePrecision` | `double` |
|
||||||
|
| `text` used as a key | `varchar(255)` | `varchar(255)` |
|
||||||
|
|
||||||
|
A column becomes `varchar` if it is a primary key, is unique, or sits on either
|
||||||
|
end of a foreign key — MySQL cannot index an unbounded `TEXT`, and both sides of
|
||||||
|
a foreign key must agree.
|
||||||
|
|
||||||
|
## Durability
|
||||||
|
|
||||||
|
On SQLite the database is loaded into memory and serialised back to an encrypted
|
||||||
|
file, so every write needs an explicit flush. That is what the `onWrite` hook
|
||||||
|
each repository receives is for.
|
||||||
|
|
||||||
|
On Postgres and MySQL a committed write is already durable. No hook is installed
|
||||||
|
at all — see `needsExplicitPersist` in `db/dialect.ts`.
|
||||||
|
|
||||||
|
## Encryption: what changes, and what does not
|
||||||
|
|
||||||
|
This is the part most likely to be misread, so it is spelled out.
|
||||||
|
|
||||||
|
### Unchanged on every backend
|
||||||
|
|
||||||
|
**Field-level encryption still applies.** Credentials and other sensitive values
|
||||||
|
are encrypted in the application before they reach the database, under a
|
||||||
|
per-user data key:
|
||||||
|
|
||||||
|
- `ssh_data` — passwords, private keys, key passphrases, sudo/RDP/VNC/Telnet
|
||||||
|
secrets
|
||||||
|
- `ssh_credentials` — passwords, private and public keys
|
||||||
|
- `users` — TOTP secret and backup codes
|
||||||
|
- `vault_tokens`, `opkssh_tokens`, `termix_identity_ca` — certificates and keys
|
||||||
|
- `shared_host_secrets` — re-encrypted per recipient
|
||||||
|
|
||||||
|
Installation-level secrets — the OIDC client secret and LDAP bind password —
|
||||||
|
are encrypted under the system key, since they have no owning user and must be
|
||||||
|
readable during login.
|
||||||
|
|
||||||
|
This is the protection that matters most, and it is identical on all three
|
||||||
|
engines.
|
||||||
|
|
||||||
|
### Different on Postgres and MySQL
|
||||||
|
|
||||||
|
**Whole-file encryption does not exist.** On SQLite the database file itself is
|
||||||
|
encrypted at rest. There is no equivalent for a client-server engine: the data
|
||||||
|
lives in the server's storage, not in a file Termix owns.
|
||||||
|
|
||||||
|
Concretely, on Postgres/MySQL the following are readable by anyone with database
|
||||||
|
access, where on SQLite they were covered by the file encryption:
|
||||||
|
|
||||||
|
- host names, addresses, ports and usernames
|
||||||
|
- folder and snippet names, and **snippet contents**
|
||||||
|
- audit log entries
|
||||||
|
- session recording metadata and paths
|
||||||
|
- user names, roles and API key hashes
|
||||||
|
|
||||||
|
None of these are credentials — those stay encrypted — but together they
|
||||||
|
describe your estate.
|
||||||
|
|
||||||
|
**If you run Postgres or MySQL, encryption at rest is your responsibility**:
|
||||||
|
transparent data encryption, an encrypted volume, or an encrypted filesystem.
|
||||||
|
Termix does not provide it and cannot.
|
||||||
|
|
||||||
|
### Threat model, side by side
|
||||||
|
|
||||||
|
| | SQLite | Postgres / MySQL |
|
||||||
|
| ----------------------------------------------- | ------------------------------------------------ | ------------------------------------------------------------------ |
|
||||||
|
| Stolen database file / volume | credentials encrypted, everything else encrypted | credentials encrypted, **rest depends on your storage encryption** |
|
||||||
|
| Database access without app access | credentials unreadable | credentials unreadable |
|
||||||
|
| Application compromise while a user is unlocked | that user's secrets readable | same |
|
||||||
|
| Backups | inherit file encryption | **plain unless you encrypt them** |
|
||||||
|
|
||||||
|
The second row is the point of field-level encryption, and it holds everywhere.
|
||||||
|
The first and last rows are where the backends genuinely differ.
|
||||||
|
|
||||||
|
## Running on Postgres or MySQL
|
||||||
|
|
||||||
|
Two variables. Unset, nothing changes and SQLite is used exactly as before.
|
||||||
|
|
||||||
|
```
|
||||||
|
DATABASE_DIALECT=postgres
|
||||||
|
DATABASE_URL=postgres://user:password@host:5432/termix
|
||||||
|
```
|
||||||
|
|
||||||
|
```
|
||||||
|
DATABASE_DIALECT=mysql
|
||||||
|
DATABASE_URL=mysql://user:password@host:3306/termix
|
||||||
|
```
|
||||||
|
|
||||||
|
`mariadb://` is accepted for MySQL. The scheme is checked against the dialect
|
||||||
|
before a connection is attempted, so a mismatch fails with a readable message
|
||||||
|
rather than a driver error deep in a stack.
|
||||||
|
|
||||||
|
Point it at an **empty** database. Migrations are applied at startup, from
|
||||||
|
`drizzle/postgres` or `drizzle/mysql`, and drizzle records what it has applied —
|
||||||
|
so several instances against one database are safe, and so is restarting.
|
||||||
|
|
||||||
|
There is no migration path from an existing SQLite database. Exporting one and
|
||||||
|
importing it into Postgres is not something this branch does.
|
||||||
|
|
||||||
|
### Docker
|
||||||
|
|
||||||
|
`drizzle/` ships in the image. A compose service needs only the two variables:
|
||||||
|
|
||||||
|
Added to the compose file in the README, that is one service and two variables:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
services:
|
||||||
|
termix:
|
||||||
|
image: ghcr.io/lukegus/termix:latest
|
||||||
|
environment:
|
||||||
|
PORT: "8080"
|
||||||
|
DATABASE_DIALECT: postgres
|
||||||
|
DATABASE_URL: postgres://termix:termix@db:5432/termix
|
||||||
|
depends_on:
|
||||||
|
- db
|
||||||
|
|
||||||
|
db:
|
||||||
|
image: postgres:16
|
||||||
|
restart: unless-stopped
|
||||||
|
environment:
|
||||||
|
POSTGRES_USER: termix
|
||||||
|
POSTGRES_PASSWORD: termix
|
||||||
|
POSTGRES_DB: termix
|
||||||
|
volumes:
|
||||||
|
- pgdata:/var/lib/postgresql/data
|
||||||
|
|
||||||
|
volumes:
|
||||||
|
pgdata:
|
||||||
|
```
|
||||||
|
|
||||||
|
`DATA_DIR` is still used for uploads and recordings on every backend. Only the
|
||||||
|
database itself moves.
|
||||||
|
|
||||||
|
## What is verified, and how
|
||||||
|
|
||||||
|
`npm run verify:dialect -- <url>` applies the migrations to an empty database and
|
||||||
|
drives the real repository classes against it, asserting values rather than the
|
||||||
|
absence of exceptions.
|
||||||
|
|
||||||
|
The repository test suite also runs against each engine:
|
||||||
|
|
||||||
|
```
|
||||||
|
TEST_DIALECT=postgres TEST_DATABASE_URL=<url> npx vitest run \
|
||||||
|
src/backend/tests/database/repositories --no-file-parallelism
|
||||||
|
```
|
||||||
|
|
||||||
|
CI runs both, against PostgreSQL 16 and MySQL 8 service containers. Eighteen
|
||||||
|
tests assert on bytes stored by the SQLite driver and skip on other engines;
|
||||||
|
they still run in the SQLite pass.
|
||||||
|
|
||||||
|
Tested against PostgreSQL 16 and MySQL 8. **MariaDB is not a substitute for
|
||||||
|
MySQL when testing** — it accepts DDL that MySQL 8 rejects, which has hidden a
|
||||||
|
real defect here more than once.
|
||||||
|
|
||||||
|
### What neither of them covers
|
||||||
|
|
||||||
|
Both harnesses build a `DatabaseContext` of their own, so neither runs
|
||||||
|
`createCurrentRepositoryContext()` — the one the application actually uses.
|
||||||
|
That gap hid a hardcoded `dialect: "sqlite"` in it: every engine reported
|
||||||
|
itself as SQLite at runtime while all three test passes stayed green, which on
|
||||||
|
MySQL meant `upsert` reached for `onConflictDoUpdate` and died with a
|
||||||
|
TypeError on the first write.
|
||||||
|
|
||||||
|
Anything the factory decides from the dialect needs its own test against the
|
||||||
|
factory. Asserting it through a hand-built context proves nothing about what
|
||||||
|
runs in production.
|
||||||
|
|
||||||
|
## Known limits
|
||||||
|
|
||||||
|
- The desktop app always uses SQLite. It embeds its own backend and cannot ship
|
||||||
|
a database server.
|
||||||
|
- Repositories import the SQLite table definitions on every engine. That is
|
||||||
|
correct — the query builder needs identifiers and value encoders, and those
|
||||||
|
agree — but it means `PortableDatabase` is a named approximation rather than a
|
||||||
|
guarantee. See `repositories/database-context.ts`.
|
||||||
|
- `getCurrentSettingValue` is a synchronous read. On Postgres and MySQL it comes
|
||||||
|
from a cache primed at startup and kept current by `SettingsRepository`,
|
||||||
|
because those drivers have no synchronous query.
|
||||||
|
|
||||||
|
That cache is per-process, so on a **multi-replica** deployment a setting
|
||||||
|
changed on one instance does not reach the others through the write path. Each
|
||||||
|
replica re-reads the settings table every 30 seconds
|
||||||
|
(`SETTINGS_CACHE_REFRESH_SECONDS`, 0 to disable), which does not make settings
|
||||||
|
immediately consistent — it bounds how long they can disagree. Changing a
|
||||||
|
setting takes effect on the replica that made the change at once, and on the
|
||||||
|
others within the interval.
|
||||||
|
|
||||||
|
- **Importing a backup is SQLite-only.** The restore writes tables in an order
|
||||||
|
that is not dependency-safe and relies on `PRAGMA foreign_keys = OFF`, which
|
||||||
|
has no equivalent here: Postgres needs superuser to disable triggers, and
|
||||||
|
MySQL's session-scoped switch is not guaranteed across a pool. It refuses with
|
||||||
|
a message rather than failing partway through and leaving a half-restored
|
||||||
|
database. Restore into Postgres or MySQL with their own tooling.
|
||||||
|
- **`LIKE` is case-insensitive on SQLite and case-sensitive on Postgres.** The
|
||||||
|
four places that use it match folder path prefixes and settings keys, so the
|
||||||
|
practical effect is that renaming a folder `prod` on SQLite also catches
|
||||||
|
`PROD / api` and on Postgres does not. Postgres is arguably the more correct
|
||||||
|
of the two; nothing was changed to make them agree, because that would alter
|
||||||
|
SQLite behaviour for existing deployments.
|
||||||
|
- The SQLite-era data migrations — legacy shared-credential cleanup, the
|
||||||
|
shared-host-secrets rebuild, per-user field-encryption backfill — do not run on
|
||||||
|
the other engines. A database created by the drizzle migrations never had the
|
||||||
|
shapes they repair.
|
||||||
@@ -0,0 +1,7 @@
|
|||||||
|
import { defineConfig } from "drizzle-kit";
|
||||||
|
|
||||||
|
export default defineConfig({
|
||||||
|
dialect: "mysql",
|
||||||
|
schema: "./src/backend/database/db/schema.mysql.ts",
|
||||||
|
out: "./drizzle/mysql",
|
||||||
|
});
|
||||||
@@ -0,0 +1,7 @@
|
|||||||
|
import { defineConfig } from "drizzle-kit";
|
||||||
|
|
||||||
|
export default defineConfig({
|
||||||
|
dialect: "postgresql",
|
||||||
|
schema: "./src/backend/database/db/schema.pg.ts",
|
||||||
|
out: "./drizzle/postgres",
|
||||||
|
});
|
||||||
@@ -0,0 +1,7 @@
|
|||||||
|
import { defineConfig } from "drizzle-kit";
|
||||||
|
|
||||||
|
export default defineConfig({
|
||||||
|
dialect: "sqlite",
|
||||||
|
schema: "./src/backend/database/db/schema.ts",
|
||||||
|
out: "./drizzle/sqlite",
|
||||||
|
});
|
||||||
@@ -0,0 +1,890 @@
|
|||||||
|
CREATE TABLE `alert_firings` (
|
||||||
|
`id` int AUTO_INCREMENT NOT NULL,
|
||||||
|
`user_id` varchar(255) NOT NULL,
|
||||||
|
`rule_id` int NOT NULL,
|
||||||
|
`host_id` int NOT NULL,
|
||||||
|
`host_name` text NOT NULL,
|
||||||
|
`fired_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
`resolved_at` text,
|
||||||
|
`value` double,
|
||||||
|
`message` text NOT NULL,
|
||||||
|
`severity` text NOT NULL DEFAULT ('warning'),
|
||||||
|
`acknowledged` boolean NOT NULL DEFAULT false,
|
||||||
|
CONSTRAINT `alert_firings_id` PRIMARY KEY(`id`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `alert_rule_channels` (
|
||||||
|
`id` int AUTO_INCREMENT NOT NULL,
|
||||||
|
`rule_id` int NOT NULL,
|
||||||
|
`channel_id` int NOT NULL,
|
||||||
|
CONSTRAINT `alert_rule_channels_id` PRIMARY KEY(`id`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `alert_rules` (
|
||||||
|
`id` int AUTO_INCREMENT NOT NULL,
|
||||||
|
`user_id` varchar(255) NOT NULL,
|
||||||
|
`host_id` int,
|
||||||
|
`name` varchar(255) NOT NULL,
|
||||||
|
`enabled` boolean NOT NULL DEFAULT true,
|
||||||
|
`trigger_type` text NOT NULL,
|
||||||
|
`threshold_value` double,
|
||||||
|
`threshold_duration_seconds` int,
|
||||||
|
`cooldown_minutes` int NOT NULL DEFAULT 15,
|
||||||
|
`created_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
`updated_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
CONSTRAINT `alert_rules_id` PRIMARY KEY(`id`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `api_keys` (
|
||||||
|
`id` varchar(255) NOT NULL,
|
||||||
|
`user_id` varchar(255) NOT NULL,
|
||||||
|
`name` varchar(255) NOT NULL,
|
||||||
|
`token_hash` text NOT NULL,
|
||||||
|
`token_prefix` text NOT NULL,
|
||||||
|
`created_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
`expires_at` text,
|
||||||
|
`last_used_at` text,
|
||||||
|
`is_active` boolean NOT NULL DEFAULT true,
|
||||||
|
CONSTRAINT `api_keys_id` PRIMARY KEY(`id`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `audit_logs` (
|
||||||
|
`id` int AUTO_INCREMENT NOT NULL,
|
||||||
|
`user_id` varchar(255),
|
||||||
|
`username` text NOT NULL,
|
||||||
|
`action` text NOT NULL,
|
||||||
|
`resource_type` text NOT NULL,
|
||||||
|
`resource_id` text,
|
||||||
|
`resource_name` text,
|
||||||
|
`details` text,
|
||||||
|
`ip_address` text,
|
||||||
|
`user_agent` text,
|
||||||
|
`success` boolean NOT NULL,
|
||||||
|
`error_message` text,
|
||||||
|
`timestamp` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
CONSTRAINT `audit_logs_id` PRIMARY KEY(`id`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `c2s_tunnel_presets` (
|
||||||
|
`id` int AUTO_INCREMENT NOT NULL,
|
||||||
|
`user_id` varchar(255) NOT NULL,
|
||||||
|
`name` varchar(255) NOT NULL,
|
||||||
|
`config` text NOT NULL,
|
||||||
|
`platform` text,
|
||||||
|
`computer_name` text,
|
||||||
|
`created_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
`updated_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
CONSTRAINT `c2s_tunnel_presets_id` PRIMARY KEY(`id`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `command_history` (
|
||||||
|
`id` int AUTO_INCREMENT NOT NULL,
|
||||||
|
`user_id` varchar(255) NOT NULL,
|
||||||
|
`host_id` int NOT NULL,
|
||||||
|
`command` text NOT NULL,
|
||||||
|
`executed_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
CONSTRAINT `command_history_id` PRIMARY KEY(`id`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `dashboard_service_links` (
|
||||||
|
`id` int AUTO_INCREMENT NOT NULL,
|
||||||
|
`user_id` varchar(255) NOT NULL,
|
||||||
|
`label` text NOT NULL,
|
||||||
|
`url` text NOT NULL,
|
||||||
|
`order` int NOT NULL DEFAULT 0,
|
||||||
|
`sync_id` varchar(255),
|
||||||
|
`created_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
`updated_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
CONSTRAINT `dashboard_service_links_id` PRIMARY KEY(`id`),
|
||||||
|
CONSTRAINT `dashboard_service_links_sync_id_unique` UNIQUE(`sync_id`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `dismissed_alerts` (
|
||||||
|
`id` int AUTO_INCREMENT NOT NULL,
|
||||||
|
`user_id` varchar(255) NOT NULL,
|
||||||
|
`alert_id` text NOT NULL,
|
||||||
|
`dismissed_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
CONSTRAINT `dismissed_alerts_id` PRIMARY KEY(`id`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `file_manager_pinned` (
|
||||||
|
`id` int AUTO_INCREMENT NOT NULL,
|
||||||
|
`user_id` varchar(255) NOT NULL,
|
||||||
|
`host_id` int NOT NULL,
|
||||||
|
`name` varchar(255) NOT NULL,
|
||||||
|
`path` text NOT NULL,
|
||||||
|
`pinned_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
CONSTRAINT `file_manager_pinned_id` PRIMARY KEY(`id`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `file_manager_recent` (
|
||||||
|
`id` int AUTO_INCREMENT NOT NULL,
|
||||||
|
`user_id` varchar(255) NOT NULL,
|
||||||
|
`host_id` int NOT NULL,
|
||||||
|
`name` varchar(255) NOT NULL,
|
||||||
|
`path` text NOT NULL,
|
||||||
|
`last_opened` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
CONSTRAINT `file_manager_recent_id` PRIMARY KEY(`id`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `file_manager_shortcuts` (
|
||||||
|
`id` int AUTO_INCREMENT NOT NULL,
|
||||||
|
`user_id` varchar(255) NOT NULL,
|
||||||
|
`host_id` int NOT NULL,
|
||||||
|
`name` varchar(255) NOT NULL,
|
||||||
|
`path` text NOT NULL,
|
||||||
|
`created_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
CONSTRAINT `file_manager_shortcuts_id` PRIMARY KEY(`id`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `homepage_items` (
|
||||||
|
`id` int AUTO_INCREMENT NOT NULL,
|
||||||
|
`user_id` varchar(255) NOT NULL,
|
||||||
|
`type_id` text NOT NULL,
|
||||||
|
`title` text,
|
||||||
|
`config` text NOT NULL DEFAULT ('{}'),
|
||||||
|
`folder_id` int,
|
||||||
|
`sync_id` varchar(255),
|
||||||
|
`created_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
`updated_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
CONSTRAINT `homepage_items_id` PRIMARY KEY(`id`),
|
||||||
|
CONSTRAINT `homepage_items_sync_id_unique` UNIQUE(`sync_id`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `homepage_layouts` (
|
||||||
|
`id` int AUTO_INCREMENT NOT NULL,
|
||||||
|
`user_id` varchar(255) NOT NULL,
|
||||||
|
`layout` text NOT NULL DEFAULT ('{}'),
|
||||||
|
`updated_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
CONSTRAINT `homepage_layouts_id` PRIMARY KEY(`id`),
|
||||||
|
CONSTRAINT `homepage_layouts_user_id_unique` UNIQUE(`user_id`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `host_access` (
|
||||||
|
`id` int AUTO_INCREMENT NOT NULL,
|
||||||
|
`host_id` int NOT NULL,
|
||||||
|
`user_id` varchar(255),
|
||||||
|
`role_id` int,
|
||||||
|
`granted_by` varchar(255) NOT NULL,
|
||||||
|
`permission_level` text NOT NULL DEFAULT ('connect'),
|
||||||
|
`expires_at` text,
|
||||||
|
`created_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
`last_accessed_at` text,
|
||||||
|
`access_count` int NOT NULL DEFAULT 0,
|
||||||
|
CONSTRAINT `host_access_id` PRIMARY KEY(`id`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `host_health_checks` (
|
||||||
|
`id` int AUTO_INCREMENT NOT NULL,
|
||||||
|
`user_id` varchar(255) NOT NULL,
|
||||||
|
`host_id` int NOT NULL,
|
||||||
|
`checks` text NOT NULL,
|
||||||
|
`interval_seconds` int NOT NULL DEFAULT 300,
|
||||||
|
`created_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
`updated_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
CONSTRAINT `host_health_checks_id` PRIMARY KEY(`id`),
|
||||||
|
CONSTRAINT `idx_host_health_checks_user_host` UNIQUE(`user_id`,`host_id`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `host_health_history` (
|
||||||
|
`id` int AUTO_INCREMENT NOT NULL,
|
||||||
|
`user_id` varchar(255) NOT NULL,
|
||||||
|
`host_id` int NOT NULL,
|
||||||
|
`check_id` text NOT NULL,
|
||||||
|
`ts` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
`ok` boolean NOT NULL,
|
||||||
|
`latency_ms` int,
|
||||||
|
`detail` text,
|
||||||
|
CONSTRAINT `host_health_history_id` PRIMARY KEY(`id`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `host_metrics_history` (
|
||||||
|
`id` int AUTO_INCREMENT NOT NULL,
|
||||||
|
`host_id` int NOT NULL,
|
||||||
|
`ts` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
`cpu_percent` double,
|
||||||
|
`mem_percent` double,
|
||||||
|
`disk_percent` double,
|
||||||
|
`net_rx_bytes` int,
|
||||||
|
`net_tx_bytes` int,
|
||||||
|
CONSTRAINT `host_metrics_history_id` PRIMARY KEY(`id`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `host_metrics_preferences` (
|
||||||
|
`id` int AUTO_INCREMENT NOT NULL,
|
||||||
|
`user_id` varchar(255) NOT NULL,
|
||||||
|
`host_id` int NOT NULL,
|
||||||
|
`layout` text NOT NULL,
|
||||||
|
`created_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
`updated_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
CONSTRAINT `host_metrics_preferences_id` PRIMARY KEY(`id`),
|
||||||
|
CONSTRAINT `idx_host_metrics_prefs_user_host` UNIQUE(`user_id`,`host_id`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `ssh_data` (
|
||||||
|
`id` int AUTO_INCREMENT NOT NULL,
|
||||||
|
`user_id` varchar(255) NOT NULL,
|
||||||
|
`connection_type` text NOT NULL DEFAULT ('ssh'),
|
||||||
|
`name` varchar(255),
|
||||||
|
`ip` text NOT NULL,
|
||||||
|
`port` int NOT NULL,
|
||||||
|
`username` text NOT NULL,
|
||||||
|
`folder` text,
|
||||||
|
`tags` text,
|
||||||
|
`pin` boolean NOT NULL DEFAULT false,
|
||||||
|
`auth_type` text NOT NULL,
|
||||||
|
`use_warpgate` boolean NOT NULL DEFAULT false,
|
||||||
|
`share_ssh_auth` boolean NOT NULL DEFAULT false,
|
||||||
|
`force_keyboard_interactive` text,
|
||||||
|
`password` text,
|
||||||
|
`key` text,
|
||||||
|
`key_password` text,
|
||||||
|
`key_type` text,
|
||||||
|
`sudo_password` text,
|
||||||
|
`autostart_password` text,
|
||||||
|
`autostart_key` text,
|
||||||
|
`autostart_key_password` text,
|
||||||
|
`credential_id` int,
|
||||||
|
`override_credential_username` boolean,
|
||||||
|
`vault_profile_id` int,
|
||||||
|
`enable_terminal` boolean NOT NULL DEFAULT true,
|
||||||
|
`enable_session_logging` boolean NOT NULL DEFAULT true,
|
||||||
|
`allow_session_sharing` boolean NOT NULL DEFAULT true,
|
||||||
|
`enable_command_history` boolean NOT NULL DEFAULT true,
|
||||||
|
`enable_tunnel` boolean NOT NULL DEFAULT true,
|
||||||
|
`tunnel_connections` text,
|
||||||
|
`jump_hosts` text,
|
||||||
|
`enable_file_manager` boolean NOT NULL DEFAULT true,
|
||||||
|
`scp_legacy` boolean NOT NULL DEFAULT false,
|
||||||
|
`enable_docker` boolean NOT NULL DEFAULT false,
|
||||||
|
`enable_tmux_monitor` boolean NOT NULL DEFAULT false,
|
||||||
|
`show_terminal_in_sidebar` boolean NOT NULL DEFAULT true,
|
||||||
|
`show_file_manager_in_sidebar` boolean NOT NULL DEFAULT false,
|
||||||
|
`show_tunnel_in_sidebar` boolean NOT NULL DEFAULT false,
|
||||||
|
`show_docker_in_sidebar` boolean NOT NULL DEFAULT false,
|
||||||
|
`show_server_stats_in_sidebar` boolean NOT NULL DEFAULT false,
|
||||||
|
`default_path` text,
|
||||||
|
`stats_config` text,
|
||||||
|
`docker_config` text,
|
||||||
|
`enable_proxmox` boolean NOT NULL DEFAULT false,
|
||||||
|
`proxmox_config` text,
|
||||||
|
`terminal_config` text,
|
||||||
|
`quick_actions` text,
|
||||||
|
`notes` text,
|
||||||
|
`enable_ssh` boolean NOT NULL DEFAULT true,
|
||||||
|
`enable_rdp` boolean NOT NULL DEFAULT false,
|
||||||
|
`enable_vnc` boolean NOT NULL DEFAULT false,
|
||||||
|
`enable_telnet` boolean NOT NULL DEFAULT false,
|
||||||
|
`ssh_port` int DEFAULT 22,
|
||||||
|
`rdp_port` int DEFAULT 3389,
|
||||||
|
`vnc_port` int DEFAULT 5900,
|
||||||
|
`telnet_port` int DEFAULT 23,
|
||||||
|
`rdp_credential_id` int,
|
||||||
|
`rdp_user` text,
|
||||||
|
`rdp_password` text,
|
||||||
|
`rdp_domain` text,
|
||||||
|
`rdp_security` text,
|
||||||
|
`rdp_ignore_cert` boolean DEFAULT false,
|
||||||
|
`vnc_credential_id` int,
|
||||||
|
`vnc_password` text,
|
||||||
|
`vnc_user` text,
|
||||||
|
`telnet_user` text,
|
||||||
|
`telnet_password` text,
|
||||||
|
`telnet_credential_id` int,
|
||||||
|
`rdp_auth_type` text,
|
||||||
|
`vnc_auth_type` text,
|
||||||
|
`telnet_auth_type` text,
|
||||||
|
`domain` text,
|
||||||
|
`security` text,
|
||||||
|
`ignore_cert` boolean DEFAULT false,
|
||||||
|
`guacamole_config` text,
|
||||||
|
`use_socks5` boolean,
|
||||||
|
`socks5_host` text,
|
||||||
|
`socks5_port` int,
|
||||||
|
`socks5_username` text,
|
||||||
|
`socks5_password` text,
|
||||||
|
`socks5_proxy_chain` text,
|
||||||
|
`connection_origin` text,
|
||||||
|
`mac_address` text,
|
||||||
|
`wol_broadcast_address` text,
|
||||||
|
`port_knock_sequence` text,
|
||||||
|
`host_key_fingerprint` text,
|
||||||
|
`host_key_type` text,
|
||||||
|
`host_key_algorithm` text DEFAULT ('sha256'),
|
||||||
|
`host_key_first_seen` text,
|
||||||
|
`host_key_last_verified` text,
|
||||||
|
`host_key_changed_count` int DEFAULT 0,
|
||||||
|
`sync_id` varchar(255),
|
||||||
|
`created_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
`updated_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
CONSTRAINT `ssh_data_id` PRIMARY KEY(`id`),
|
||||||
|
CONSTRAINT `ssh_data_sync_id_unique` UNIQUE(`sync_id`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `network_topology` (
|
||||||
|
`id` int AUTO_INCREMENT NOT NULL,
|
||||||
|
`user_id` varchar(255) NOT NULL,
|
||||||
|
`topology` text,
|
||||||
|
`created_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
`updated_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
CONSTRAINT `network_topology_id` PRIMARY KEY(`id`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `notification_channels` (
|
||||||
|
`id` int AUTO_INCREMENT NOT NULL,
|
||||||
|
`user_id` varchar(255) NOT NULL,
|
||||||
|
`name` varchar(255) NOT NULL,
|
||||||
|
`type` text NOT NULL,
|
||||||
|
`config` text NOT NULL,
|
||||||
|
`enabled` boolean NOT NULL DEFAULT true,
|
||||||
|
`created_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
CONSTRAINT `notification_channels_id` PRIMARY KEY(`id`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `opkssh_tokens` (
|
||||||
|
`id` int AUTO_INCREMENT NOT NULL,
|
||||||
|
`user_id` varchar(255) NOT NULL,
|
||||||
|
`host_id` int NOT NULL,
|
||||||
|
`ssh_cert` text NOT NULL,
|
||||||
|
`private_key` text NOT NULL,
|
||||||
|
`email` text,
|
||||||
|
`sub` text,
|
||||||
|
`issuer` text,
|
||||||
|
`audience` text,
|
||||||
|
`created_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
`expires_at` text NOT NULL,
|
||||||
|
`last_used` text,
|
||||||
|
CONSTRAINT `opkssh_tokens_id` PRIMARY KEY(`id`),
|
||||||
|
CONSTRAINT `idx_opkssh_tokens_user_host` UNIQUE(`user_id`,`host_id`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `recent_activity` (
|
||||||
|
`id` int AUTO_INCREMENT NOT NULL,
|
||||||
|
`user_id` varchar(255) NOT NULL,
|
||||||
|
`type` text NOT NULL,
|
||||||
|
`host_id` int NOT NULL,
|
||||||
|
`host_name` text,
|
||||||
|
`timestamp` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
CONSTRAINT `recent_activity_id` PRIMARY KEY(`id`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `roles` (
|
||||||
|
`id` int AUTO_INCREMENT NOT NULL,
|
||||||
|
`name` varchar(255) NOT NULL,
|
||||||
|
`display_name` text NOT NULL,
|
||||||
|
`description` text,
|
||||||
|
`is_system` boolean NOT NULL DEFAULT false,
|
||||||
|
`permissions` text,
|
||||||
|
`created_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
`updated_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
CONSTRAINT `roles_id` PRIMARY KEY(`id`),
|
||||||
|
CONSTRAINT `roles_name_unique` UNIQUE(`name`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `session_recordings` (
|
||||||
|
`id` int AUTO_INCREMENT NOT NULL,
|
||||||
|
`host_id` int NOT NULL,
|
||||||
|
`user_id` varchar(255),
|
||||||
|
`username` text,
|
||||||
|
`access_id` int,
|
||||||
|
`started_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
`ended_at` text,
|
||||||
|
`duration` int,
|
||||||
|
`commands` text,
|
||||||
|
`dangerous_actions` text,
|
||||||
|
`recording_path` text,
|
||||||
|
`protocol` varchar(255) NOT NULL DEFAULT 'ssh',
|
||||||
|
`format` text NOT NULL DEFAULT ('text'),
|
||||||
|
`terminated_by_owner` boolean DEFAULT false,
|
||||||
|
`termination_reason` text,
|
||||||
|
CONSTRAINT `session_recordings_id` PRIMARY KEY(`id`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `session_share_participants` (
|
||||||
|
`id` int AUTO_INCREMENT NOT NULL,
|
||||||
|
`share_id` varchar(255) NOT NULL,
|
||||||
|
`user_id` varchar(255),
|
||||||
|
`guest_label` text,
|
||||||
|
`joined_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
`left_at` text,
|
||||||
|
CONSTRAINT `session_share_participants_id` PRIMARY KEY(`id`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `session_shares` (
|
||||||
|
`id` varchar(255) NOT NULL,
|
||||||
|
`host_id` int NOT NULL,
|
||||||
|
`owner_user_id` varchar(255) NOT NULL,
|
||||||
|
`protocol` varchar(255) NOT NULL,
|
||||||
|
`session_id` text NOT NULL,
|
||||||
|
`tab_instance_id` text,
|
||||||
|
`share_type` text NOT NULL,
|
||||||
|
`target_user_id` varchar(255),
|
||||||
|
`link_token` varchar(255),
|
||||||
|
`permission_level` text NOT NULL DEFAULT ('read-only'),
|
||||||
|
`created_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
`expires_at` text NOT NULL,
|
||||||
|
`revoked_at` text,
|
||||||
|
`last_joined_at` text,
|
||||||
|
`join_count` int NOT NULL DEFAULT 0,
|
||||||
|
CONSTRAINT `session_shares_id` PRIMARY KEY(`id`),
|
||||||
|
CONSTRAINT `session_shares_link_token_unique` UNIQUE(`link_token`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `sessions` (
|
||||||
|
`id` varchar(255) NOT NULL,
|
||||||
|
`user_id` varchar(255) NOT NULL,
|
||||||
|
`jwt_token` text NOT NULL,
|
||||||
|
`device_type` text NOT NULL,
|
||||||
|
`device_info` text NOT NULL,
|
||||||
|
`oidc_sub` text,
|
||||||
|
`oidc_sid` text,
|
||||||
|
`sso_provider_id` int,
|
||||||
|
`created_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
`expires_at` text NOT NULL,
|
||||||
|
`last_active_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
CONSTRAINT `sessions_id` PRIMARY KEY(`id`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `settings` (
|
||||||
|
`key` varchar(255) NOT NULL,
|
||||||
|
`value` text NOT NULL,
|
||||||
|
CONSTRAINT `settings_key` PRIMARY KEY(`key`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `shared_host_auth_overrides` (
|
||||||
|
`id` int AUTO_INCREMENT NOT NULL,
|
||||||
|
`host_id` int NOT NULL,
|
||||||
|
`user_id` varchar(255) NOT NULL,
|
||||||
|
`protocol` varchar(255) NOT NULL DEFAULT 'ssh',
|
||||||
|
`credential_id` int NOT NULL,
|
||||||
|
`created_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
`updated_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
CONSTRAINT `shared_host_auth_overrides_id` PRIMARY KEY(`id`),
|
||||||
|
CONSTRAINT `shared_host_auth_overrides_host_user_protocol_unique` UNIQUE(`host_id`,`user_id`,`protocol`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `shared_host_secrets` (
|
||||||
|
`id` int AUTO_INCREMENT NOT NULL,
|
||||||
|
`host_access_id` int NOT NULL,
|
||||||
|
`target_user_id` varchar(255) NOT NULL,
|
||||||
|
`protocol` varchar(255) NOT NULL DEFAULT 'ssh',
|
||||||
|
`source_type` text NOT NULL DEFAULT ('credential'),
|
||||||
|
`original_credential_id` int,
|
||||||
|
`encrypted_username` text,
|
||||||
|
`encrypted_auth_type` text,
|
||||||
|
`encrypted_password` text,
|
||||||
|
`encrypted_key` text,
|
||||||
|
`encrypted_key_password` text,
|
||||||
|
`encrypted_key_type` text,
|
||||||
|
`encrypted_domain` text,
|
||||||
|
`created_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
`updated_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
CONSTRAINT `shared_host_secrets_id` PRIMARY KEY(`id`),
|
||||||
|
CONSTRAINT `idx_shared_host_secrets_scope` UNIQUE(`host_access_id`,`target_user_id`,`protocol`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `snippet_access` (
|
||||||
|
`id` int AUTO_INCREMENT NOT NULL,
|
||||||
|
`snippet_id` int NOT NULL,
|
||||||
|
`user_id` varchar(255),
|
||||||
|
`role_id` int,
|
||||||
|
`granted_by` varchar(255) NOT NULL,
|
||||||
|
`permission_level` text NOT NULL DEFAULT ('view'),
|
||||||
|
`expires_at` text,
|
||||||
|
`created_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
CONSTRAINT `snippet_access_id` PRIMARY KEY(`id`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `snippet_folders` (
|
||||||
|
`id` int AUTO_INCREMENT NOT NULL,
|
||||||
|
`user_id` varchar(255) NOT NULL,
|
||||||
|
`name` varchar(255) NOT NULL,
|
||||||
|
`color` text,
|
||||||
|
`icon` text,
|
||||||
|
`sync_id` varchar(255),
|
||||||
|
`created_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
`updated_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
CONSTRAINT `snippet_folders_id` PRIMARY KEY(`id`),
|
||||||
|
CONSTRAINT `snippet_folders_sync_id_unique` UNIQUE(`sync_id`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `snippets` (
|
||||||
|
`id` int AUTO_INCREMENT NOT NULL,
|
||||||
|
`user_id` varchar(255) NOT NULL,
|
||||||
|
`name` varchar(255) NOT NULL,
|
||||||
|
`content` text NOT NULL,
|
||||||
|
`description` text,
|
||||||
|
`folder` text,
|
||||||
|
`order` int NOT NULL DEFAULT 0,
|
||||||
|
`sync_id` varchar(255),
|
||||||
|
`created_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
`updated_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
`host_filter` text,
|
||||||
|
CONSTRAINT `snippets_id` PRIMARY KEY(`id`),
|
||||||
|
CONSTRAINT `snippets_sync_id_unique` UNIQUE(`sync_id`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `ssh_credential_usage` (
|
||||||
|
`id` int AUTO_INCREMENT NOT NULL,
|
||||||
|
`credential_id` int NOT NULL,
|
||||||
|
`host_id` int NOT NULL,
|
||||||
|
`user_id` varchar(255) NOT NULL,
|
||||||
|
`used_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
CONSTRAINT `ssh_credential_usage_id` PRIMARY KEY(`id`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `ssh_credentials` (
|
||||||
|
`id` int AUTO_INCREMENT NOT NULL,
|
||||||
|
`user_id` varchar(255) NOT NULL,
|
||||||
|
`name` varchar(255) NOT NULL,
|
||||||
|
`description` text,
|
||||||
|
`folder` text,
|
||||||
|
`tags` text,
|
||||||
|
`auth_type` text NOT NULL,
|
||||||
|
`username` text,
|
||||||
|
`password` text,
|
||||||
|
`key` text,
|
||||||
|
`private_key` text,
|
||||||
|
`public_key` text,
|
||||||
|
`key_password` text,
|
||||||
|
`key_type` text,
|
||||||
|
`detected_key_type` text,
|
||||||
|
`cert_public_key` text,
|
||||||
|
`usage_count` int NOT NULL DEFAULT 0,
|
||||||
|
`last_used` text,
|
||||||
|
`sync_id` varchar(255),
|
||||||
|
`created_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
`updated_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
CONSTRAINT `ssh_credentials_id` PRIMARY KEY(`id`),
|
||||||
|
CONSTRAINT `ssh_credentials_sync_id_unique` UNIQUE(`sync_id`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `ssh_folders` (
|
||||||
|
`id` int AUTO_INCREMENT NOT NULL,
|
||||||
|
`user_id` varchar(255) NOT NULL,
|
||||||
|
`name` varchar(255) NOT NULL,
|
||||||
|
`color` text,
|
||||||
|
`icon` text,
|
||||||
|
`credential_id` int,
|
||||||
|
`sync_id` varchar(255),
|
||||||
|
`created_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
`updated_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
CONSTRAINT `ssh_folders_id` PRIMARY KEY(`id`),
|
||||||
|
CONSTRAINT `ssh_folders_sync_id_unique` UNIQUE(`sync_id`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `sso_providers` (
|
||||||
|
`id` int AUTO_INCREMENT NOT NULL,
|
||||||
|
`name` varchar(255) NOT NULL,
|
||||||
|
`type` text NOT NULL,
|
||||||
|
`enabled` boolean NOT NULL DEFAULT true,
|
||||||
|
`display_order` int NOT NULL DEFAULT 0,
|
||||||
|
`config` text NOT NULL,
|
||||||
|
`created_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
`updated_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
CONSTRAINT `sso_providers_id` PRIMARY KEY(`id`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `sync_tombstones` (
|
||||||
|
`id` int AUTO_INCREMENT NOT NULL,
|
||||||
|
`user_id` varchar(255) NOT NULL,
|
||||||
|
`entity_type` text NOT NULL,
|
||||||
|
`sync_id` varchar(255) NOT NULL,
|
||||||
|
`deleted_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
CONSTRAINT `sync_tombstones_id` PRIMARY KEY(`id`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `termix_identities` (
|
||||||
|
`id` int AUTO_INCREMENT NOT NULL,
|
||||||
|
`user_id` varchar(255) NOT NULL,
|
||||||
|
`handle` varchar(255) NOT NULL,
|
||||||
|
`description` text,
|
||||||
|
`created_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
`updated_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
CONSTRAINT `termix_identities_id` PRIMARY KEY(`id`),
|
||||||
|
CONSTRAINT `termix_identities_user_id_unique` UNIQUE(`user_id`),
|
||||||
|
CONSTRAINT `termix_identities_handle_unique` UNIQUE(`handle`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `termix_identity_ca` (
|
||||||
|
`id` int AUTO_INCREMENT NOT NULL,
|
||||||
|
`identity_id` int NOT NULL,
|
||||||
|
`user_id` varchar(255) NOT NULL,
|
||||||
|
`public_key` text NOT NULL,
|
||||||
|
`private_key` text NOT NULL,
|
||||||
|
`validity_days` int NOT NULL DEFAULT 90,
|
||||||
|
`created_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
`updated_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
CONSTRAINT `termix_identity_ca_id` PRIMARY KEY(`id`),
|
||||||
|
CONSTRAINT `termix_identity_ca_identity_id_unique` UNIQUE(`identity_id`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `termix_identity_keys` (
|
||||||
|
`id` int AUTO_INCREMENT NOT NULL,
|
||||||
|
`identity_id` int NOT NULL,
|
||||||
|
`user_id` varchar(255) NOT NULL,
|
||||||
|
`public_key` text NOT NULL,
|
||||||
|
`key_type` text NOT NULL,
|
||||||
|
`algorithm` text NOT NULL,
|
||||||
|
`label` text,
|
||||||
|
`comment` text,
|
||||||
|
`source` text NOT NULL DEFAULT ('manual'),
|
||||||
|
`credential_id` int,
|
||||||
|
`enabled` boolean NOT NULL DEFAULT true,
|
||||||
|
`created_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
CONSTRAINT `termix_identity_keys_id` PRIMARY KEY(`id`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `tmux_session_tags` (
|
||||||
|
`id` int AUTO_INCREMENT NOT NULL,
|
||||||
|
`user_id` varchar(255) NOT NULL,
|
||||||
|
`host_id` int NOT NULL,
|
||||||
|
`session_name` text NOT NULL,
|
||||||
|
`tag` text NOT NULL,
|
||||||
|
`created_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
CONSTRAINT `tmux_session_tags_id` PRIMARY KEY(`id`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `transfer_recent` (
|
||||||
|
`id` int AUTO_INCREMENT NOT NULL,
|
||||||
|
`user_id` varchar(255) NOT NULL,
|
||||||
|
`source_host_id` int NOT NULL,
|
||||||
|
`dest_host_id` int NOT NULL,
|
||||||
|
`dest_path` text NOT NULL,
|
||||||
|
`dest_path_label` text NOT NULL,
|
||||||
|
`last_used` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
CONSTRAINT `transfer_recent_id` PRIMARY KEY(`id`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `trusted_devices` (
|
||||||
|
`id` varchar(255) NOT NULL,
|
||||||
|
`user_id` varchar(255) NOT NULL,
|
||||||
|
`device_fingerprint` text NOT NULL,
|
||||||
|
`device_type` text NOT NULL,
|
||||||
|
`device_info` text NOT NULL,
|
||||||
|
`created_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
`expires_at` text NOT NULL,
|
||||||
|
`last_used_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
CONSTRAINT `trusted_devices_id` PRIMARY KEY(`id`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `user_open_tabs` (
|
||||||
|
`id` varchar(255) NOT NULL,
|
||||||
|
`user_id` varchar(255) NOT NULL,
|
||||||
|
`tab_type` text NOT NULL,
|
||||||
|
`host_id` int,
|
||||||
|
`label` text NOT NULL,
|
||||||
|
`tab_order` int NOT NULL DEFAULT 0,
|
||||||
|
`backend_session_id` text,
|
||||||
|
`created_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
`updated_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
CONSTRAINT `user_open_tabs_id` PRIMARY KEY(`id`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `user_preferences` (
|
||||||
|
`user_id` varchar(255) NOT NULL,
|
||||||
|
`reopen_tabs_on_login` boolean NOT NULL DEFAULT false,
|
||||||
|
`theme` text,
|
||||||
|
`font_size` text,
|
||||||
|
`accent_color` text,
|
||||||
|
`language` text,
|
||||||
|
`storage_mode` text,
|
||||||
|
`command_autocomplete` boolean,
|
||||||
|
`command_palette_enabled` boolean,
|
||||||
|
`show_host_tags` boolean,
|
||||||
|
`host_tray_on_click` boolean,
|
||||||
|
`pin_app_rail` boolean,
|
||||||
|
`expand_app_rail_on_hover` boolean,
|
||||||
|
`folders_collapsed` boolean,
|
||||||
|
`confirm_snippet_execution` boolean,
|
||||||
|
`disable_update_check` boolean,
|
||||||
|
`confirm_tab_close` boolean,
|
||||||
|
`hidden_rail_tabs` text,
|
||||||
|
`compact_host_view` boolean,
|
||||||
|
`status_color_scheme` text,
|
||||||
|
`custom_themes` text,
|
||||||
|
`custom_keybindings` text,
|
||||||
|
`updated_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
CONSTRAINT `user_preferences_user_id` PRIMARY KEY(`user_id`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `user_roles` (
|
||||||
|
`id` int AUTO_INCREMENT NOT NULL,
|
||||||
|
`user_id` varchar(255) NOT NULL,
|
||||||
|
`role_id` int NOT NULL,
|
||||||
|
`granted_by` varchar(255),
|
||||||
|
`granted_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
CONSTRAINT `user_roles_id` PRIMARY KEY(`id`),
|
||||||
|
CONSTRAINT `idx_user_roles_user_role` UNIQUE(`user_id`,`role_id`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `users` (
|
||||||
|
`id` varchar(255) NOT NULL,
|
||||||
|
`username` text NOT NULL,
|
||||||
|
`password_hash` text NOT NULL,
|
||||||
|
`is_admin` boolean NOT NULL DEFAULT false,
|
||||||
|
`is_oidc` boolean NOT NULL DEFAULT false,
|
||||||
|
`oidc_identifier` text,
|
||||||
|
`sso_provider_id` int,
|
||||||
|
`client_id` text,
|
||||||
|
`client_secret` text,
|
||||||
|
`issuer_url` text,
|
||||||
|
`authorization_url` text,
|
||||||
|
`token_url` text,
|
||||||
|
`identifier_path` text,
|
||||||
|
`name_path` text,
|
||||||
|
`scopes` text DEFAULT ('openid email profile'),
|
||||||
|
`totp_secret` text,
|
||||||
|
`totp_enabled` boolean NOT NULL DEFAULT false,
|
||||||
|
`totp_backup_codes` text,
|
||||||
|
`registered_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
`donation_modal_dismissed` boolean NOT NULL DEFAULT false,
|
||||||
|
CONSTRAINT `users_id` PRIMARY KEY(`id`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `vault_profiles` (
|
||||||
|
`id` int AUTO_INCREMENT NOT NULL,
|
||||||
|
`user_id` varchar(255) NOT NULL,
|
||||||
|
`name` varchar(255) NOT NULL,
|
||||||
|
`description` text,
|
||||||
|
`folder` text,
|
||||||
|
`tags` text,
|
||||||
|
`vault_addr` text NOT NULL,
|
||||||
|
`vault_namespace` text,
|
||||||
|
`oidc_mount` text,
|
||||||
|
`oidc_role` text,
|
||||||
|
`ssh_mount` text,
|
||||||
|
`ssh_role` text NOT NULL,
|
||||||
|
`valid_principals` text,
|
||||||
|
`key_type` text,
|
||||||
|
`shared` boolean NOT NULL DEFAULT false,
|
||||||
|
`sync_id` varchar(255),
|
||||||
|
`created_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
`updated_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
CONSTRAINT `vault_profiles_id` PRIMARY KEY(`id`),
|
||||||
|
CONSTRAINT `vault_profiles_sync_id_unique` UNIQUE(`sync_id`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `vault_tokens` (
|
||||||
|
`id` int AUTO_INCREMENT NOT NULL,
|
||||||
|
`user_id` varchar(255) NOT NULL,
|
||||||
|
`profile_id` int NOT NULL,
|
||||||
|
`ssh_cert` text NOT NULL,
|
||||||
|
`private_key` text NOT NULL,
|
||||||
|
`created_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
`expires_at` text NOT NULL,
|
||||||
|
`last_used` text,
|
||||||
|
CONSTRAINT `vault_tokens_id` PRIMARY KEY(`id`),
|
||||||
|
CONSTRAINT `idx_vault_tokens_user_profile` UNIQUE(`user_id`,`profile_id`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `webauthn_credentials` (
|
||||||
|
`id` varchar(255) NOT NULL,
|
||||||
|
`user_id` varchar(255) NOT NULL,
|
||||||
|
`name` varchar(255) NOT NULL,
|
||||||
|
`credential_id` text NOT NULL,
|
||||||
|
`public_key` text NOT NULL,
|
||||||
|
`counter` int NOT NULL DEFAULT 0,
|
||||||
|
`device_type` text,
|
||||||
|
`backed_up` boolean NOT NULL DEFAULT false,
|
||||||
|
`transports` text,
|
||||||
|
`user_verification` text NOT NULL DEFAULT ('preferred'),
|
||||||
|
`created_at` text NOT NULL DEFAULT (CURRENT_TIMESTAMP),
|
||||||
|
`last_used_at` text,
|
||||||
|
CONSTRAINT `webauthn_credentials_id` PRIMARY KEY(`id`)
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
ALTER TABLE `alert_firings` ADD CONSTRAINT `alert_firings_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `alert_firings` ADD CONSTRAINT `alert_firings_rule_id_alert_rules_id_fk` FOREIGN KEY (`rule_id`) REFERENCES `alert_rules`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `alert_rule_channels` ADD CONSTRAINT `alert_rule_channels_rule_id_alert_rules_id_fk` FOREIGN KEY (`rule_id`) REFERENCES `alert_rules`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `alert_rule_channels` ADD CONSTRAINT `alert_rule_channels_channel_id_notification_channels_id_fk` FOREIGN KEY (`channel_id`) REFERENCES `notification_channels`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `alert_rules` ADD CONSTRAINT `alert_rules_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `alert_rules` ADD CONSTRAINT `alert_rules_host_id_ssh_data_id_fk` FOREIGN KEY (`host_id`) REFERENCES `ssh_data`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `api_keys` ADD CONSTRAINT `api_keys_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `audit_logs` ADD CONSTRAINT `audit_logs_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE set null ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `c2s_tunnel_presets` ADD CONSTRAINT `c2s_tunnel_presets_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `command_history` ADD CONSTRAINT `command_history_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `command_history` ADD CONSTRAINT `command_history_host_id_ssh_data_id_fk` FOREIGN KEY (`host_id`) REFERENCES `ssh_data`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `dashboard_service_links` ADD CONSTRAINT `dashboard_service_links_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `dismissed_alerts` ADD CONSTRAINT `dismissed_alerts_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `file_manager_pinned` ADD CONSTRAINT `file_manager_pinned_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `file_manager_pinned` ADD CONSTRAINT `file_manager_pinned_host_id_ssh_data_id_fk` FOREIGN KEY (`host_id`) REFERENCES `ssh_data`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `file_manager_recent` ADD CONSTRAINT `file_manager_recent_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `file_manager_recent` ADD CONSTRAINT `file_manager_recent_host_id_ssh_data_id_fk` FOREIGN KEY (`host_id`) REFERENCES `ssh_data`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `file_manager_shortcuts` ADD CONSTRAINT `file_manager_shortcuts_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `file_manager_shortcuts` ADD CONSTRAINT `file_manager_shortcuts_host_id_ssh_data_id_fk` FOREIGN KEY (`host_id`) REFERENCES `ssh_data`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `homepage_items` ADD CONSTRAINT `homepage_items_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `homepage_layouts` ADD CONSTRAINT `homepage_layouts_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `host_access` ADD CONSTRAINT `host_access_host_id_ssh_data_id_fk` FOREIGN KEY (`host_id`) REFERENCES `ssh_data`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `host_access` ADD CONSTRAINT `host_access_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `host_access` ADD CONSTRAINT `host_access_role_id_roles_id_fk` FOREIGN KEY (`role_id`) REFERENCES `roles`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `host_access` ADD CONSTRAINT `host_access_granted_by_users_id_fk` FOREIGN KEY (`granted_by`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `host_health_checks` ADD CONSTRAINT `host_health_checks_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `host_health_checks` ADD CONSTRAINT `host_health_checks_host_id_ssh_data_id_fk` FOREIGN KEY (`host_id`) REFERENCES `ssh_data`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `host_health_history` ADD CONSTRAINT `host_health_history_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `host_health_history` ADD CONSTRAINT `host_health_history_host_id_ssh_data_id_fk` FOREIGN KEY (`host_id`) REFERENCES `ssh_data`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `host_metrics_history` ADD CONSTRAINT `host_metrics_history_host_id_ssh_data_id_fk` FOREIGN KEY (`host_id`) REFERENCES `ssh_data`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `host_metrics_preferences` ADD CONSTRAINT `host_metrics_preferences_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `host_metrics_preferences` ADD CONSTRAINT `host_metrics_preferences_host_id_ssh_data_id_fk` FOREIGN KEY (`host_id`) REFERENCES `ssh_data`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `ssh_data` ADD CONSTRAINT `ssh_data_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `ssh_data` ADD CONSTRAINT `ssh_data_credential_id_ssh_credentials_id_fk` FOREIGN KEY (`credential_id`) REFERENCES `ssh_credentials`(`id`) ON DELETE set null ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `ssh_data` ADD CONSTRAINT `ssh_data_vault_profile_id_vault_profiles_id_fk` FOREIGN KEY (`vault_profile_id`) REFERENCES `vault_profiles`(`id`) ON DELETE set null ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `ssh_data` ADD CONSTRAINT `ssh_data_rdp_credential_id_ssh_credentials_id_fk` FOREIGN KEY (`rdp_credential_id`) REFERENCES `ssh_credentials`(`id`) ON DELETE set null ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `ssh_data` ADD CONSTRAINT `ssh_data_vnc_credential_id_ssh_credentials_id_fk` FOREIGN KEY (`vnc_credential_id`) REFERENCES `ssh_credentials`(`id`) ON DELETE set null ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `ssh_data` ADD CONSTRAINT `ssh_data_telnet_credential_id_ssh_credentials_id_fk` FOREIGN KEY (`telnet_credential_id`) REFERENCES `ssh_credentials`(`id`) ON DELETE set null ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `network_topology` ADD CONSTRAINT `network_topology_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `notification_channels` ADD CONSTRAINT `notification_channels_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `opkssh_tokens` ADD CONSTRAINT `opkssh_tokens_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `opkssh_tokens` ADD CONSTRAINT `opkssh_tokens_host_id_ssh_data_id_fk` FOREIGN KEY (`host_id`) REFERENCES `ssh_data`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `recent_activity` ADD CONSTRAINT `recent_activity_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `recent_activity` ADD CONSTRAINT `recent_activity_host_id_ssh_data_id_fk` FOREIGN KEY (`host_id`) REFERENCES `ssh_data`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `session_recordings` ADD CONSTRAINT `session_recordings_host_id_ssh_data_id_fk` FOREIGN KEY (`host_id`) REFERENCES `ssh_data`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `session_recordings` ADD CONSTRAINT `session_recordings_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE set null ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `session_recordings` ADD CONSTRAINT `session_recordings_access_id_host_access_id_fk` FOREIGN KEY (`access_id`) REFERENCES `host_access`(`id`) ON DELETE set null ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `session_share_participants` ADD CONSTRAINT `session_share_participants_share_id_session_shares_id_fk` FOREIGN KEY (`share_id`) REFERENCES `session_shares`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `session_share_participants` ADD CONSTRAINT `session_share_participants_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `session_shares` ADD CONSTRAINT `session_shares_host_id_ssh_data_id_fk` FOREIGN KEY (`host_id`) REFERENCES `ssh_data`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `session_shares` ADD CONSTRAINT `session_shares_owner_user_id_users_id_fk` FOREIGN KEY (`owner_user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `session_shares` ADD CONSTRAINT `session_shares_target_user_id_users_id_fk` FOREIGN KEY (`target_user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `sessions` ADD CONSTRAINT `sessions_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `shared_host_auth_overrides` ADD CONSTRAINT `shared_host_auth_overrides_host_id_ssh_data_id_fk` FOREIGN KEY (`host_id`) REFERENCES `ssh_data`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `shared_host_auth_overrides` ADD CONSTRAINT `shared_host_auth_overrides_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `shared_host_auth_overrides` ADD CONSTRAINT `shared_host_auth_overrides_credential_id_ssh_credentials_id_fk` FOREIGN KEY (`credential_id`) REFERENCES `ssh_credentials`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `shared_host_secrets` ADD CONSTRAINT `shared_host_secrets_host_access_id_host_access_id_fk` FOREIGN KEY (`host_access_id`) REFERENCES `host_access`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `shared_host_secrets` ADD CONSTRAINT `shared_host_secrets_target_user_id_users_id_fk` FOREIGN KEY (`target_user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `shared_host_secrets` ADD CONSTRAINT `shared_host_secrets_original_credential_id_ssh_credentials_id_fk` FOREIGN KEY (`original_credential_id`) REFERENCES `ssh_credentials`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `snippet_access` ADD CONSTRAINT `snippet_access_snippet_id_snippets_id_fk` FOREIGN KEY (`snippet_id`) REFERENCES `snippets`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `snippet_access` ADD CONSTRAINT `snippet_access_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `snippet_access` ADD CONSTRAINT `snippet_access_role_id_roles_id_fk` FOREIGN KEY (`role_id`) REFERENCES `roles`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `snippet_access` ADD CONSTRAINT `snippet_access_granted_by_users_id_fk` FOREIGN KEY (`granted_by`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `snippet_folders` ADD CONSTRAINT `snippet_folders_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `snippets` ADD CONSTRAINT `snippets_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `ssh_credential_usage` ADD CONSTRAINT `ssh_credential_usage_credential_id_ssh_credentials_id_fk` FOREIGN KEY (`credential_id`) REFERENCES `ssh_credentials`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `ssh_credential_usage` ADD CONSTRAINT `ssh_credential_usage_host_id_ssh_data_id_fk` FOREIGN KEY (`host_id`) REFERENCES `ssh_data`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `ssh_credential_usage` ADD CONSTRAINT `ssh_credential_usage_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `ssh_credentials` ADD CONSTRAINT `ssh_credentials_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `ssh_folders` ADD CONSTRAINT `ssh_folders_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `ssh_folders` ADD CONSTRAINT `ssh_folders_credential_id_ssh_credentials_id_fk` FOREIGN KEY (`credential_id`) REFERENCES `ssh_credentials`(`id`) ON DELETE set null ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `sync_tombstones` ADD CONSTRAINT `sync_tombstones_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `termix_identities` ADD CONSTRAINT `termix_identities_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `termix_identity_ca` ADD CONSTRAINT `termix_identity_ca_identity_id_termix_identities_id_fk` FOREIGN KEY (`identity_id`) REFERENCES `termix_identities`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `termix_identity_ca` ADD CONSTRAINT `termix_identity_ca_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `termix_identity_keys` ADD CONSTRAINT `termix_identity_keys_identity_id_termix_identities_id_fk` FOREIGN KEY (`identity_id`) REFERENCES `termix_identities`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `termix_identity_keys` ADD CONSTRAINT `termix_identity_keys_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `termix_identity_keys` ADD CONSTRAINT `termix_identity_keys_credential_id_ssh_credentials_id_fk` FOREIGN KEY (`credential_id`) REFERENCES `ssh_credentials`(`id`) ON DELETE set null ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `tmux_session_tags` ADD CONSTRAINT `tmux_session_tags_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `tmux_session_tags` ADD CONSTRAINT `tmux_session_tags_host_id_ssh_data_id_fk` FOREIGN KEY (`host_id`) REFERENCES `ssh_data`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `transfer_recent` ADD CONSTRAINT `transfer_recent_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `transfer_recent` ADD CONSTRAINT `transfer_recent_source_host_id_ssh_data_id_fk` FOREIGN KEY (`source_host_id`) REFERENCES `ssh_data`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `transfer_recent` ADD CONSTRAINT `transfer_recent_dest_host_id_ssh_data_id_fk` FOREIGN KEY (`dest_host_id`) REFERENCES `ssh_data`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `trusted_devices` ADD CONSTRAINT `trusted_devices_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `user_open_tabs` ADD CONSTRAINT `user_open_tabs_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `user_open_tabs` ADD CONSTRAINT `user_open_tabs_host_id_ssh_data_id_fk` FOREIGN KEY (`host_id`) REFERENCES `ssh_data`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `user_preferences` ADD CONSTRAINT `user_preferences_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `user_roles` ADD CONSTRAINT `user_roles_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `user_roles` ADD CONSTRAINT `user_roles_role_id_roles_id_fk` FOREIGN KEY (`role_id`) REFERENCES `roles`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `user_roles` ADD CONSTRAINT `user_roles_granted_by_users_id_fk` FOREIGN KEY (`granted_by`) REFERENCES `users`(`id`) ON DELETE set null ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `vault_profiles` ADD CONSTRAINT `vault_profiles_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `vault_tokens` ADD CONSTRAINT `vault_tokens_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `vault_tokens` ADD CONSTRAINT `vault_tokens_profile_id_vault_profiles_id_fk` FOREIGN KEY (`profile_id`) REFERENCES `vault_profiles`(`id`) ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE `webauthn_credentials` ADD CONSTRAINT `webauthn_credentials_user_id_users_id_fk` FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON DELETE cascade ON UPDATE no action;
|
||||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,13 @@
|
|||||||
|
{
|
||||||
|
"version": "7",
|
||||||
|
"dialect": "mysql",
|
||||||
|
"entries": [
|
||||||
|
{
|
||||||
|
"idx": 0,
|
||||||
|
"version": "5",
|
||||||
|
"when": 1785738871436,
|
||||||
|
"tag": "0000_clean_pretty_boy",
|
||||||
|
"breakpoints": true
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
@@ -0,0 +1,837 @@
|
|||||||
|
CREATE TABLE "alert_firings" (
|
||||||
|
"id" serial PRIMARY KEY NOT NULL,
|
||||||
|
"user_id" varchar(255) NOT NULL,
|
||||||
|
"rule_id" integer NOT NULL,
|
||||||
|
"host_id" integer NOT NULL,
|
||||||
|
"host_name" text NOT NULL,
|
||||||
|
"fired_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
"resolved_at" text,
|
||||||
|
"value" double precision,
|
||||||
|
"message" text NOT NULL,
|
||||||
|
"severity" text DEFAULT 'warning' NOT NULL,
|
||||||
|
"acknowledged" boolean DEFAULT false NOT NULL
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "alert_rule_channels" (
|
||||||
|
"id" serial PRIMARY KEY NOT NULL,
|
||||||
|
"rule_id" integer NOT NULL,
|
||||||
|
"channel_id" integer NOT NULL
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "alert_rules" (
|
||||||
|
"id" serial PRIMARY KEY NOT NULL,
|
||||||
|
"user_id" varchar(255) NOT NULL,
|
||||||
|
"host_id" integer,
|
||||||
|
"name" varchar(255) NOT NULL,
|
||||||
|
"enabled" boolean DEFAULT true NOT NULL,
|
||||||
|
"trigger_type" text NOT NULL,
|
||||||
|
"threshold_value" double precision,
|
||||||
|
"threshold_duration_seconds" integer,
|
||||||
|
"cooldown_minutes" integer DEFAULT 15 NOT NULL,
|
||||||
|
"created_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
"updated_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "api_keys" (
|
||||||
|
"id" varchar(255) PRIMARY KEY NOT NULL,
|
||||||
|
"user_id" varchar(255) NOT NULL,
|
||||||
|
"name" varchar(255) NOT NULL,
|
||||||
|
"token_hash" text NOT NULL,
|
||||||
|
"token_prefix" text NOT NULL,
|
||||||
|
"created_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
"expires_at" text,
|
||||||
|
"last_used_at" text,
|
||||||
|
"is_active" boolean DEFAULT true NOT NULL
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "audit_logs" (
|
||||||
|
"id" serial PRIMARY KEY NOT NULL,
|
||||||
|
"user_id" varchar(255),
|
||||||
|
"username" text NOT NULL,
|
||||||
|
"action" text NOT NULL,
|
||||||
|
"resource_type" text NOT NULL,
|
||||||
|
"resource_id" text,
|
||||||
|
"resource_name" text,
|
||||||
|
"details" text,
|
||||||
|
"ip_address" text,
|
||||||
|
"user_agent" text,
|
||||||
|
"success" boolean NOT NULL,
|
||||||
|
"error_message" text,
|
||||||
|
"timestamp" text DEFAULT CURRENT_TIMESTAMP NOT NULL
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "c2s_tunnel_presets" (
|
||||||
|
"id" serial PRIMARY KEY NOT NULL,
|
||||||
|
"user_id" varchar(255) NOT NULL,
|
||||||
|
"name" varchar(255) NOT NULL,
|
||||||
|
"config" text NOT NULL,
|
||||||
|
"platform" text,
|
||||||
|
"computer_name" text,
|
||||||
|
"created_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
"updated_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "command_history" (
|
||||||
|
"id" serial PRIMARY KEY NOT NULL,
|
||||||
|
"user_id" varchar(255) NOT NULL,
|
||||||
|
"host_id" integer NOT NULL,
|
||||||
|
"command" text NOT NULL,
|
||||||
|
"executed_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "dashboard_service_links" (
|
||||||
|
"id" serial PRIMARY KEY NOT NULL,
|
||||||
|
"user_id" varchar(255) NOT NULL,
|
||||||
|
"label" text NOT NULL,
|
||||||
|
"url" text NOT NULL,
|
||||||
|
"order" integer DEFAULT 0 NOT NULL,
|
||||||
|
"sync_id" varchar(255),
|
||||||
|
"created_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
"updated_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
CONSTRAINT "dashboard_service_links_sync_id_unique" UNIQUE("sync_id")
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "dismissed_alerts" (
|
||||||
|
"id" serial PRIMARY KEY NOT NULL,
|
||||||
|
"user_id" varchar(255) NOT NULL,
|
||||||
|
"alert_id" text NOT NULL,
|
||||||
|
"dismissed_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "file_manager_pinned" (
|
||||||
|
"id" serial PRIMARY KEY NOT NULL,
|
||||||
|
"user_id" varchar(255) NOT NULL,
|
||||||
|
"host_id" integer NOT NULL,
|
||||||
|
"name" varchar(255) NOT NULL,
|
||||||
|
"path" text NOT NULL,
|
||||||
|
"pinned_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "file_manager_recent" (
|
||||||
|
"id" serial PRIMARY KEY NOT NULL,
|
||||||
|
"user_id" varchar(255) NOT NULL,
|
||||||
|
"host_id" integer NOT NULL,
|
||||||
|
"name" varchar(255) NOT NULL,
|
||||||
|
"path" text NOT NULL,
|
||||||
|
"last_opened" text DEFAULT CURRENT_TIMESTAMP NOT NULL
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "file_manager_shortcuts" (
|
||||||
|
"id" serial PRIMARY KEY NOT NULL,
|
||||||
|
"user_id" varchar(255) NOT NULL,
|
||||||
|
"host_id" integer NOT NULL,
|
||||||
|
"name" varchar(255) NOT NULL,
|
||||||
|
"path" text NOT NULL,
|
||||||
|
"created_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "homepage_items" (
|
||||||
|
"id" serial PRIMARY KEY NOT NULL,
|
||||||
|
"user_id" varchar(255) NOT NULL,
|
||||||
|
"type_id" text NOT NULL,
|
||||||
|
"title" text,
|
||||||
|
"config" text DEFAULT '{}' NOT NULL,
|
||||||
|
"folder_id" integer,
|
||||||
|
"sync_id" varchar(255),
|
||||||
|
"created_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
"updated_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
CONSTRAINT "homepage_items_sync_id_unique" UNIQUE("sync_id")
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "homepage_layouts" (
|
||||||
|
"id" serial PRIMARY KEY NOT NULL,
|
||||||
|
"user_id" varchar(255) NOT NULL,
|
||||||
|
"layout" text DEFAULT '{}' NOT NULL,
|
||||||
|
"updated_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
CONSTRAINT "homepage_layouts_user_id_unique" UNIQUE("user_id")
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "host_access" (
|
||||||
|
"id" serial PRIMARY KEY NOT NULL,
|
||||||
|
"host_id" integer NOT NULL,
|
||||||
|
"user_id" varchar(255),
|
||||||
|
"role_id" integer,
|
||||||
|
"granted_by" varchar(255) NOT NULL,
|
||||||
|
"permission_level" text DEFAULT 'connect' NOT NULL,
|
||||||
|
"expires_at" text,
|
||||||
|
"created_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
"last_accessed_at" text,
|
||||||
|
"access_count" integer DEFAULT 0 NOT NULL
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "host_health_checks" (
|
||||||
|
"id" serial PRIMARY KEY NOT NULL,
|
||||||
|
"user_id" varchar(255) NOT NULL,
|
||||||
|
"host_id" integer NOT NULL,
|
||||||
|
"checks" text NOT NULL,
|
||||||
|
"interval_seconds" integer DEFAULT 300 NOT NULL,
|
||||||
|
"created_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
"updated_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "host_health_history" (
|
||||||
|
"id" serial PRIMARY KEY NOT NULL,
|
||||||
|
"user_id" varchar(255) NOT NULL,
|
||||||
|
"host_id" integer NOT NULL,
|
||||||
|
"check_id" text NOT NULL,
|
||||||
|
"ts" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
"ok" boolean NOT NULL,
|
||||||
|
"latency_ms" integer,
|
||||||
|
"detail" text
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "host_metrics_history" (
|
||||||
|
"id" serial PRIMARY KEY NOT NULL,
|
||||||
|
"host_id" integer NOT NULL,
|
||||||
|
"ts" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
"cpu_percent" double precision,
|
||||||
|
"mem_percent" double precision,
|
||||||
|
"disk_percent" double precision,
|
||||||
|
"net_rx_bytes" integer,
|
||||||
|
"net_tx_bytes" integer
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "host_metrics_preferences" (
|
||||||
|
"id" serial PRIMARY KEY NOT NULL,
|
||||||
|
"user_id" varchar(255) NOT NULL,
|
||||||
|
"host_id" integer NOT NULL,
|
||||||
|
"layout" text NOT NULL,
|
||||||
|
"created_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
"updated_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "ssh_data" (
|
||||||
|
"id" serial PRIMARY KEY NOT NULL,
|
||||||
|
"user_id" varchar(255) NOT NULL,
|
||||||
|
"connection_type" text DEFAULT 'ssh' NOT NULL,
|
||||||
|
"name" varchar(255),
|
||||||
|
"ip" text NOT NULL,
|
||||||
|
"port" integer NOT NULL,
|
||||||
|
"username" text NOT NULL,
|
||||||
|
"folder" text,
|
||||||
|
"tags" text,
|
||||||
|
"pin" boolean DEFAULT false NOT NULL,
|
||||||
|
"auth_type" text NOT NULL,
|
||||||
|
"use_warpgate" boolean DEFAULT false NOT NULL,
|
||||||
|
"share_ssh_auth" boolean DEFAULT false NOT NULL,
|
||||||
|
"force_keyboard_interactive" text,
|
||||||
|
"password" text,
|
||||||
|
"key" text,
|
||||||
|
"key_password" text,
|
||||||
|
"key_type" text,
|
||||||
|
"sudo_password" text,
|
||||||
|
"autostart_password" text,
|
||||||
|
"autostart_key" text,
|
||||||
|
"autostart_key_password" text,
|
||||||
|
"credential_id" integer,
|
||||||
|
"override_credential_username" boolean,
|
||||||
|
"vault_profile_id" integer,
|
||||||
|
"enable_terminal" boolean DEFAULT true NOT NULL,
|
||||||
|
"enable_session_logging" boolean DEFAULT true NOT NULL,
|
||||||
|
"allow_session_sharing" boolean DEFAULT true NOT NULL,
|
||||||
|
"enable_command_history" boolean DEFAULT true NOT NULL,
|
||||||
|
"enable_tunnel" boolean DEFAULT true NOT NULL,
|
||||||
|
"tunnel_connections" text,
|
||||||
|
"jump_hosts" text,
|
||||||
|
"enable_file_manager" boolean DEFAULT true NOT NULL,
|
||||||
|
"scp_legacy" boolean DEFAULT false NOT NULL,
|
||||||
|
"enable_docker" boolean DEFAULT false NOT NULL,
|
||||||
|
"enable_tmux_monitor" boolean DEFAULT false NOT NULL,
|
||||||
|
"show_terminal_in_sidebar" boolean DEFAULT true NOT NULL,
|
||||||
|
"show_file_manager_in_sidebar" boolean DEFAULT false NOT NULL,
|
||||||
|
"show_tunnel_in_sidebar" boolean DEFAULT false NOT NULL,
|
||||||
|
"show_docker_in_sidebar" boolean DEFAULT false NOT NULL,
|
||||||
|
"show_server_stats_in_sidebar" boolean DEFAULT false NOT NULL,
|
||||||
|
"default_path" text,
|
||||||
|
"stats_config" text,
|
||||||
|
"docker_config" text,
|
||||||
|
"enable_proxmox" boolean DEFAULT false NOT NULL,
|
||||||
|
"proxmox_config" text,
|
||||||
|
"terminal_config" text,
|
||||||
|
"quick_actions" text,
|
||||||
|
"notes" text,
|
||||||
|
"enable_ssh" boolean DEFAULT true NOT NULL,
|
||||||
|
"enable_rdp" boolean DEFAULT false NOT NULL,
|
||||||
|
"enable_vnc" boolean DEFAULT false NOT NULL,
|
||||||
|
"enable_telnet" boolean DEFAULT false NOT NULL,
|
||||||
|
"ssh_port" integer DEFAULT 22,
|
||||||
|
"rdp_port" integer DEFAULT 3389,
|
||||||
|
"vnc_port" integer DEFAULT 5900,
|
||||||
|
"telnet_port" integer DEFAULT 23,
|
||||||
|
"rdp_credential_id" integer,
|
||||||
|
"rdp_user" text,
|
||||||
|
"rdp_password" text,
|
||||||
|
"rdp_domain" text,
|
||||||
|
"rdp_security" text,
|
||||||
|
"rdp_ignore_cert" boolean DEFAULT false,
|
||||||
|
"vnc_credential_id" integer,
|
||||||
|
"vnc_password" text,
|
||||||
|
"vnc_user" text,
|
||||||
|
"telnet_user" text,
|
||||||
|
"telnet_password" text,
|
||||||
|
"telnet_credential_id" integer,
|
||||||
|
"rdp_auth_type" text,
|
||||||
|
"vnc_auth_type" text,
|
||||||
|
"telnet_auth_type" text,
|
||||||
|
"domain" text,
|
||||||
|
"security" text,
|
||||||
|
"ignore_cert" boolean DEFAULT false,
|
||||||
|
"guacamole_config" text,
|
||||||
|
"use_socks5" boolean,
|
||||||
|
"socks5_host" text,
|
||||||
|
"socks5_port" integer,
|
||||||
|
"socks5_username" text,
|
||||||
|
"socks5_password" text,
|
||||||
|
"socks5_proxy_chain" text,
|
||||||
|
"connection_origin" text,
|
||||||
|
"mac_address" text,
|
||||||
|
"wol_broadcast_address" text,
|
||||||
|
"port_knock_sequence" text,
|
||||||
|
"host_key_fingerprint" text,
|
||||||
|
"host_key_type" text,
|
||||||
|
"host_key_algorithm" text DEFAULT 'sha256',
|
||||||
|
"host_key_first_seen" text,
|
||||||
|
"host_key_last_verified" text,
|
||||||
|
"host_key_changed_count" integer DEFAULT 0,
|
||||||
|
"sync_id" varchar(255),
|
||||||
|
"created_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
"updated_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
CONSTRAINT "ssh_data_sync_id_unique" UNIQUE("sync_id")
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "network_topology" (
|
||||||
|
"id" serial PRIMARY KEY NOT NULL,
|
||||||
|
"user_id" varchar(255) NOT NULL,
|
||||||
|
"topology" text,
|
||||||
|
"created_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
"updated_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "notification_channels" (
|
||||||
|
"id" serial PRIMARY KEY NOT NULL,
|
||||||
|
"user_id" varchar(255) NOT NULL,
|
||||||
|
"name" varchar(255) NOT NULL,
|
||||||
|
"type" text NOT NULL,
|
||||||
|
"config" text NOT NULL,
|
||||||
|
"enabled" boolean DEFAULT true NOT NULL,
|
||||||
|
"created_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "opkssh_tokens" (
|
||||||
|
"id" serial PRIMARY KEY NOT NULL,
|
||||||
|
"user_id" varchar(255) NOT NULL,
|
||||||
|
"host_id" integer NOT NULL,
|
||||||
|
"ssh_cert" text NOT NULL,
|
||||||
|
"private_key" text NOT NULL,
|
||||||
|
"email" text,
|
||||||
|
"sub" text,
|
||||||
|
"issuer" text,
|
||||||
|
"audience" text,
|
||||||
|
"created_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
"expires_at" text NOT NULL,
|
||||||
|
"last_used" text
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "recent_activity" (
|
||||||
|
"id" serial PRIMARY KEY NOT NULL,
|
||||||
|
"user_id" varchar(255) NOT NULL,
|
||||||
|
"type" text NOT NULL,
|
||||||
|
"host_id" integer NOT NULL,
|
||||||
|
"host_name" text,
|
||||||
|
"timestamp" text DEFAULT CURRENT_TIMESTAMP NOT NULL
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "roles" (
|
||||||
|
"id" serial PRIMARY KEY NOT NULL,
|
||||||
|
"name" varchar(255) NOT NULL,
|
||||||
|
"display_name" text NOT NULL,
|
||||||
|
"description" text,
|
||||||
|
"is_system" boolean DEFAULT false NOT NULL,
|
||||||
|
"permissions" text,
|
||||||
|
"created_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
"updated_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
CONSTRAINT "roles_name_unique" UNIQUE("name")
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "session_recordings" (
|
||||||
|
"id" serial PRIMARY KEY NOT NULL,
|
||||||
|
"host_id" integer NOT NULL,
|
||||||
|
"user_id" varchar(255),
|
||||||
|
"username" text,
|
||||||
|
"access_id" integer,
|
||||||
|
"started_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
"ended_at" text,
|
||||||
|
"duration" integer,
|
||||||
|
"commands" text,
|
||||||
|
"dangerous_actions" text,
|
||||||
|
"recording_path" text,
|
||||||
|
"protocol" varchar(255) DEFAULT 'ssh' NOT NULL,
|
||||||
|
"format" text DEFAULT 'text' NOT NULL,
|
||||||
|
"terminated_by_owner" boolean DEFAULT false,
|
||||||
|
"termination_reason" text
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "session_share_participants" (
|
||||||
|
"id" serial PRIMARY KEY NOT NULL,
|
||||||
|
"share_id" varchar(255) NOT NULL,
|
||||||
|
"user_id" varchar(255),
|
||||||
|
"guest_label" text,
|
||||||
|
"joined_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
"left_at" text
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "session_shares" (
|
||||||
|
"id" varchar(255) PRIMARY KEY NOT NULL,
|
||||||
|
"host_id" integer NOT NULL,
|
||||||
|
"owner_user_id" varchar(255) NOT NULL,
|
||||||
|
"protocol" varchar(255) NOT NULL,
|
||||||
|
"session_id" text NOT NULL,
|
||||||
|
"tab_instance_id" text,
|
||||||
|
"share_type" text NOT NULL,
|
||||||
|
"target_user_id" varchar(255),
|
||||||
|
"link_token" varchar(255),
|
||||||
|
"permission_level" text DEFAULT 'read-only' NOT NULL,
|
||||||
|
"created_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
"expires_at" text NOT NULL,
|
||||||
|
"revoked_at" text,
|
||||||
|
"last_joined_at" text,
|
||||||
|
"join_count" integer DEFAULT 0 NOT NULL,
|
||||||
|
CONSTRAINT "session_shares_link_token_unique" UNIQUE("link_token")
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "sessions" (
|
||||||
|
"id" varchar(255) PRIMARY KEY NOT NULL,
|
||||||
|
"user_id" varchar(255) NOT NULL,
|
||||||
|
"jwt_token" text NOT NULL,
|
||||||
|
"device_type" text NOT NULL,
|
||||||
|
"device_info" text NOT NULL,
|
||||||
|
"oidc_sub" text,
|
||||||
|
"oidc_sid" text,
|
||||||
|
"sso_provider_id" integer,
|
||||||
|
"created_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
"expires_at" text NOT NULL,
|
||||||
|
"last_active_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "settings" (
|
||||||
|
"key" varchar(255) PRIMARY KEY NOT NULL,
|
||||||
|
"value" text NOT NULL
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "shared_host_auth_overrides" (
|
||||||
|
"id" serial PRIMARY KEY NOT NULL,
|
||||||
|
"host_id" integer NOT NULL,
|
||||||
|
"user_id" varchar(255) NOT NULL,
|
||||||
|
"protocol" varchar(255) DEFAULT 'ssh' NOT NULL,
|
||||||
|
"credential_id" integer NOT NULL,
|
||||||
|
"created_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
"updated_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "shared_host_secrets" (
|
||||||
|
"id" serial PRIMARY KEY NOT NULL,
|
||||||
|
"host_access_id" integer NOT NULL,
|
||||||
|
"target_user_id" varchar(255) NOT NULL,
|
||||||
|
"protocol" varchar(255) DEFAULT 'ssh' NOT NULL,
|
||||||
|
"source_type" text DEFAULT 'credential' NOT NULL,
|
||||||
|
"original_credential_id" integer,
|
||||||
|
"encrypted_username" text,
|
||||||
|
"encrypted_auth_type" text,
|
||||||
|
"encrypted_password" text,
|
||||||
|
"encrypted_key" text,
|
||||||
|
"encrypted_key_password" text,
|
||||||
|
"encrypted_key_type" text,
|
||||||
|
"encrypted_domain" text,
|
||||||
|
"created_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
"updated_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "snippet_access" (
|
||||||
|
"id" serial PRIMARY KEY NOT NULL,
|
||||||
|
"snippet_id" integer NOT NULL,
|
||||||
|
"user_id" varchar(255),
|
||||||
|
"role_id" integer,
|
||||||
|
"granted_by" varchar(255) NOT NULL,
|
||||||
|
"permission_level" text DEFAULT 'view' NOT NULL,
|
||||||
|
"expires_at" text,
|
||||||
|
"created_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "snippet_folders" (
|
||||||
|
"id" serial PRIMARY KEY NOT NULL,
|
||||||
|
"user_id" varchar(255) NOT NULL,
|
||||||
|
"name" varchar(255) NOT NULL,
|
||||||
|
"color" text,
|
||||||
|
"icon" text,
|
||||||
|
"sync_id" varchar(255),
|
||||||
|
"created_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
"updated_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
CONSTRAINT "snippet_folders_sync_id_unique" UNIQUE("sync_id")
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "snippets" (
|
||||||
|
"id" serial PRIMARY KEY NOT NULL,
|
||||||
|
"user_id" varchar(255) NOT NULL,
|
||||||
|
"name" varchar(255) NOT NULL,
|
||||||
|
"content" text NOT NULL,
|
||||||
|
"description" text,
|
||||||
|
"folder" text,
|
||||||
|
"order" integer DEFAULT 0 NOT NULL,
|
||||||
|
"sync_id" varchar(255),
|
||||||
|
"created_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
"updated_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
"host_filter" text,
|
||||||
|
CONSTRAINT "snippets_sync_id_unique" UNIQUE("sync_id")
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "ssh_credential_usage" (
|
||||||
|
"id" serial PRIMARY KEY NOT NULL,
|
||||||
|
"credential_id" integer NOT NULL,
|
||||||
|
"host_id" integer NOT NULL,
|
||||||
|
"user_id" varchar(255) NOT NULL,
|
||||||
|
"used_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "ssh_credentials" (
|
||||||
|
"id" serial PRIMARY KEY NOT NULL,
|
||||||
|
"user_id" varchar(255) NOT NULL,
|
||||||
|
"name" varchar(255) NOT NULL,
|
||||||
|
"description" text,
|
||||||
|
"folder" text,
|
||||||
|
"tags" text,
|
||||||
|
"auth_type" text NOT NULL,
|
||||||
|
"username" text,
|
||||||
|
"password" text,
|
||||||
|
"key" text,
|
||||||
|
"private_key" text,
|
||||||
|
"public_key" text,
|
||||||
|
"key_password" text,
|
||||||
|
"key_type" text,
|
||||||
|
"detected_key_type" text,
|
||||||
|
"cert_public_key" text,
|
||||||
|
"usage_count" integer DEFAULT 0 NOT NULL,
|
||||||
|
"last_used" text,
|
||||||
|
"sync_id" varchar(255),
|
||||||
|
"created_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
"updated_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
CONSTRAINT "ssh_credentials_sync_id_unique" UNIQUE("sync_id")
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "ssh_folders" (
|
||||||
|
"id" serial PRIMARY KEY NOT NULL,
|
||||||
|
"user_id" varchar(255) NOT NULL,
|
||||||
|
"name" varchar(255) NOT NULL,
|
||||||
|
"color" text,
|
||||||
|
"icon" text,
|
||||||
|
"credential_id" integer,
|
||||||
|
"sync_id" varchar(255),
|
||||||
|
"created_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
"updated_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
CONSTRAINT "ssh_folders_sync_id_unique" UNIQUE("sync_id")
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "sso_providers" (
|
||||||
|
"id" serial PRIMARY KEY NOT NULL,
|
||||||
|
"name" varchar(255) NOT NULL,
|
||||||
|
"type" text NOT NULL,
|
||||||
|
"enabled" boolean DEFAULT true NOT NULL,
|
||||||
|
"display_order" integer DEFAULT 0 NOT NULL,
|
||||||
|
"config" text NOT NULL,
|
||||||
|
"created_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
"updated_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "sync_tombstones" (
|
||||||
|
"id" serial PRIMARY KEY NOT NULL,
|
||||||
|
"user_id" varchar(255) NOT NULL,
|
||||||
|
"entity_type" text NOT NULL,
|
||||||
|
"sync_id" varchar(255) NOT NULL,
|
||||||
|
"deleted_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "termix_identities" (
|
||||||
|
"id" serial PRIMARY KEY NOT NULL,
|
||||||
|
"user_id" varchar(255) NOT NULL,
|
||||||
|
"handle" varchar(255) NOT NULL,
|
||||||
|
"description" text,
|
||||||
|
"created_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
"updated_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
CONSTRAINT "termix_identities_user_id_unique" UNIQUE("user_id"),
|
||||||
|
CONSTRAINT "termix_identities_handle_unique" UNIQUE("handle")
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "termix_identity_ca" (
|
||||||
|
"id" serial PRIMARY KEY NOT NULL,
|
||||||
|
"identity_id" integer NOT NULL,
|
||||||
|
"user_id" varchar(255) NOT NULL,
|
||||||
|
"public_key" text NOT NULL,
|
||||||
|
"private_key" text NOT NULL,
|
||||||
|
"validity_days" integer DEFAULT 90 NOT NULL,
|
||||||
|
"created_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
"updated_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
CONSTRAINT "termix_identity_ca_identity_id_unique" UNIQUE("identity_id")
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "termix_identity_keys" (
|
||||||
|
"id" serial PRIMARY KEY NOT NULL,
|
||||||
|
"identity_id" integer NOT NULL,
|
||||||
|
"user_id" varchar(255) NOT NULL,
|
||||||
|
"public_key" text NOT NULL,
|
||||||
|
"key_type" text NOT NULL,
|
||||||
|
"algorithm" text NOT NULL,
|
||||||
|
"label" text,
|
||||||
|
"comment" text,
|
||||||
|
"source" text DEFAULT 'manual' NOT NULL,
|
||||||
|
"credential_id" integer,
|
||||||
|
"enabled" boolean DEFAULT true NOT NULL,
|
||||||
|
"created_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "tmux_session_tags" (
|
||||||
|
"id" serial PRIMARY KEY NOT NULL,
|
||||||
|
"user_id" varchar(255) NOT NULL,
|
||||||
|
"host_id" integer NOT NULL,
|
||||||
|
"session_name" text NOT NULL,
|
||||||
|
"tag" text NOT NULL,
|
||||||
|
"created_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "transfer_recent" (
|
||||||
|
"id" serial PRIMARY KEY NOT NULL,
|
||||||
|
"user_id" varchar(255) NOT NULL,
|
||||||
|
"source_host_id" integer NOT NULL,
|
||||||
|
"dest_host_id" integer NOT NULL,
|
||||||
|
"dest_path" text NOT NULL,
|
||||||
|
"dest_path_label" text NOT NULL,
|
||||||
|
"last_used" text DEFAULT CURRENT_TIMESTAMP NOT NULL
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "trusted_devices" (
|
||||||
|
"id" varchar(255) PRIMARY KEY NOT NULL,
|
||||||
|
"user_id" varchar(255) NOT NULL,
|
||||||
|
"device_fingerprint" text NOT NULL,
|
||||||
|
"device_type" text NOT NULL,
|
||||||
|
"device_info" text NOT NULL,
|
||||||
|
"created_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
"expires_at" text NOT NULL,
|
||||||
|
"last_used_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "user_open_tabs" (
|
||||||
|
"id" varchar(255) PRIMARY KEY NOT NULL,
|
||||||
|
"user_id" varchar(255) NOT NULL,
|
||||||
|
"tab_type" text NOT NULL,
|
||||||
|
"host_id" integer,
|
||||||
|
"label" text NOT NULL,
|
||||||
|
"tab_order" integer DEFAULT 0 NOT NULL,
|
||||||
|
"backend_session_id" text,
|
||||||
|
"created_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
"updated_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "user_preferences" (
|
||||||
|
"user_id" varchar(255) PRIMARY KEY NOT NULL,
|
||||||
|
"reopen_tabs_on_login" boolean DEFAULT false NOT NULL,
|
||||||
|
"theme" text,
|
||||||
|
"font_size" text,
|
||||||
|
"accent_color" text,
|
||||||
|
"language" text,
|
||||||
|
"storage_mode" text,
|
||||||
|
"command_autocomplete" boolean,
|
||||||
|
"command_palette_enabled" boolean,
|
||||||
|
"show_host_tags" boolean,
|
||||||
|
"host_tray_on_click" boolean,
|
||||||
|
"pin_app_rail" boolean,
|
||||||
|
"expand_app_rail_on_hover" boolean,
|
||||||
|
"folders_collapsed" boolean,
|
||||||
|
"confirm_snippet_execution" boolean,
|
||||||
|
"disable_update_check" boolean,
|
||||||
|
"confirm_tab_close" boolean,
|
||||||
|
"hidden_rail_tabs" text,
|
||||||
|
"compact_host_view" boolean,
|
||||||
|
"status_color_scheme" text,
|
||||||
|
"custom_themes" text,
|
||||||
|
"custom_keybindings" text,
|
||||||
|
"updated_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "user_roles" (
|
||||||
|
"id" serial PRIMARY KEY NOT NULL,
|
||||||
|
"user_id" varchar(255) NOT NULL,
|
||||||
|
"role_id" integer NOT NULL,
|
||||||
|
"granted_by" varchar(255),
|
||||||
|
"granted_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "users" (
|
||||||
|
"id" varchar(255) PRIMARY KEY NOT NULL,
|
||||||
|
"username" text NOT NULL,
|
||||||
|
"password_hash" text NOT NULL,
|
||||||
|
"is_admin" boolean DEFAULT false NOT NULL,
|
||||||
|
"is_oidc" boolean DEFAULT false NOT NULL,
|
||||||
|
"oidc_identifier" text,
|
||||||
|
"sso_provider_id" integer,
|
||||||
|
"client_id" text,
|
||||||
|
"client_secret" text,
|
||||||
|
"issuer_url" text,
|
||||||
|
"authorization_url" text,
|
||||||
|
"token_url" text,
|
||||||
|
"identifier_path" text,
|
||||||
|
"name_path" text,
|
||||||
|
"scopes" text DEFAULT 'openid email profile',
|
||||||
|
"totp_secret" text,
|
||||||
|
"totp_enabled" boolean DEFAULT false NOT NULL,
|
||||||
|
"totp_backup_codes" text,
|
||||||
|
"registered_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
"donation_modal_dismissed" boolean DEFAULT false NOT NULL
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "vault_profiles" (
|
||||||
|
"id" serial PRIMARY KEY NOT NULL,
|
||||||
|
"user_id" varchar(255) NOT NULL,
|
||||||
|
"name" varchar(255) NOT NULL,
|
||||||
|
"description" text,
|
||||||
|
"folder" text,
|
||||||
|
"tags" text,
|
||||||
|
"vault_addr" text NOT NULL,
|
||||||
|
"vault_namespace" text,
|
||||||
|
"oidc_mount" text,
|
||||||
|
"oidc_role" text,
|
||||||
|
"ssh_mount" text,
|
||||||
|
"ssh_role" text NOT NULL,
|
||||||
|
"valid_principals" text,
|
||||||
|
"key_type" text,
|
||||||
|
"shared" boolean DEFAULT false NOT NULL,
|
||||||
|
"sync_id" varchar(255),
|
||||||
|
"created_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
"updated_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
CONSTRAINT "vault_profiles_sync_id_unique" UNIQUE("sync_id")
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "vault_tokens" (
|
||||||
|
"id" serial PRIMARY KEY NOT NULL,
|
||||||
|
"user_id" varchar(255) NOT NULL,
|
||||||
|
"profile_id" integer NOT NULL,
|
||||||
|
"ssh_cert" text NOT NULL,
|
||||||
|
"private_key" text NOT NULL,
|
||||||
|
"created_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
"expires_at" text NOT NULL,
|
||||||
|
"last_used" text
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE "webauthn_credentials" (
|
||||||
|
"id" varchar(255) PRIMARY KEY NOT NULL,
|
||||||
|
"user_id" varchar(255) NOT NULL,
|
||||||
|
"name" varchar(255) NOT NULL,
|
||||||
|
"credential_id" text NOT NULL,
|
||||||
|
"public_key" text NOT NULL,
|
||||||
|
"counter" integer DEFAULT 0 NOT NULL,
|
||||||
|
"device_type" text,
|
||||||
|
"backed_up" boolean DEFAULT false NOT NULL,
|
||||||
|
"transports" text,
|
||||||
|
"user_verification" text DEFAULT 'preferred' NOT NULL,
|
||||||
|
"created_at" text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
"last_used_at" text
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
ALTER TABLE "alert_firings" ADD CONSTRAINT "alert_firings_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "alert_firings" ADD CONSTRAINT "alert_firings_rule_id_alert_rules_id_fk" FOREIGN KEY ("rule_id") REFERENCES "public"."alert_rules"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "alert_rule_channels" ADD CONSTRAINT "alert_rule_channels_rule_id_alert_rules_id_fk" FOREIGN KEY ("rule_id") REFERENCES "public"."alert_rules"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "alert_rule_channels" ADD CONSTRAINT "alert_rule_channels_channel_id_notification_channels_id_fk" FOREIGN KEY ("channel_id") REFERENCES "public"."notification_channels"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "alert_rules" ADD CONSTRAINT "alert_rules_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "alert_rules" ADD CONSTRAINT "alert_rules_host_id_ssh_data_id_fk" FOREIGN KEY ("host_id") REFERENCES "public"."ssh_data"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "api_keys" ADD CONSTRAINT "api_keys_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "audit_logs" ADD CONSTRAINT "audit_logs_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE set null ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "c2s_tunnel_presets" ADD CONSTRAINT "c2s_tunnel_presets_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "command_history" ADD CONSTRAINT "command_history_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "command_history" ADD CONSTRAINT "command_history_host_id_ssh_data_id_fk" FOREIGN KEY ("host_id") REFERENCES "public"."ssh_data"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "dashboard_service_links" ADD CONSTRAINT "dashboard_service_links_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "dismissed_alerts" ADD CONSTRAINT "dismissed_alerts_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "file_manager_pinned" ADD CONSTRAINT "file_manager_pinned_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "file_manager_pinned" ADD CONSTRAINT "file_manager_pinned_host_id_ssh_data_id_fk" FOREIGN KEY ("host_id") REFERENCES "public"."ssh_data"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "file_manager_recent" ADD CONSTRAINT "file_manager_recent_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "file_manager_recent" ADD CONSTRAINT "file_manager_recent_host_id_ssh_data_id_fk" FOREIGN KEY ("host_id") REFERENCES "public"."ssh_data"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "file_manager_shortcuts" ADD CONSTRAINT "file_manager_shortcuts_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "file_manager_shortcuts" ADD CONSTRAINT "file_manager_shortcuts_host_id_ssh_data_id_fk" FOREIGN KEY ("host_id") REFERENCES "public"."ssh_data"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "homepage_items" ADD CONSTRAINT "homepage_items_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "homepage_layouts" ADD CONSTRAINT "homepage_layouts_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "host_access" ADD CONSTRAINT "host_access_host_id_ssh_data_id_fk" FOREIGN KEY ("host_id") REFERENCES "public"."ssh_data"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "host_access" ADD CONSTRAINT "host_access_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "host_access" ADD CONSTRAINT "host_access_role_id_roles_id_fk" FOREIGN KEY ("role_id") REFERENCES "public"."roles"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "host_access" ADD CONSTRAINT "host_access_granted_by_users_id_fk" FOREIGN KEY ("granted_by") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "host_health_checks" ADD CONSTRAINT "host_health_checks_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "host_health_checks" ADD CONSTRAINT "host_health_checks_host_id_ssh_data_id_fk" FOREIGN KEY ("host_id") REFERENCES "public"."ssh_data"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "host_health_history" ADD CONSTRAINT "host_health_history_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "host_health_history" ADD CONSTRAINT "host_health_history_host_id_ssh_data_id_fk" FOREIGN KEY ("host_id") REFERENCES "public"."ssh_data"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "host_metrics_history" ADD CONSTRAINT "host_metrics_history_host_id_ssh_data_id_fk" FOREIGN KEY ("host_id") REFERENCES "public"."ssh_data"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "host_metrics_preferences" ADD CONSTRAINT "host_metrics_preferences_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "host_metrics_preferences" ADD CONSTRAINT "host_metrics_preferences_host_id_ssh_data_id_fk" FOREIGN KEY ("host_id") REFERENCES "public"."ssh_data"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "ssh_data" ADD CONSTRAINT "ssh_data_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "ssh_data" ADD CONSTRAINT "ssh_data_credential_id_ssh_credentials_id_fk" FOREIGN KEY ("credential_id") REFERENCES "public"."ssh_credentials"("id") ON DELETE set null ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "ssh_data" ADD CONSTRAINT "ssh_data_vault_profile_id_vault_profiles_id_fk" FOREIGN KEY ("vault_profile_id") REFERENCES "public"."vault_profiles"("id") ON DELETE set null ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "ssh_data" ADD CONSTRAINT "ssh_data_rdp_credential_id_ssh_credentials_id_fk" FOREIGN KEY ("rdp_credential_id") REFERENCES "public"."ssh_credentials"("id") ON DELETE set null ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "ssh_data" ADD CONSTRAINT "ssh_data_vnc_credential_id_ssh_credentials_id_fk" FOREIGN KEY ("vnc_credential_id") REFERENCES "public"."ssh_credentials"("id") ON DELETE set null ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "ssh_data" ADD CONSTRAINT "ssh_data_telnet_credential_id_ssh_credentials_id_fk" FOREIGN KEY ("telnet_credential_id") REFERENCES "public"."ssh_credentials"("id") ON DELETE set null ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "network_topology" ADD CONSTRAINT "network_topology_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "notification_channels" ADD CONSTRAINT "notification_channels_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "opkssh_tokens" ADD CONSTRAINT "opkssh_tokens_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "opkssh_tokens" ADD CONSTRAINT "opkssh_tokens_host_id_ssh_data_id_fk" FOREIGN KEY ("host_id") REFERENCES "public"."ssh_data"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "recent_activity" ADD CONSTRAINT "recent_activity_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "recent_activity" ADD CONSTRAINT "recent_activity_host_id_ssh_data_id_fk" FOREIGN KEY ("host_id") REFERENCES "public"."ssh_data"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "session_recordings" ADD CONSTRAINT "session_recordings_host_id_ssh_data_id_fk" FOREIGN KEY ("host_id") REFERENCES "public"."ssh_data"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "session_recordings" ADD CONSTRAINT "session_recordings_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE set null ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "session_recordings" ADD CONSTRAINT "session_recordings_access_id_host_access_id_fk" FOREIGN KEY ("access_id") REFERENCES "public"."host_access"("id") ON DELETE set null ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "session_share_participants" ADD CONSTRAINT "session_share_participants_share_id_session_shares_id_fk" FOREIGN KEY ("share_id") REFERENCES "public"."session_shares"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "session_share_participants" ADD CONSTRAINT "session_share_participants_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "session_shares" ADD CONSTRAINT "session_shares_host_id_ssh_data_id_fk" FOREIGN KEY ("host_id") REFERENCES "public"."ssh_data"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "session_shares" ADD CONSTRAINT "session_shares_owner_user_id_users_id_fk" FOREIGN KEY ("owner_user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "session_shares" ADD CONSTRAINT "session_shares_target_user_id_users_id_fk" FOREIGN KEY ("target_user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "sessions" ADD CONSTRAINT "sessions_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "shared_host_auth_overrides" ADD CONSTRAINT "shared_host_auth_overrides_host_id_ssh_data_id_fk" FOREIGN KEY ("host_id") REFERENCES "public"."ssh_data"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "shared_host_auth_overrides" ADD CONSTRAINT "shared_host_auth_overrides_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "shared_host_auth_overrides" ADD CONSTRAINT "shared_host_auth_overrides_credential_id_ssh_credentials_id_fk" FOREIGN KEY ("credential_id") REFERENCES "public"."ssh_credentials"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "shared_host_secrets" ADD CONSTRAINT "shared_host_secrets_host_access_id_host_access_id_fk" FOREIGN KEY ("host_access_id") REFERENCES "public"."host_access"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "shared_host_secrets" ADD CONSTRAINT "shared_host_secrets_target_user_id_users_id_fk" FOREIGN KEY ("target_user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "shared_host_secrets" ADD CONSTRAINT "shared_host_secrets_original_credential_id_ssh_credentials_id_fk" FOREIGN KEY ("original_credential_id") REFERENCES "public"."ssh_credentials"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "snippet_access" ADD CONSTRAINT "snippet_access_snippet_id_snippets_id_fk" FOREIGN KEY ("snippet_id") REFERENCES "public"."snippets"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "snippet_access" ADD CONSTRAINT "snippet_access_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "snippet_access" ADD CONSTRAINT "snippet_access_role_id_roles_id_fk" FOREIGN KEY ("role_id") REFERENCES "public"."roles"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "snippet_access" ADD CONSTRAINT "snippet_access_granted_by_users_id_fk" FOREIGN KEY ("granted_by") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "snippet_folders" ADD CONSTRAINT "snippet_folders_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "snippets" ADD CONSTRAINT "snippets_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "ssh_credential_usage" ADD CONSTRAINT "ssh_credential_usage_credential_id_ssh_credentials_id_fk" FOREIGN KEY ("credential_id") REFERENCES "public"."ssh_credentials"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "ssh_credential_usage" ADD CONSTRAINT "ssh_credential_usage_host_id_ssh_data_id_fk" FOREIGN KEY ("host_id") REFERENCES "public"."ssh_data"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "ssh_credential_usage" ADD CONSTRAINT "ssh_credential_usage_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "ssh_credentials" ADD CONSTRAINT "ssh_credentials_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "ssh_folders" ADD CONSTRAINT "ssh_folders_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "ssh_folders" ADD CONSTRAINT "ssh_folders_credential_id_ssh_credentials_id_fk" FOREIGN KEY ("credential_id") REFERENCES "public"."ssh_credentials"("id") ON DELETE set null ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "sync_tombstones" ADD CONSTRAINT "sync_tombstones_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "termix_identities" ADD CONSTRAINT "termix_identities_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "termix_identity_ca" ADD CONSTRAINT "termix_identity_ca_identity_id_termix_identities_id_fk" FOREIGN KEY ("identity_id") REFERENCES "public"."termix_identities"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "termix_identity_ca" ADD CONSTRAINT "termix_identity_ca_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "termix_identity_keys" ADD CONSTRAINT "termix_identity_keys_identity_id_termix_identities_id_fk" FOREIGN KEY ("identity_id") REFERENCES "public"."termix_identities"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "termix_identity_keys" ADD CONSTRAINT "termix_identity_keys_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "termix_identity_keys" ADD CONSTRAINT "termix_identity_keys_credential_id_ssh_credentials_id_fk" FOREIGN KEY ("credential_id") REFERENCES "public"."ssh_credentials"("id") ON DELETE set null ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "tmux_session_tags" ADD CONSTRAINT "tmux_session_tags_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "tmux_session_tags" ADD CONSTRAINT "tmux_session_tags_host_id_ssh_data_id_fk" FOREIGN KEY ("host_id") REFERENCES "public"."ssh_data"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "transfer_recent" ADD CONSTRAINT "transfer_recent_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "transfer_recent" ADD CONSTRAINT "transfer_recent_source_host_id_ssh_data_id_fk" FOREIGN KEY ("source_host_id") REFERENCES "public"."ssh_data"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "transfer_recent" ADD CONSTRAINT "transfer_recent_dest_host_id_ssh_data_id_fk" FOREIGN KEY ("dest_host_id") REFERENCES "public"."ssh_data"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "trusted_devices" ADD CONSTRAINT "trusted_devices_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "user_open_tabs" ADD CONSTRAINT "user_open_tabs_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "user_open_tabs" ADD CONSTRAINT "user_open_tabs_host_id_ssh_data_id_fk" FOREIGN KEY ("host_id") REFERENCES "public"."ssh_data"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "user_preferences" ADD CONSTRAINT "user_preferences_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "user_roles" ADD CONSTRAINT "user_roles_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "user_roles" ADD CONSTRAINT "user_roles_role_id_roles_id_fk" FOREIGN KEY ("role_id") REFERENCES "public"."roles"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "user_roles" ADD CONSTRAINT "user_roles_granted_by_users_id_fk" FOREIGN KEY ("granted_by") REFERENCES "public"."users"("id") ON DELETE set null ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "vault_profiles" ADD CONSTRAINT "vault_profiles_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "vault_tokens" ADD CONSTRAINT "vault_tokens_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "vault_tokens" ADD CONSTRAINT "vault_tokens_profile_id_vault_profiles_id_fk" FOREIGN KEY ("profile_id") REFERENCES "public"."vault_profiles"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
ALTER TABLE "webauthn_credentials" ADD CONSTRAINT "webauthn_credentials_user_id_users_id_fk" FOREIGN KEY ("user_id") REFERENCES "public"."users"("id") ON DELETE cascade ON UPDATE no action;--> statement-breakpoint
|
||||||
|
CREATE UNIQUE INDEX "idx_host_health_checks_user_host" ON "host_health_checks" USING btree ("user_id","host_id");--> statement-breakpoint
|
||||||
|
CREATE UNIQUE INDEX "idx_host_metrics_prefs_user_host" ON "host_metrics_preferences" USING btree ("user_id","host_id");--> statement-breakpoint
|
||||||
|
CREATE UNIQUE INDEX "idx_opkssh_tokens_user_host" ON "opkssh_tokens" USING btree ("user_id","host_id");--> statement-breakpoint
|
||||||
|
CREATE UNIQUE INDEX "shared_host_auth_overrides_host_user_protocol_unique" ON "shared_host_auth_overrides" USING btree ("host_id","user_id","protocol");--> statement-breakpoint
|
||||||
|
CREATE UNIQUE INDEX "idx_shared_host_secrets_scope" ON "shared_host_secrets" USING btree ("host_access_id","target_user_id","protocol");--> statement-breakpoint
|
||||||
|
CREATE UNIQUE INDEX "idx_user_roles_user_role" ON "user_roles" USING btree ("user_id","role_id");--> statement-breakpoint
|
||||||
|
CREATE UNIQUE INDEX "idx_vault_tokens_user_profile" ON "vault_tokens" USING btree ("user_id","profile_id");
|
||||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,13 @@
|
|||||||
|
{
|
||||||
|
"version": "7",
|
||||||
|
"dialect": "postgresql",
|
||||||
|
"entries": [
|
||||||
|
{
|
||||||
|
"idx": 0,
|
||||||
|
"version": "7",
|
||||||
|
"when": 1785738871078,
|
||||||
|
"tag": "0000_jazzy_infant_terrible",
|
||||||
|
"breakpoints": true
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
@@ -0,0 +1,836 @@
|
|||||||
|
CREATE TABLE `alert_firings` (
|
||||||
|
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
|
||||||
|
`user_id` text NOT NULL,
|
||||||
|
`rule_id` integer NOT NULL,
|
||||||
|
`host_id` integer NOT NULL,
|
||||||
|
`host_name` text NOT NULL,
|
||||||
|
`fired_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
`resolved_at` text,
|
||||||
|
`value` real,
|
||||||
|
`message` text NOT NULL,
|
||||||
|
`severity` text DEFAULT 'warning' NOT NULL,
|
||||||
|
`acknowledged` integer DEFAULT false NOT NULL,
|
||||||
|
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade,
|
||||||
|
FOREIGN KEY (`rule_id`) REFERENCES `alert_rules`(`id`) ON UPDATE no action ON DELETE cascade
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `alert_rule_channels` (
|
||||||
|
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
|
||||||
|
`rule_id` integer NOT NULL,
|
||||||
|
`channel_id` integer NOT NULL,
|
||||||
|
FOREIGN KEY (`rule_id`) REFERENCES `alert_rules`(`id`) ON UPDATE no action ON DELETE cascade,
|
||||||
|
FOREIGN KEY (`channel_id`) REFERENCES `notification_channels`(`id`) ON UPDATE no action ON DELETE cascade
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `alert_rules` (
|
||||||
|
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
|
||||||
|
`user_id` text NOT NULL,
|
||||||
|
`host_id` integer,
|
||||||
|
`name` text NOT NULL,
|
||||||
|
`enabled` integer DEFAULT true NOT NULL,
|
||||||
|
`trigger_type` text NOT NULL,
|
||||||
|
`threshold_value` real,
|
||||||
|
`threshold_duration_seconds` integer,
|
||||||
|
`cooldown_minutes` integer DEFAULT 15 NOT NULL,
|
||||||
|
`created_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
`updated_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade,
|
||||||
|
FOREIGN KEY (`host_id`) REFERENCES `ssh_data`(`id`) ON UPDATE no action ON DELETE cascade
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `api_keys` (
|
||||||
|
`id` text PRIMARY KEY NOT NULL,
|
||||||
|
`user_id` text NOT NULL,
|
||||||
|
`name` text NOT NULL,
|
||||||
|
`token_hash` text NOT NULL,
|
||||||
|
`token_prefix` text NOT NULL,
|
||||||
|
`created_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
`expires_at` text,
|
||||||
|
`last_used_at` text,
|
||||||
|
`is_active` integer DEFAULT true NOT NULL,
|
||||||
|
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `audit_logs` (
|
||||||
|
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
|
||||||
|
`user_id` text,
|
||||||
|
`username` text NOT NULL,
|
||||||
|
`action` text NOT NULL,
|
||||||
|
`resource_type` text NOT NULL,
|
||||||
|
`resource_id` text,
|
||||||
|
`resource_name` text,
|
||||||
|
`details` text,
|
||||||
|
`ip_address` text,
|
||||||
|
`user_agent` text,
|
||||||
|
`success` integer NOT NULL,
|
||||||
|
`error_message` text,
|
||||||
|
`timestamp` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE set null
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `c2s_tunnel_presets` (
|
||||||
|
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
|
||||||
|
`user_id` text NOT NULL,
|
||||||
|
`name` text NOT NULL,
|
||||||
|
`config` text NOT NULL,
|
||||||
|
`platform` text,
|
||||||
|
`computer_name` text,
|
||||||
|
`created_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
`updated_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `command_history` (
|
||||||
|
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
|
||||||
|
`user_id` text NOT NULL,
|
||||||
|
`host_id` integer NOT NULL,
|
||||||
|
`command` text NOT NULL,
|
||||||
|
`executed_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade,
|
||||||
|
FOREIGN KEY (`host_id`) REFERENCES `ssh_data`(`id`) ON UPDATE no action ON DELETE cascade
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `dashboard_service_links` (
|
||||||
|
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
|
||||||
|
`user_id` text NOT NULL,
|
||||||
|
`label` text NOT NULL,
|
||||||
|
`url` text NOT NULL,
|
||||||
|
`order` integer DEFAULT 0 NOT NULL,
|
||||||
|
`sync_id` text,
|
||||||
|
`created_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
`updated_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE UNIQUE INDEX `dashboard_service_links_sync_id_unique` ON `dashboard_service_links` (`sync_id`);--> statement-breakpoint
|
||||||
|
CREATE TABLE `dismissed_alerts` (
|
||||||
|
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
|
||||||
|
`user_id` text NOT NULL,
|
||||||
|
`alert_id` text NOT NULL,
|
||||||
|
`dismissed_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `file_manager_pinned` (
|
||||||
|
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
|
||||||
|
`user_id` text NOT NULL,
|
||||||
|
`host_id` integer NOT NULL,
|
||||||
|
`name` text NOT NULL,
|
||||||
|
`path` text NOT NULL,
|
||||||
|
`pinned_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade,
|
||||||
|
FOREIGN KEY (`host_id`) REFERENCES `ssh_data`(`id`) ON UPDATE no action ON DELETE cascade
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `file_manager_recent` (
|
||||||
|
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
|
||||||
|
`user_id` text NOT NULL,
|
||||||
|
`host_id` integer NOT NULL,
|
||||||
|
`name` text NOT NULL,
|
||||||
|
`path` text NOT NULL,
|
||||||
|
`last_opened` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade,
|
||||||
|
FOREIGN KEY (`host_id`) REFERENCES `ssh_data`(`id`) ON UPDATE no action ON DELETE cascade
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `file_manager_shortcuts` (
|
||||||
|
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
|
||||||
|
`user_id` text NOT NULL,
|
||||||
|
`host_id` integer NOT NULL,
|
||||||
|
`name` text NOT NULL,
|
||||||
|
`path` text NOT NULL,
|
||||||
|
`created_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade,
|
||||||
|
FOREIGN KEY (`host_id`) REFERENCES `ssh_data`(`id`) ON UPDATE no action ON DELETE cascade
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `homepage_items` (
|
||||||
|
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
|
||||||
|
`user_id` text NOT NULL,
|
||||||
|
`type_id` text NOT NULL,
|
||||||
|
`title` text,
|
||||||
|
`config` text DEFAULT '{}' NOT NULL,
|
||||||
|
`folder_id` integer,
|
||||||
|
`sync_id` text,
|
||||||
|
`created_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
`updated_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE UNIQUE INDEX `homepage_items_sync_id_unique` ON `homepage_items` (`sync_id`);--> statement-breakpoint
|
||||||
|
CREATE TABLE `homepage_layouts` (
|
||||||
|
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
|
||||||
|
`user_id` text NOT NULL,
|
||||||
|
`layout` text DEFAULT '{}' NOT NULL,
|
||||||
|
`updated_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE UNIQUE INDEX `homepage_layouts_user_id_unique` ON `homepage_layouts` (`user_id`);--> statement-breakpoint
|
||||||
|
CREATE TABLE `host_access` (
|
||||||
|
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
|
||||||
|
`host_id` integer NOT NULL,
|
||||||
|
`user_id` text,
|
||||||
|
`role_id` integer,
|
||||||
|
`granted_by` text NOT NULL,
|
||||||
|
`permission_level` text DEFAULT 'connect' NOT NULL,
|
||||||
|
`expires_at` text,
|
||||||
|
`created_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
`last_accessed_at` text,
|
||||||
|
`access_count` integer DEFAULT 0 NOT NULL,
|
||||||
|
FOREIGN KEY (`host_id`) REFERENCES `ssh_data`(`id`) ON UPDATE no action ON DELETE cascade,
|
||||||
|
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade,
|
||||||
|
FOREIGN KEY (`role_id`) REFERENCES `roles`(`id`) ON UPDATE no action ON DELETE cascade,
|
||||||
|
FOREIGN KEY (`granted_by`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `host_health_checks` (
|
||||||
|
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
|
||||||
|
`user_id` text NOT NULL,
|
||||||
|
`host_id` integer NOT NULL,
|
||||||
|
`checks` text NOT NULL,
|
||||||
|
`interval_seconds` integer DEFAULT 300 NOT NULL,
|
||||||
|
`created_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
`updated_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade,
|
||||||
|
FOREIGN KEY (`host_id`) REFERENCES `ssh_data`(`id`) ON UPDATE no action ON DELETE cascade
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE UNIQUE INDEX `idx_host_health_checks_user_host` ON `host_health_checks` (`user_id`,`host_id`);--> statement-breakpoint
|
||||||
|
CREATE TABLE `host_health_history` (
|
||||||
|
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
|
||||||
|
`user_id` text NOT NULL,
|
||||||
|
`host_id` integer NOT NULL,
|
||||||
|
`check_id` text NOT NULL,
|
||||||
|
`ts` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
`ok` integer NOT NULL,
|
||||||
|
`latency_ms` integer,
|
||||||
|
`detail` text,
|
||||||
|
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade,
|
||||||
|
FOREIGN KEY (`host_id`) REFERENCES `ssh_data`(`id`) ON UPDATE no action ON DELETE cascade
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `host_metrics_history` (
|
||||||
|
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
|
||||||
|
`host_id` integer NOT NULL,
|
||||||
|
`ts` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
`cpu_percent` real,
|
||||||
|
`mem_percent` real,
|
||||||
|
`disk_percent` real,
|
||||||
|
`net_rx_bytes` integer,
|
||||||
|
`net_tx_bytes` integer,
|
||||||
|
FOREIGN KEY (`host_id`) REFERENCES `ssh_data`(`id`) ON UPDATE no action ON DELETE cascade
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `host_metrics_preferences` (
|
||||||
|
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
|
||||||
|
`user_id` text NOT NULL,
|
||||||
|
`host_id` integer NOT NULL,
|
||||||
|
`layout` text NOT NULL,
|
||||||
|
`created_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
`updated_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade,
|
||||||
|
FOREIGN KEY (`host_id`) REFERENCES `ssh_data`(`id`) ON UPDATE no action ON DELETE cascade
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE UNIQUE INDEX `idx_host_metrics_prefs_user_host` ON `host_metrics_preferences` (`user_id`,`host_id`);--> statement-breakpoint
|
||||||
|
CREATE TABLE `ssh_data` (
|
||||||
|
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
|
||||||
|
`user_id` text NOT NULL,
|
||||||
|
`connection_type` text DEFAULT 'ssh' NOT NULL,
|
||||||
|
`name` text,
|
||||||
|
`ip` text NOT NULL,
|
||||||
|
`port` integer NOT NULL,
|
||||||
|
`username` text NOT NULL,
|
||||||
|
`folder` text,
|
||||||
|
`tags` text,
|
||||||
|
`pin` integer DEFAULT false NOT NULL,
|
||||||
|
`auth_type` text NOT NULL,
|
||||||
|
`use_warpgate` integer DEFAULT false NOT NULL,
|
||||||
|
`share_ssh_auth` integer DEFAULT false NOT NULL,
|
||||||
|
`force_keyboard_interactive` text,
|
||||||
|
`password` text,
|
||||||
|
`key` text(8192),
|
||||||
|
`key_password` text,
|
||||||
|
`key_type` text,
|
||||||
|
`sudo_password` text,
|
||||||
|
`autostart_password` text,
|
||||||
|
`autostart_key` text(8192),
|
||||||
|
`autostart_key_password` text,
|
||||||
|
`credential_id` integer,
|
||||||
|
`override_credential_username` integer,
|
||||||
|
`vault_profile_id` integer,
|
||||||
|
`enable_terminal` integer DEFAULT true NOT NULL,
|
||||||
|
`enable_session_logging` integer DEFAULT true NOT NULL,
|
||||||
|
`allow_session_sharing` integer DEFAULT true NOT NULL,
|
||||||
|
`enable_command_history` integer DEFAULT true NOT NULL,
|
||||||
|
`enable_tunnel` integer DEFAULT true NOT NULL,
|
||||||
|
`tunnel_connections` text,
|
||||||
|
`jump_hosts` text,
|
||||||
|
`enable_file_manager` integer DEFAULT true NOT NULL,
|
||||||
|
`scp_legacy` integer DEFAULT false NOT NULL,
|
||||||
|
`enable_docker` integer DEFAULT false NOT NULL,
|
||||||
|
`enable_tmux_monitor` integer DEFAULT false NOT NULL,
|
||||||
|
`show_terminal_in_sidebar` integer DEFAULT true NOT NULL,
|
||||||
|
`show_file_manager_in_sidebar` integer DEFAULT false NOT NULL,
|
||||||
|
`show_tunnel_in_sidebar` integer DEFAULT false NOT NULL,
|
||||||
|
`show_docker_in_sidebar` integer DEFAULT false NOT NULL,
|
||||||
|
`show_server_stats_in_sidebar` integer DEFAULT false NOT NULL,
|
||||||
|
`default_path` text,
|
||||||
|
`stats_config` text,
|
||||||
|
`docker_config` text,
|
||||||
|
`enable_proxmox` integer DEFAULT false NOT NULL,
|
||||||
|
`proxmox_config` text,
|
||||||
|
`terminal_config` text,
|
||||||
|
`quick_actions` text,
|
||||||
|
`notes` text,
|
||||||
|
`enable_ssh` integer DEFAULT true NOT NULL,
|
||||||
|
`enable_rdp` integer DEFAULT false NOT NULL,
|
||||||
|
`enable_vnc` integer DEFAULT false NOT NULL,
|
||||||
|
`enable_telnet` integer DEFAULT false NOT NULL,
|
||||||
|
`ssh_port` integer DEFAULT 22,
|
||||||
|
`rdp_port` integer DEFAULT 3389,
|
||||||
|
`vnc_port` integer DEFAULT 5900,
|
||||||
|
`telnet_port` integer DEFAULT 23,
|
||||||
|
`rdp_credential_id` integer,
|
||||||
|
`rdp_user` text,
|
||||||
|
`rdp_password` text,
|
||||||
|
`rdp_domain` text,
|
||||||
|
`rdp_security` text,
|
||||||
|
`rdp_ignore_cert` integer DEFAULT false,
|
||||||
|
`vnc_credential_id` integer,
|
||||||
|
`vnc_password` text,
|
||||||
|
`vnc_user` text,
|
||||||
|
`telnet_user` text,
|
||||||
|
`telnet_password` text,
|
||||||
|
`telnet_credential_id` integer,
|
||||||
|
`rdp_auth_type` text,
|
||||||
|
`vnc_auth_type` text,
|
||||||
|
`telnet_auth_type` text,
|
||||||
|
`domain` text,
|
||||||
|
`security` text,
|
||||||
|
`ignore_cert` integer DEFAULT false,
|
||||||
|
`guacamole_config` text,
|
||||||
|
`use_socks5` integer,
|
||||||
|
`socks5_host` text,
|
||||||
|
`socks5_port` integer,
|
||||||
|
`socks5_username` text,
|
||||||
|
`socks5_password` text,
|
||||||
|
`socks5_proxy_chain` text,
|
||||||
|
`connection_origin` text,
|
||||||
|
`mac_address` text,
|
||||||
|
`wol_broadcast_address` text,
|
||||||
|
`port_knock_sequence` text,
|
||||||
|
`host_key_fingerprint` text,
|
||||||
|
`host_key_type` text,
|
||||||
|
`host_key_algorithm` text DEFAULT 'sha256',
|
||||||
|
`host_key_first_seen` text,
|
||||||
|
`host_key_last_verified` text,
|
||||||
|
`host_key_changed_count` integer DEFAULT 0,
|
||||||
|
`sync_id` text,
|
||||||
|
`created_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
`updated_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade,
|
||||||
|
FOREIGN KEY (`credential_id`) REFERENCES `ssh_credentials`(`id`) ON UPDATE no action ON DELETE set null,
|
||||||
|
FOREIGN KEY (`vault_profile_id`) REFERENCES `vault_profiles`(`id`) ON UPDATE no action ON DELETE set null,
|
||||||
|
FOREIGN KEY (`rdp_credential_id`) REFERENCES `ssh_credentials`(`id`) ON UPDATE no action ON DELETE set null,
|
||||||
|
FOREIGN KEY (`vnc_credential_id`) REFERENCES `ssh_credentials`(`id`) ON UPDATE no action ON DELETE set null,
|
||||||
|
FOREIGN KEY (`telnet_credential_id`) REFERENCES `ssh_credentials`(`id`) ON UPDATE no action ON DELETE set null
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE UNIQUE INDEX `ssh_data_sync_id_unique` ON `ssh_data` (`sync_id`);--> statement-breakpoint
|
||||||
|
CREATE TABLE `network_topology` (
|
||||||
|
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
|
||||||
|
`user_id` text NOT NULL,
|
||||||
|
`topology` text,
|
||||||
|
`created_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
`updated_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `notification_channels` (
|
||||||
|
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
|
||||||
|
`user_id` text NOT NULL,
|
||||||
|
`name` text NOT NULL,
|
||||||
|
`type` text NOT NULL,
|
||||||
|
`config` text NOT NULL,
|
||||||
|
`enabled` integer DEFAULT true NOT NULL,
|
||||||
|
`created_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `opkssh_tokens` (
|
||||||
|
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
|
||||||
|
`user_id` text NOT NULL,
|
||||||
|
`host_id` integer NOT NULL,
|
||||||
|
`ssh_cert` text(8192) NOT NULL,
|
||||||
|
`private_key` text(8192) NOT NULL,
|
||||||
|
`email` text,
|
||||||
|
`sub` text,
|
||||||
|
`issuer` text,
|
||||||
|
`audience` text,
|
||||||
|
`created_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
`expires_at` text NOT NULL,
|
||||||
|
`last_used` text,
|
||||||
|
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade,
|
||||||
|
FOREIGN KEY (`host_id`) REFERENCES `ssh_data`(`id`) ON UPDATE no action ON DELETE cascade
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE UNIQUE INDEX `idx_opkssh_tokens_user_host` ON `opkssh_tokens` (`user_id`,`host_id`);--> statement-breakpoint
|
||||||
|
CREATE TABLE `recent_activity` (
|
||||||
|
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
|
||||||
|
`user_id` text NOT NULL,
|
||||||
|
`type` text NOT NULL,
|
||||||
|
`host_id` integer NOT NULL,
|
||||||
|
`host_name` text,
|
||||||
|
`timestamp` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade,
|
||||||
|
FOREIGN KEY (`host_id`) REFERENCES `ssh_data`(`id`) ON UPDATE no action ON DELETE cascade
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `roles` (
|
||||||
|
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
|
||||||
|
`name` text NOT NULL,
|
||||||
|
`display_name` text NOT NULL,
|
||||||
|
`description` text,
|
||||||
|
`is_system` integer DEFAULT false NOT NULL,
|
||||||
|
`permissions` text,
|
||||||
|
`created_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
`updated_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE UNIQUE INDEX `roles_name_unique` ON `roles` (`name`);--> statement-breakpoint
|
||||||
|
CREATE TABLE `session_recordings` (
|
||||||
|
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
|
||||||
|
`host_id` integer NOT NULL,
|
||||||
|
`user_id` text,
|
||||||
|
`username` text,
|
||||||
|
`access_id` integer,
|
||||||
|
`started_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
`ended_at` text,
|
||||||
|
`duration` integer,
|
||||||
|
`commands` text,
|
||||||
|
`dangerous_actions` text,
|
||||||
|
`recording_path` text,
|
||||||
|
`protocol` text DEFAULT 'ssh' NOT NULL,
|
||||||
|
`format` text DEFAULT 'text' NOT NULL,
|
||||||
|
`terminated_by_owner` integer DEFAULT false,
|
||||||
|
`termination_reason` text,
|
||||||
|
FOREIGN KEY (`host_id`) REFERENCES `ssh_data`(`id`) ON UPDATE no action ON DELETE cascade,
|
||||||
|
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE set null,
|
||||||
|
FOREIGN KEY (`access_id`) REFERENCES `host_access`(`id`) ON UPDATE no action ON DELETE set null
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `session_share_participants` (
|
||||||
|
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
|
||||||
|
`share_id` text NOT NULL,
|
||||||
|
`user_id` text,
|
||||||
|
`guest_label` text,
|
||||||
|
`joined_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
`left_at` text,
|
||||||
|
FOREIGN KEY (`share_id`) REFERENCES `session_shares`(`id`) ON UPDATE no action ON DELETE cascade,
|
||||||
|
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `session_shares` (
|
||||||
|
`id` text PRIMARY KEY NOT NULL,
|
||||||
|
`host_id` integer NOT NULL,
|
||||||
|
`owner_user_id` text NOT NULL,
|
||||||
|
`protocol` text NOT NULL,
|
||||||
|
`session_id` text NOT NULL,
|
||||||
|
`tab_instance_id` text,
|
||||||
|
`share_type` text NOT NULL,
|
||||||
|
`target_user_id` text,
|
||||||
|
`link_token` text,
|
||||||
|
`permission_level` text DEFAULT 'read-only' NOT NULL,
|
||||||
|
`created_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
`expires_at` text NOT NULL,
|
||||||
|
`revoked_at` text,
|
||||||
|
`last_joined_at` text,
|
||||||
|
`join_count` integer DEFAULT 0 NOT NULL,
|
||||||
|
FOREIGN KEY (`host_id`) REFERENCES `ssh_data`(`id`) ON UPDATE no action ON DELETE cascade,
|
||||||
|
FOREIGN KEY (`owner_user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade,
|
||||||
|
FOREIGN KEY (`target_user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE UNIQUE INDEX `session_shares_link_token_unique` ON `session_shares` (`link_token`);--> statement-breakpoint
|
||||||
|
CREATE TABLE `sessions` (
|
||||||
|
`id` text PRIMARY KEY NOT NULL,
|
||||||
|
`user_id` text NOT NULL,
|
||||||
|
`jwt_token` text NOT NULL,
|
||||||
|
`device_type` text NOT NULL,
|
||||||
|
`device_info` text NOT NULL,
|
||||||
|
`oidc_sub` text,
|
||||||
|
`oidc_sid` text,
|
||||||
|
`sso_provider_id` integer,
|
||||||
|
`created_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
`expires_at` text NOT NULL,
|
||||||
|
`last_active_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `settings` (
|
||||||
|
`key` text PRIMARY KEY NOT NULL,
|
||||||
|
`value` text NOT NULL
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `shared_host_auth_overrides` (
|
||||||
|
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
|
||||||
|
`host_id` integer NOT NULL,
|
||||||
|
`user_id` text NOT NULL,
|
||||||
|
`protocol` text DEFAULT 'ssh' NOT NULL,
|
||||||
|
`credential_id` integer NOT NULL,
|
||||||
|
`created_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
`updated_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
FOREIGN KEY (`host_id`) REFERENCES `ssh_data`(`id`) ON UPDATE no action ON DELETE cascade,
|
||||||
|
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade,
|
||||||
|
FOREIGN KEY (`credential_id`) REFERENCES `ssh_credentials`(`id`) ON UPDATE no action ON DELETE cascade
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE UNIQUE INDEX `shared_host_auth_overrides_host_user_protocol_unique` ON `shared_host_auth_overrides` (`host_id`,`user_id`,`protocol`);--> statement-breakpoint
|
||||||
|
CREATE TABLE `shared_host_secrets` (
|
||||||
|
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
|
||||||
|
`host_access_id` integer NOT NULL,
|
||||||
|
`target_user_id` text NOT NULL,
|
||||||
|
`protocol` text DEFAULT 'ssh' NOT NULL,
|
||||||
|
`source_type` text DEFAULT 'credential' NOT NULL,
|
||||||
|
`original_credential_id` integer,
|
||||||
|
`encrypted_username` text,
|
||||||
|
`encrypted_auth_type` text,
|
||||||
|
`encrypted_password` text,
|
||||||
|
`encrypted_key` text(16384),
|
||||||
|
`encrypted_key_password` text,
|
||||||
|
`encrypted_key_type` text,
|
||||||
|
`encrypted_domain` text,
|
||||||
|
`created_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
`updated_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
FOREIGN KEY (`host_access_id`) REFERENCES `host_access`(`id`) ON UPDATE no action ON DELETE cascade,
|
||||||
|
FOREIGN KEY (`target_user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade,
|
||||||
|
FOREIGN KEY (`original_credential_id`) REFERENCES `ssh_credentials`(`id`) ON UPDATE no action ON DELETE cascade
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE UNIQUE INDEX `idx_shared_host_secrets_scope` ON `shared_host_secrets` (`host_access_id`,`target_user_id`,`protocol`);--> statement-breakpoint
|
||||||
|
CREATE TABLE `snippet_access` (
|
||||||
|
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
|
||||||
|
`snippet_id` integer NOT NULL,
|
||||||
|
`user_id` text,
|
||||||
|
`role_id` integer,
|
||||||
|
`granted_by` text NOT NULL,
|
||||||
|
`permission_level` text DEFAULT 'view' NOT NULL,
|
||||||
|
`expires_at` text,
|
||||||
|
`created_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
FOREIGN KEY (`snippet_id`) REFERENCES `snippets`(`id`) ON UPDATE no action ON DELETE cascade,
|
||||||
|
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade,
|
||||||
|
FOREIGN KEY (`role_id`) REFERENCES `roles`(`id`) ON UPDATE no action ON DELETE cascade,
|
||||||
|
FOREIGN KEY (`granted_by`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `snippet_folders` (
|
||||||
|
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
|
||||||
|
`user_id` text NOT NULL,
|
||||||
|
`name` text NOT NULL,
|
||||||
|
`color` text,
|
||||||
|
`icon` text,
|
||||||
|
`sync_id` text,
|
||||||
|
`created_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
`updated_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE UNIQUE INDEX `snippet_folders_sync_id_unique` ON `snippet_folders` (`sync_id`);--> statement-breakpoint
|
||||||
|
CREATE TABLE `snippets` (
|
||||||
|
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
|
||||||
|
`user_id` text NOT NULL,
|
||||||
|
`name` text NOT NULL,
|
||||||
|
`content` text NOT NULL,
|
||||||
|
`description` text,
|
||||||
|
`folder` text,
|
||||||
|
`order` integer DEFAULT 0 NOT NULL,
|
||||||
|
`sync_id` text,
|
||||||
|
`created_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
`updated_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
`host_filter` text,
|
||||||
|
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE UNIQUE INDEX `snippets_sync_id_unique` ON `snippets` (`sync_id`);--> statement-breakpoint
|
||||||
|
CREATE TABLE `ssh_credential_usage` (
|
||||||
|
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
|
||||||
|
`credential_id` integer NOT NULL,
|
||||||
|
`host_id` integer NOT NULL,
|
||||||
|
`user_id` text NOT NULL,
|
||||||
|
`used_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
FOREIGN KEY (`credential_id`) REFERENCES `ssh_credentials`(`id`) ON UPDATE no action ON DELETE cascade,
|
||||||
|
FOREIGN KEY (`host_id`) REFERENCES `ssh_data`(`id`) ON UPDATE no action ON DELETE cascade,
|
||||||
|
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `ssh_credentials` (
|
||||||
|
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
|
||||||
|
`user_id` text NOT NULL,
|
||||||
|
`name` text NOT NULL,
|
||||||
|
`description` text,
|
||||||
|
`folder` text,
|
||||||
|
`tags` text,
|
||||||
|
`auth_type` text NOT NULL,
|
||||||
|
`username` text,
|
||||||
|
`password` text,
|
||||||
|
`key` text(16384),
|
||||||
|
`private_key` text(16384),
|
||||||
|
`public_key` text(4096),
|
||||||
|
`key_password` text,
|
||||||
|
`key_type` text,
|
||||||
|
`detected_key_type` text,
|
||||||
|
`cert_public_key` text(8192),
|
||||||
|
`usage_count` integer DEFAULT 0 NOT NULL,
|
||||||
|
`last_used` text,
|
||||||
|
`sync_id` text,
|
||||||
|
`created_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
`updated_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE UNIQUE INDEX `ssh_credentials_sync_id_unique` ON `ssh_credentials` (`sync_id`);--> statement-breakpoint
|
||||||
|
CREATE TABLE `ssh_folders` (
|
||||||
|
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
|
||||||
|
`user_id` text NOT NULL,
|
||||||
|
`name` text NOT NULL,
|
||||||
|
`color` text,
|
||||||
|
`icon` text,
|
||||||
|
`credential_id` integer,
|
||||||
|
`sync_id` text,
|
||||||
|
`created_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
`updated_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade,
|
||||||
|
FOREIGN KEY (`credential_id`) REFERENCES `ssh_credentials`(`id`) ON UPDATE no action ON DELETE set null
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE UNIQUE INDEX `ssh_folders_sync_id_unique` ON `ssh_folders` (`sync_id`);--> statement-breakpoint
|
||||||
|
CREATE TABLE `sso_providers` (
|
||||||
|
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
|
||||||
|
`name` text NOT NULL,
|
||||||
|
`type` text NOT NULL,
|
||||||
|
`enabled` integer DEFAULT true NOT NULL,
|
||||||
|
`display_order` integer DEFAULT 0 NOT NULL,
|
||||||
|
`config` text NOT NULL,
|
||||||
|
`created_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
`updated_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `sync_tombstones` (
|
||||||
|
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
|
||||||
|
`user_id` text NOT NULL,
|
||||||
|
`entity_type` text NOT NULL,
|
||||||
|
`sync_id` text NOT NULL,
|
||||||
|
`deleted_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `termix_identities` (
|
||||||
|
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
|
||||||
|
`user_id` text NOT NULL,
|
||||||
|
`handle` text NOT NULL,
|
||||||
|
`description` text,
|
||||||
|
`created_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
`updated_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE UNIQUE INDEX `termix_identities_user_id_unique` ON `termix_identities` (`user_id`);--> statement-breakpoint
|
||||||
|
CREATE UNIQUE INDEX `termix_identities_handle_unique` ON `termix_identities` (`handle`);--> statement-breakpoint
|
||||||
|
CREATE TABLE `termix_identity_ca` (
|
||||||
|
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
|
||||||
|
`identity_id` integer NOT NULL,
|
||||||
|
`user_id` text NOT NULL,
|
||||||
|
`public_key` text(4096) NOT NULL,
|
||||||
|
`private_key` text(8192) NOT NULL,
|
||||||
|
`validity_days` integer DEFAULT 90 NOT NULL,
|
||||||
|
`created_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
`updated_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
FOREIGN KEY (`identity_id`) REFERENCES `termix_identities`(`id`) ON UPDATE no action ON DELETE cascade,
|
||||||
|
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE UNIQUE INDEX `termix_identity_ca_identity_id_unique` ON `termix_identity_ca` (`identity_id`);--> statement-breakpoint
|
||||||
|
CREATE TABLE `termix_identity_keys` (
|
||||||
|
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
|
||||||
|
`identity_id` integer NOT NULL,
|
||||||
|
`user_id` text NOT NULL,
|
||||||
|
`public_key` text(8192) NOT NULL,
|
||||||
|
`key_type` text NOT NULL,
|
||||||
|
`algorithm` text NOT NULL,
|
||||||
|
`label` text,
|
||||||
|
`comment` text,
|
||||||
|
`source` text DEFAULT 'manual' NOT NULL,
|
||||||
|
`credential_id` integer,
|
||||||
|
`enabled` integer DEFAULT true NOT NULL,
|
||||||
|
`created_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
FOREIGN KEY (`identity_id`) REFERENCES `termix_identities`(`id`) ON UPDATE no action ON DELETE cascade,
|
||||||
|
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade,
|
||||||
|
FOREIGN KEY (`credential_id`) REFERENCES `ssh_credentials`(`id`) ON UPDATE no action ON DELETE set null
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `tmux_session_tags` (
|
||||||
|
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
|
||||||
|
`user_id` text NOT NULL,
|
||||||
|
`host_id` integer NOT NULL,
|
||||||
|
`session_name` text NOT NULL,
|
||||||
|
`tag` text NOT NULL,
|
||||||
|
`created_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade,
|
||||||
|
FOREIGN KEY (`host_id`) REFERENCES `ssh_data`(`id`) ON UPDATE no action ON DELETE cascade
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `transfer_recent` (
|
||||||
|
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
|
||||||
|
`user_id` text NOT NULL,
|
||||||
|
`source_host_id` integer NOT NULL,
|
||||||
|
`dest_host_id` integer NOT NULL,
|
||||||
|
`dest_path` text NOT NULL,
|
||||||
|
`dest_path_label` text NOT NULL,
|
||||||
|
`last_used` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade,
|
||||||
|
FOREIGN KEY (`source_host_id`) REFERENCES `ssh_data`(`id`) ON UPDATE no action ON DELETE cascade,
|
||||||
|
FOREIGN KEY (`dest_host_id`) REFERENCES `ssh_data`(`id`) ON UPDATE no action ON DELETE cascade
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `trusted_devices` (
|
||||||
|
`id` text PRIMARY KEY NOT NULL,
|
||||||
|
`user_id` text NOT NULL,
|
||||||
|
`device_fingerprint` text NOT NULL,
|
||||||
|
`device_type` text NOT NULL,
|
||||||
|
`device_info` text NOT NULL,
|
||||||
|
`created_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
`expires_at` text NOT NULL,
|
||||||
|
`last_used_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `user_open_tabs` (
|
||||||
|
`id` text PRIMARY KEY NOT NULL,
|
||||||
|
`user_id` text NOT NULL,
|
||||||
|
`tab_type` text NOT NULL,
|
||||||
|
`host_id` integer,
|
||||||
|
`label` text NOT NULL,
|
||||||
|
`tab_order` integer DEFAULT 0 NOT NULL,
|
||||||
|
`backend_session_id` text,
|
||||||
|
`created_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
`updated_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade,
|
||||||
|
FOREIGN KEY (`host_id`) REFERENCES `ssh_data`(`id`) ON UPDATE no action ON DELETE cascade
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `user_preferences` (
|
||||||
|
`user_id` text PRIMARY KEY NOT NULL,
|
||||||
|
`reopen_tabs_on_login` integer DEFAULT false NOT NULL,
|
||||||
|
`theme` text,
|
||||||
|
`font_size` text,
|
||||||
|
`accent_color` text,
|
||||||
|
`language` text,
|
||||||
|
`storage_mode` text,
|
||||||
|
`command_autocomplete` integer,
|
||||||
|
`command_palette_enabled` integer,
|
||||||
|
`show_host_tags` integer,
|
||||||
|
`host_tray_on_click` integer,
|
||||||
|
`pin_app_rail` integer,
|
||||||
|
`expand_app_rail_on_hover` integer,
|
||||||
|
`folders_collapsed` integer,
|
||||||
|
`confirm_snippet_execution` integer,
|
||||||
|
`disable_update_check` integer,
|
||||||
|
`confirm_tab_close` integer,
|
||||||
|
`hidden_rail_tabs` text,
|
||||||
|
`compact_host_view` integer,
|
||||||
|
`status_color_scheme` text,
|
||||||
|
`custom_themes` text,
|
||||||
|
`custom_keybindings` text,
|
||||||
|
`updated_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `user_roles` (
|
||||||
|
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
|
||||||
|
`user_id` text NOT NULL,
|
||||||
|
`role_id` integer NOT NULL,
|
||||||
|
`granted_by` text,
|
||||||
|
`granted_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade,
|
||||||
|
FOREIGN KEY (`role_id`) REFERENCES `roles`(`id`) ON UPDATE no action ON DELETE cascade,
|
||||||
|
FOREIGN KEY (`granted_by`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE set null
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE UNIQUE INDEX `idx_user_roles_user_role` ON `user_roles` (`user_id`,`role_id`);--> statement-breakpoint
|
||||||
|
CREATE TABLE `users` (
|
||||||
|
`id` text PRIMARY KEY NOT NULL,
|
||||||
|
`username` text NOT NULL,
|
||||||
|
`password_hash` text NOT NULL,
|
||||||
|
`is_admin` integer DEFAULT false NOT NULL,
|
||||||
|
`is_oidc` integer DEFAULT false NOT NULL,
|
||||||
|
`oidc_identifier` text,
|
||||||
|
`sso_provider_id` integer,
|
||||||
|
`client_id` text,
|
||||||
|
`client_secret` text,
|
||||||
|
`issuer_url` text,
|
||||||
|
`authorization_url` text,
|
||||||
|
`token_url` text,
|
||||||
|
`identifier_path` text,
|
||||||
|
`name_path` text,
|
||||||
|
`scopes` text DEFAULT 'openid email profile',
|
||||||
|
`totp_secret` text,
|
||||||
|
`totp_enabled` integer DEFAULT false NOT NULL,
|
||||||
|
`totp_backup_codes` text,
|
||||||
|
`registered_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
`donation_modal_dismissed` integer DEFAULT false NOT NULL
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE TABLE `vault_profiles` (
|
||||||
|
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
|
||||||
|
`user_id` text NOT NULL,
|
||||||
|
`name` text NOT NULL,
|
||||||
|
`description` text,
|
||||||
|
`folder` text,
|
||||||
|
`tags` text,
|
||||||
|
`vault_addr` text NOT NULL,
|
||||||
|
`vault_namespace` text,
|
||||||
|
`oidc_mount` text,
|
||||||
|
`oidc_role` text,
|
||||||
|
`ssh_mount` text,
|
||||||
|
`ssh_role` text NOT NULL,
|
||||||
|
`valid_principals` text,
|
||||||
|
`key_type` text,
|
||||||
|
`shared` integer DEFAULT false NOT NULL,
|
||||||
|
`sync_id` text,
|
||||||
|
`created_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
`updated_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE UNIQUE INDEX `vault_profiles_sync_id_unique` ON `vault_profiles` (`sync_id`);--> statement-breakpoint
|
||||||
|
CREATE TABLE `vault_tokens` (
|
||||||
|
`id` integer PRIMARY KEY AUTOINCREMENT NOT NULL,
|
||||||
|
`user_id` text NOT NULL,
|
||||||
|
`profile_id` integer NOT NULL,
|
||||||
|
`ssh_cert` text(8192) NOT NULL,
|
||||||
|
`private_key` text(8192) NOT NULL,
|
||||||
|
`created_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
`expires_at` text NOT NULL,
|
||||||
|
`last_used` text,
|
||||||
|
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade,
|
||||||
|
FOREIGN KEY (`profile_id`) REFERENCES `vault_profiles`(`id`) ON UPDATE no action ON DELETE cascade
|
||||||
|
);
|
||||||
|
--> statement-breakpoint
|
||||||
|
CREATE UNIQUE INDEX `idx_vault_tokens_user_profile` ON `vault_tokens` (`user_id`,`profile_id`);--> statement-breakpoint
|
||||||
|
CREATE TABLE `webauthn_credentials` (
|
||||||
|
`id` text PRIMARY KEY NOT NULL,
|
||||||
|
`user_id` text NOT NULL,
|
||||||
|
`name` text NOT NULL,
|
||||||
|
`credential_id` text NOT NULL,
|
||||||
|
`public_key` text NOT NULL,
|
||||||
|
`counter` integer DEFAULT 0 NOT NULL,
|
||||||
|
`device_type` text,
|
||||||
|
`backed_up` integer DEFAULT false NOT NULL,
|
||||||
|
`transports` text,
|
||||||
|
`user_verification` text DEFAULT 'preferred' NOT NULL,
|
||||||
|
`created_at` text DEFAULT CURRENT_TIMESTAMP NOT NULL,
|
||||||
|
`last_used_at` text,
|
||||||
|
FOREIGN KEY (`user_id`) REFERENCES `users`(`id`) ON UPDATE no action ON DELETE cascade
|
||||||
|
);
|
||||||
File diff suppressed because it is too large
Load Diff
@@ -0,0 +1,13 @@
|
|||||||
|
{
|
||||||
|
"version": "7",
|
||||||
|
"dialect": "sqlite",
|
||||||
|
"entries": [
|
||||||
|
{
|
||||||
|
"idx": 0,
|
||||||
|
"version": "6",
|
||||||
|
"when": 1785738870735,
|
||||||
|
"tag": "0000_clever_hercules",
|
||||||
|
"breakpoints": true
|
||||||
|
}
|
||||||
|
]
|
||||||
|
}
|
||||||
@@ -0,0 +1,8 @@
|
|||||||
|
function getUnpackedAppRoot(appRoot) {
|
||||||
|
return appRoot.replace(
|
||||||
|
/app(-[a-z0-9]+)?\.asar(?!\.unpacked)/,
|
||||||
|
"app$1.asar.unpacked",
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
module.exports = { getUnpackedAppRoot };
|
||||||
+6
-4
@@ -12,6 +12,7 @@ const {
|
|||||||
nativeImage,
|
nativeImage,
|
||||||
} = require("electron");
|
} = require("electron");
|
||||||
const path = require("path");
|
const path = require("path");
|
||||||
|
const { getUnpackedAppRoot } = require("./backend-paths.cjs");
|
||||||
const fs = require("fs");
|
const fs = require("fs");
|
||||||
const os = require("os");
|
const os = require("os");
|
||||||
const https = require("https");
|
const https = require("https");
|
||||||
@@ -800,10 +801,7 @@ function getBackendPaths() {
|
|||||||
// fork() does not go through Electron's asar redirector — use the unpacked path.
|
// fork() does not go through Electron's asar redirector — use the unpacked path.
|
||||||
// On macOS multi-arch builds (mergeASARs: false), electron-builder names the ASAR
|
// On macOS multi-arch builds (mergeASARs: false), electron-builder names the ASAR
|
||||||
// app-arm64.asar / app-x64.asar instead of app.asar, so match all variants.
|
// app-arm64.asar / app-x64.asar instead of app.asar, so match all variants.
|
||||||
const unpackedRoot = appRoot.replace(
|
const unpackedRoot = getUnpackedAppRoot(appRoot);
|
||||||
/app(-[a-z0-9]+)?\.asar(?!\.unpacked)/,
|
|
||||||
"app.asar.unpacked",
|
|
||||||
);
|
|
||||||
const backendDir = path.join(unpackedRoot, "dist", "backend", "backend");
|
const backendDir = path.join(unpackedRoot, "dist", "backend", "backend");
|
||||||
return {
|
return {
|
||||||
entryPath: path.join(backendDir, "starter.js"),
|
entryPath: path.join(backendDir, "starter.js"),
|
||||||
@@ -1581,6 +1579,10 @@ ipcMain.handle("get-remote-sync-status", () => {
|
|||||||
return remoteSync.getRemoteSyncEngine()?.status || null;
|
return remoteSync.getRemoteSyncEngine()?.status || null;
|
||||||
});
|
});
|
||||||
|
|
||||||
|
ipcMain.handle("get-remote-sync-user-info", () => {
|
||||||
|
return remoteSync.getRemoteSyncUserInfo();
|
||||||
|
});
|
||||||
|
|
||||||
ipcMain.handle("remote-sync-now", async () => {
|
ipcMain.handle("remote-sync-now", async () => {
|
||||||
return (await remoteSync.getRemoteSyncEngine()?.syncNow()) || null;
|
return (await remoteSync.getRemoteSyncEngine()?.syncNow()) || null;
|
||||||
});
|
});
|
||||||
|
|||||||
@@ -0,0 +1,15 @@
|
|||||||
|
const SYNCED_ENTITY_TYPES = Object.freeze([
|
||||||
|
// Ordered by reference dependency: hosts and snippets resolve credential,
|
||||||
|
// vault and folder syncIds, so those have to exist on the other side first.
|
||||||
|
"sshCredentials",
|
||||||
|
"vaultProfiles",
|
||||||
|
"sshFolders",
|
||||||
|
"snippetFolders",
|
||||||
|
"hosts",
|
||||||
|
"snippets",
|
||||||
|
"dashboardServiceLinks",
|
||||||
|
"homepageItems",
|
||||||
|
"userPreferences",
|
||||||
|
]);
|
||||||
|
|
||||||
|
module.exports = { SYNCED_ENTITY_TYPES };
|
||||||
+84
-27
@@ -14,17 +14,7 @@
|
|||||||
const { app, safeStorage } = require("electron");
|
const { app, safeStorage } = require("electron");
|
||||||
const fs = require("fs");
|
const fs = require("fs");
|
||||||
const path = require("path");
|
const path = require("path");
|
||||||
|
const { SYNCED_ENTITY_TYPES } = require("./remote-sync-entities.cjs");
|
||||||
const SYNCED_ENTITY_TYPES = [
|
|
||||||
"hosts",
|
|
||||||
"sshCredentials",
|
|
||||||
"sshFolders",
|
|
||||||
"snippets",
|
|
||||||
"snippetFolders",
|
|
||||||
"vaultProfiles",
|
|
||||||
"dashboardServiceLinks",
|
|
||||||
"homepageItems",
|
|
||||||
];
|
|
||||||
|
|
||||||
const SYNC_INTERVAL_MS = 90 * 1000;
|
const SYNC_INTERVAL_MS = 90 * 1000;
|
||||||
const EMBEDDED_BASE_URL = "http://127.0.0.1:30001";
|
const EMBEDDED_BASE_URL = "http://127.0.0.1:30001";
|
||||||
@@ -135,6 +125,41 @@ function clearRemoteSyncJwt() {
|
|||||||
return { success: true };
|
return { success: true };
|
||||||
}
|
}
|
||||||
|
|
||||||
|
async function getRemoteSyncUserInfo() {
|
||||||
|
const config = getRemoteSyncConfig();
|
||||||
|
const token = getRemoteSyncJwt();
|
||||||
|
if (!config?.serverUrl || !token || isJwtExpiredOrExpiringSoon(token)) {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
const baseUrl = config.serverUrl.replace(/\/$/, "");
|
||||||
|
const userResponse = await fetch(`${baseUrl}/users/me`, {
|
||||||
|
headers: { Authorization: `Bearer ${token}`, "X-Electron-App": "true" },
|
||||||
|
});
|
||||||
|
if (!userResponse.ok) return null;
|
||||||
|
|
||||||
|
const user = await userResponse.json();
|
||||||
|
const rolesResponse = await fetch(
|
||||||
|
`${baseUrl}/rbac/users/${encodeURIComponent(user.userId)}/roles`,
|
||||||
|
{
|
||||||
|
headers: { Authorization: `Bearer ${token}`, "X-Electron-App": "true" },
|
||||||
|
},
|
||||||
|
);
|
||||||
|
const roles = rolesResponse.ok
|
||||||
|
? (await rolesResponse.json()).roles || []
|
||||||
|
: [];
|
||||||
|
|
||||||
|
return {
|
||||||
|
userId: user.userId,
|
||||||
|
username: user.username,
|
||||||
|
is_admin: !!user.is_admin,
|
||||||
|
is_oidc: !!user.is_oidc,
|
||||||
|
is_dual_auth: !!user.is_dual_auth,
|
||||||
|
totp_enabled: !!user.totp_enabled,
|
||||||
|
roles,
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
function decodeJwtExpiry(token) {
|
function decodeJwtExpiry(token) {
|
||||||
try {
|
try {
|
||||||
const payloadB64 = token.split(".")[1];
|
const payloadB64 = token.split(".")[1];
|
||||||
@@ -373,6 +398,15 @@ class RemoteSyncEngine {
|
|||||||
return data.rows || [];
|
return data.rows || [];
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Every syncId a side currently holds, ignoring the incremental window.
|
||||||
|
* Used only to decide whether a deletion still has something to delete.
|
||||||
|
*/
|
||||||
|
async pullSyncIds(baseUrl, token, entityType) {
|
||||||
|
const rows = await this.pullSide(baseUrl, token, entityType, null);
|
||||||
|
return new Set(rows.filter((row) => row.syncId).map((row) => row.syncId));
|
||||||
|
}
|
||||||
|
|
||||||
async pullTombstones(baseUrl, token, entityType, since) {
|
async pullTombstones(baseUrl, token, entityType, since) {
|
||||||
const url = `${baseUrl}/sync/${entityType}/tombstones${since ? `?since=${encodeURIComponent(since)}` : ""}`;
|
const url = `${baseUrl}/sync/${entityType}/tombstones${since ? `?since=${encodeURIComponent(since)}` : ""}`;
|
||||||
const data = await this.fetchJson(url, token);
|
const data = await this.fetchJson(url, token);
|
||||||
@@ -457,24 +491,46 @@ class RemoteSyncEngine {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// Apply tombstones to whichever side hasn't already deleted the row.
|
// Apply tombstones to whichever side hasn't already deleted the row.
|
||||||
for (const tombstone of localTombstones) {
|
//
|
||||||
if (remoteBySyncId.has(tombstone.syncId)) {
|
// The presence check cannot use localRows/remoteRows: those are the
|
||||||
await this.pushTombstone(
|
// incremental window, and a row deleted on one side while untouched on
|
||||||
remoteBaseUrl,
|
// the other is by definition outside it, so every deletion was dropped.
|
||||||
remoteJwt,
|
// It also cannot be skipped -- pushing unconditionally makes the
|
||||||
entityType,
|
// receiving side record a fresh tombstone, which the next pass would push
|
||||||
tombstone.syncId,
|
// back, forever. So ask the receiving side what it actually still holds,
|
||||||
);
|
// and only when there is a deletion to apply.
|
||||||
|
if (localTombstones.length) {
|
||||||
|
const remoteSyncIds = await this.pullSyncIds(
|
||||||
|
remoteBaseUrl,
|
||||||
|
remoteJwt,
|
||||||
|
entityType,
|
||||||
|
);
|
||||||
|
for (const tombstone of localTombstones) {
|
||||||
|
if (remoteSyncIds.has(tombstone.syncId)) {
|
||||||
|
await this.pushTombstone(
|
||||||
|
remoteBaseUrl,
|
||||||
|
remoteJwt,
|
||||||
|
entityType,
|
||||||
|
tombstone.syncId,
|
||||||
|
);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
for (const tombstone of remoteTombstones) {
|
if (remoteTombstones.length) {
|
||||||
if (localBySyncId.has(tombstone.syncId)) {
|
const localSyncIds = await this.pullSyncIds(
|
||||||
await this.pushTombstone(
|
EMBEDDED_BASE_URL,
|
||||||
EMBEDDED_BASE_URL,
|
this.localJwt,
|
||||||
this.localJwt,
|
entityType,
|
||||||
entityType,
|
);
|
||||||
tombstone.syncId,
|
for (const tombstone of remoteTombstones) {
|
||||||
);
|
if (localSyncIds.has(tombstone.syncId)) {
|
||||||
|
await this.pushTombstone(
|
||||||
|
EMBEDDED_BASE_URL,
|
||||||
|
this.localJwt,
|
||||||
|
entityType,
|
||||||
|
tombstone.syncId,
|
||||||
|
);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -511,6 +567,7 @@ module.exports = {
|
|||||||
saveRemoteSyncJwt,
|
saveRemoteSyncJwt,
|
||||||
getRemoteSyncJwt,
|
getRemoteSyncJwt,
|
||||||
clearRemoteSyncJwt,
|
clearRemoteSyncJwt,
|
||||||
|
getRemoteSyncUserInfo,
|
||||||
isJwtExpiredOrExpiringSoon,
|
isJwtExpiredOrExpiringSoon,
|
||||||
decodeJwtExpiry,
|
decodeJwtExpiry,
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -46,4 +46,57 @@ export default tseslint.config([
|
|||||||
"react-refresh/only-export-components": "warn",
|
"react-refresh/only-export-components": "warn",
|
||||||
},
|
},
|
||||||
},
|
},
|
||||||
|
{
|
||||||
|
// MySQL has no RETURNING clause, and drizzle's mysql-core does not expose
|
||||||
|
// the method at all — a bare .returning() is a TypeError there, not a bad
|
||||||
|
// query, and it only fails on the engine no test in this repo runs against.
|
||||||
|
//
|
||||||
|
// 175 call sites were migrated off it. This is what stops number 176.
|
||||||
|
// Writes that need rows back go through repositories/returning.ts, which
|
||||||
|
// picks one statement or a read-then-write transaction per dialect.
|
||||||
|
files: ["src/backend/database/repositories/**/*.ts"],
|
||||||
|
ignores: [
|
||||||
|
// The two files whose job is to absorb these differences.
|
||||||
|
"src/backend/database/repositories/returning.ts",
|
||||||
|
"src/backend/database/repositories/mutation-result.ts",
|
||||||
|
],
|
||||||
|
rules: {
|
||||||
|
"no-restricted-syntax": [
|
||||||
|
"error",
|
||||||
|
{
|
||||||
|
selector: "CallExpression[callee.property.name='returning']",
|
||||||
|
message:
|
||||||
|
"MySQL has no RETURNING. Use insertReturning/updateReturning/deleteReturning from ./returning.js, or rowsAffected() if you only need a count. Inside a proven sqlite-only branch, disable this rule with a comment saying so.",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
// `||` concatenates on SQLite and Postgres. On MySQL it is logical OR
|
||||||
|
// unless the server runs with PIPES_AS_CONCAT, so a folder path built
|
||||||
|
// this way silently became 0. Use CONCAT, which all three agree on.
|
||||||
|
selector:
|
||||||
|
"TaggedTemplateExpression[tag.name='sql'] TemplateElement[value.raw=/\\|\\|/]",
|
||||||
|
message:
|
||||||
|
"`||` is logical OR on MySQL, not concatenation. Use CONCAT(...).",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
// Postgres and SQLite spell it ON CONFLICT; MySQL spells it ON
|
||||||
|
// DUPLICATE KEY and names no columns, so drizzle's mysql-core has no
|
||||||
|
// onConflictDoUpdate at all — another TypeError, not a bad query.
|
||||||
|
selector: "CallExpression[callee.property.name='onConflictDoUpdate']",
|
||||||
|
message:
|
||||||
|
"MySQL has no ON CONFLICT. Use upsert() from ./returning.js.",
|
||||||
|
},
|
||||||
|
{
|
||||||
|
// better-sqlite3 puts these on a write result; node-postgres and
|
||||||
|
// mysql2 do not, so reading them directly yields undefined — and
|
||||||
|
// Number(undefined) is NaN, which reaches the database as the string
|
||||||
|
// "NaN" and fails an integer column. Three call sites did exactly
|
||||||
|
// this and only broke on Postgres.
|
||||||
|
selector:
|
||||||
|
"MemberExpression[property.name=/^(lastInsertRowid|changes)$/]",
|
||||||
|
message:
|
||||||
|
"lastInsertRowid and changes are better-sqlite3 only. Use insertedId() or rowsAffected() from ./mutation-result.js.",
|
||||||
|
},
|
||||||
|
],
|
||||||
|
},
|
||||||
|
},
|
||||||
]);
|
]);
|
||||||
|
|||||||
Generated
+2654
-1689
File diff suppressed because it is too large
Load Diff
+62
-53
@@ -1,7 +1,7 @@
|
|||||||
{
|
{
|
||||||
"name": "termix",
|
"name": "termix",
|
||||||
"private": true,
|
"private": true,
|
||||||
"version": "2.6.0",
|
"version": "2.6.1",
|
||||||
"description": "Self-hosted SSH and remote desktop management.",
|
"description": "Self-hosted SSH and remote desktop management.",
|
||||||
"author": "Karmaa",
|
"author": "Karmaa",
|
||||||
"main": "electron/main.cjs",
|
"main": "electron/main.cjs",
|
||||||
@@ -16,10 +16,11 @@
|
|||||||
"biome:fix": "biome check --write biome.json package.json",
|
"biome:fix": "biome check --write biome.json package.json",
|
||||||
"postinstall": "node scripts/patch-app-builder-lib.cjs && node scripts/patch-guacamole-lite.cjs && node scripts/patch-guacamole-common-js.cjs && node scripts/patch-better-sqlite3.cjs && node scripts/patch-nan.cjs && node scripts/patch-xterm-android-ime.cjs",
|
"postinstall": "node scripts/patch-app-builder-lib.cjs && node scripts/patch-guacamole-lite.cjs && node scripts/patch-guacamole-common-js.cjs && node scripts/patch-better-sqlite3.cjs && node scripts/patch-nan.cjs && node scripts/patch-xterm-android-ime.cjs",
|
||||||
"prebuild": "node scripts/write-electron-build-info.cjs",
|
"prebuild": "node scripts/write-electron-build-info.cjs",
|
||||||
"lint": "eslint .",
|
"lint": "node scripts/generate-dialect-schema.cjs --check && eslint .",
|
||||||
"lint:fix": "eslint --fix .",
|
"lint:fix": "eslint --fix .",
|
||||||
"type-check": "tsc --noEmit",
|
"type-check": "tsc --noEmit",
|
||||||
"test": "vitest run",
|
"test": "vitest run",
|
||||||
|
"verify:dialect": "tsx scripts/verify-dialects.mjs",
|
||||||
"test:watch": "vitest",
|
"test:watch": "vitest",
|
||||||
"test:ui": "vitest --ui",
|
"test:ui": "vitest --ui",
|
||||||
"test:coverage": "vitest run --coverage",
|
"test:coverage": "vitest run --coverage",
|
||||||
@@ -40,77 +41,82 @@
|
|||||||
"build:linux-appimage": "npm run build && npm run electron:rebuild && npm run electron:patch-builder && electron-builder --linux AppImage",
|
"build:linux-appimage": "npm run build && npm run electron:rebuild && npm run electron:patch-builder && electron-builder --linux AppImage",
|
||||||
"build:linux-targz": "npm run build && npm run electron:rebuild && npm run electron:patch-builder && electron-builder --linux tar.gz",
|
"build:linux-targz": "npm run build && npm run electron:rebuild && npm run electron:patch-builder && electron-builder --linux tar.gz",
|
||||||
"build:mac": "npm run build && npm run electron:rebuild && npm run electron:patch-builder && electron-builder --mac --universal",
|
"build:mac": "npm run build && npm run electron:rebuild && npm run electron:patch-builder && electron-builder --mac --universal",
|
||||||
"build:mac-dev": "npm run build && npm run electron:rebuild && npm run electron:patch-builder && electron-builder --mac dir --publish=never"
|
"build:mac-dev": "npm run build && npm run electron:rebuild && npm run electron:patch-builder && electron-builder --mac dir --publish=never",
|
||||||
|
"schema:generate": "node scripts/generate-dialect-schema.cjs",
|
||||||
|
"schema:check": "node scripts/generate-dialect-schema.cjs --check",
|
||||||
|
"schema:migrations": "drizzle-kit generate --config=drizzle.config.sqlite.ts && drizzle-kit generate --config=drizzle.config.pg.ts && drizzle-kit generate --config=drizzle.config.mysql.ts"
|
||||||
},
|
},
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@simplewebauthn/browser": "^13.3.0",
|
"@simplewebauthn/browser": "^13.3.0",
|
||||||
"@simplewebauthn/server": "^13.3.2",
|
"@simplewebauthn/server": "^13.3.2",
|
||||||
"@tanstack/react-virtual": "^3.14.6",
|
"@tanstack/react-virtual": "^3.14.9",
|
||||||
"@types/ldapjs": "^3.0.6",
|
"@types/ldapjs": "^3.0.6",
|
||||||
"axios": "^1.18.1",
|
"axios": "^1.19.0",
|
||||||
"bcryptjs": "^3.0.3",
|
"bcryptjs": "^3.0.3",
|
||||||
"better-sqlite3": "^12.11.1",
|
"better-sqlite3": "^13.0.2",
|
||||||
"body-parser": "^2.3.0",
|
"body-parser": "^2.3.0",
|
||||||
"chalk": "^5.6.2",
|
"chalk": "^6.0.0",
|
||||||
"cookie-parser": "^1.4.7",
|
"cookie-parser": "^1.4.7",
|
||||||
"cors": "^2.8.6",
|
"cors": "^2.8.6",
|
||||||
"dotenv": "^17.4.2",
|
"dotenv": "^17.4.2",
|
||||||
"drizzle-orm": "^0.45.2",
|
"drizzle-orm": "^0.45.2",
|
||||||
"express": "^5.2.1",
|
"express": "^5.2.1",
|
||||||
"guacamole-lite": "^1.2.0",
|
"guacamole-lite": "^1.2.0",
|
||||||
"jose": "^6.2.2",
|
"jose": "^6.2.5",
|
||||||
"js-yaml": "^5.2.1",
|
"js-yaml": "^5.2.2",
|
||||||
"jsonwebtoken": "^9.0.3",
|
"jsonwebtoken": "^9.0.3",
|
||||||
"jszip": "^3.10.1",
|
"jszip": "^3.10.1",
|
||||||
"ldapjs": "^3.0.7",
|
"ldapjs": "^3.0.7",
|
||||||
"motion": "^12.42.2",
|
"motion": "^12.43.0",
|
||||||
"multer": "^2.2.0",
|
"multer": "^2.2.0",
|
||||||
|
"mysql2": "^3.23.2",
|
||||||
"nanoid": "^6.0.0",
|
"nanoid": "^6.0.0",
|
||||||
|
"pg": "^8.22.0",
|
||||||
"qrcode": "^1.5.4",
|
"qrcode": "^1.5.4",
|
||||||
"serialport": "^13.0.0",
|
"serialport": "^13.0.0",
|
||||||
"socks": "^2.8.7",
|
"socks": "^2.8.7",
|
||||||
"speakeasy": "^2.0.0",
|
"speakeasy": "^2.0.0",
|
||||||
"ssh2": "^1.17.0",
|
"ssh2": "^1.17.0",
|
||||||
"undici": "^8.7.0",
|
"undici": "^8.9.0",
|
||||||
"ws": "^8.21.1"
|
"ws": "^8.21.1"
|
||||||
},
|
},
|
||||||
"devDependencies": {
|
"devDependencies": {
|
||||||
"@biomejs/biome": "2.5.4",
|
"@biomejs/biome": "2.5.6",
|
||||||
"@codemirror/autocomplete": "^6.20.3",
|
"@codemirror/autocomplete": "^6.20.3",
|
||||||
"@codemirror/commands": "^6.10.4",
|
"@codemirror/commands": "^6.10.4",
|
||||||
"@codemirror/search": "^6.7.1",
|
"@codemirror/search": "^6.7.1",
|
||||||
"@codemirror/theme-one-dark": "^6.1.3",
|
"@codemirror/theme-one-dark": "^6.1.3",
|
||||||
"@codemirror/view": "^6.43.6",
|
"@codemirror/view": "^6.43.7",
|
||||||
"@commitlint/cli": "^21.0.2",
|
"@commitlint/cli": "^21.2.1",
|
||||||
"@commitlint/config-conventional": "^21.0.2",
|
"@commitlint/config-conventional": "^21.2.0",
|
||||||
"@deadendjs/swagger-jsdoc": "^8.1.2",
|
"@deadendjs/swagger-jsdoc": "^8.1.2",
|
||||||
"@electron/notarize": "^3.1.1",
|
"@electron/notarize": "^3.1.1",
|
||||||
"@electron/rebuild": "^4.0.4",
|
"@electron/rebuild": "^4.2.0",
|
||||||
"@eslint/js": "^10.0.1",
|
"@eslint/js": "^10.0.1",
|
||||||
"@fontsource-variable/jetbrains-mono": "^5.2.8",
|
"@fontsource-variable/jetbrains-mono": "^5.3.0",
|
||||||
"@fontsource/fira-code": "^5.2.7",
|
"@fontsource/fira-code": "^5.3.0",
|
||||||
"@fontsource/jetbrains-mono": "^5.2.8",
|
"@fontsource/jetbrains-mono": "^5.3.0",
|
||||||
"@fontsource/source-code-pro": "^5.2.7",
|
"@fontsource/source-code-pro": "^5.3.0",
|
||||||
"@monaco-editor/react": "^4.7.0",
|
"@monaco-editor/react": "^4.7.0",
|
||||||
"@radix-ui/react-accordion": "^1.2.17",
|
"@radix-ui/react-accordion": "^1.2.20",
|
||||||
"@radix-ui/react-alert-dialog": "^1.1.20",
|
"@radix-ui/react-alert-dialog": "^1.1.23",
|
||||||
"@radix-ui/react-checkbox": "^1.3.8",
|
"@radix-ui/react-checkbox": "^1.3.11",
|
||||||
"@radix-ui/react-dialog": "^1.1.20",
|
"@radix-ui/react-dialog": "^1.1.23",
|
||||||
"@radix-ui/react-dropdown-menu": "^2.1.21",
|
"@radix-ui/react-dropdown-menu": "^2.1.24",
|
||||||
"@radix-ui/react-label": "^2.1.12",
|
"@radix-ui/react-label": "^2.1.15",
|
||||||
"@radix-ui/react-popover": "^1.1.20",
|
"@radix-ui/react-popover": "^1.1.23",
|
||||||
"@radix-ui/react-progress": "^1.1.13",
|
"@radix-ui/react-progress": "^1.1.16",
|
||||||
"@radix-ui/react-scroll-area": "^1.2.15",
|
"@radix-ui/react-scroll-area": "^1.2.18",
|
||||||
"@radix-ui/react-select": "^2.3.4",
|
"@radix-ui/react-select": "^2.3.7",
|
||||||
"@radix-ui/react-separator": "^1.1.12",
|
"@radix-ui/react-separator": "^1.1.15",
|
||||||
"@radix-ui/react-slider": "^1.4.4",
|
"@radix-ui/react-slider": "^1.4.7",
|
||||||
"@radix-ui/react-slot": "^1.3.0",
|
"@radix-ui/react-slot": "^1.3.3",
|
||||||
"@radix-ui/react-switch": "^1.3.4",
|
"@radix-ui/react-switch": "^1.3.7",
|
||||||
"@radix-ui/react-tabs": "^1.1.18",
|
"@radix-ui/react-tabs": "^1.1.21",
|
||||||
"@radix-ui/react-tooltip": "^1.2.13",
|
"@radix-ui/react-tooltip": "^1.2.16",
|
||||||
"@tailwindcss/vite": "^4.3.3",
|
"@tailwindcss/vite": "^4.3.3",
|
||||||
"@testing-library/dom": "^10.4.1",
|
"@testing-library/dom": "^10.4.1",
|
||||||
"@testing-library/jest-dom": "^6.9.1",
|
"@testing-library/jest-dom": "^7.0.0",
|
||||||
"@testing-library/react": "^16.3.2",
|
"@testing-library/react": "^16.3.2",
|
||||||
"@testing-library/user-event": "^14.6.1",
|
"@testing-library/user-event": "^14.6.1",
|
||||||
"@types/better-sqlite3": "^7.6.13",
|
"@types/better-sqlite3": "^7.6.13",
|
||||||
@@ -120,52 +126,55 @@
|
|||||||
"@types/guacamole-common-js": "^1.5.5",
|
"@types/guacamole-common-js": "^1.5.5",
|
||||||
"@types/js-yaml": "^4.0.9",
|
"@types/js-yaml": "^4.0.9",
|
||||||
"@types/jsonwebtoken": "^9.0.10",
|
"@types/jsonwebtoken": "^9.0.10",
|
||||||
"@types/multer": "^2.1.0",
|
"@types/multer": "^2.2.0",
|
||||||
"@types/node": "^26.0.0",
|
"@types/node": "^26.1.2",
|
||||||
|
"@types/pg": "^8.20.0",
|
||||||
"@types/qrcode": "^1.5.6",
|
"@types/qrcode": "^1.5.6",
|
||||||
"@types/react": "^19.2.17",
|
"@types/react": "^19.2.18",
|
||||||
"@types/react-dom": "^19.2.3",
|
"@types/react-dom": "^19.2.4",
|
||||||
"@types/speakeasy": "^2.0.10",
|
"@types/speakeasy": "^2.0.10",
|
||||||
"@types/ssh2": "^1.15.5",
|
"@types/ssh2": "^1.15.5",
|
||||||
"@types/ws": "^8.18.1",
|
"@types/ws": "^8.18.1",
|
||||||
"@uiw/codemirror-extensions-langs": "^4.25.11",
|
"@uiw/codemirror-extensions-langs": "^4.25.11",
|
||||||
"@uiw/codemirror-theme-github": "^4.25.11",
|
"@uiw/codemirror-theme-github": "^4.25.11",
|
||||||
"@uiw/react-codemirror": "^4.25.11",
|
"@uiw/react-codemirror": "^4.25.11",
|
||||||
"@vitejs/plugin-react": "^6.0.3",
|
"@vitejs/plugin-react": "^6.0.5",
|
||||||
"@vitest/coverage-v8": "^4.1.10",
|
"@vitest/coverage-v8": "^4.1.10",
|
||||||
"@vitest/ui": "^4.1.10",
|
"@vitest/ui": "^4.1.10",
|
||||||
"@xterm/addon-clipboard": "^0.2.0",
|
"@xterm/addon-clipboard": "^0.2.0",
|
||||||
"@xterm/addon-fit": "^0.11.0",
|
"@xterm/addon-fit": "^0.11.0",
|
||||||
|
"@xterm/addon-search": "^0.16.0",
|
||||||
"@xterm/addon-unicode11": "^0.9.0",
|
"@xterm/addon-unicode11": "^0.9.0",
|
||||||
"@xterm/addon-web-links": "^0.12.0",
|
"@xterm/addon-web-links": "^0.12.0",
|
||||||
"@xterm/xterm": "^6.0.0",
|
"@xterm/xterm": "^6.0.0",
|
||||||
"class-variance-authority": "^0.7.1",
|
"class-variance-authority": "^0.7.1",
|
||||||
"clsx": "^2.1.1",
|
"clsx": "^2.1.1",
|
||||||
"cmdk": "^1.1.1",
|
"cmdk": "^1.1.1",
|
||||||
"concurrently": "^10.0.3",
|
"concurrently": "^10.0.4",
|
||||||
"cytoscape": "^3.34.0",
|
"cytoscape": "^3.34.0",
|
||||||
"electron": "^43.0.0",
|
"drizzle-kit": "^0.31.10",
|
||||||
|
"electron": "^43.2.0",
|
||||||
"electron-builder": "^26.15.3",
|
"electron-builder": "^26.15.3",
|
||||||
"eslint": "^10.5.0",
|
"eslint": "^10.8.0",
|
||||||
"eslint-plugin-react-hooks": "^7.1.1",
|
"eslint-plugin-react-hooks": "^7.1.1",
|
||||||
"eslint-plugin-react-refresh": "^0.5.3",
|
"eslint-plugin-react-refresh": "^0.5.3",
|
||||||
"eslint-plugin-unused-imports": "^4.4.1",
|
"eslint-plugin-unused-imports": "^4.4.1",
|
||||||
"globals": "^17.5.0",
|
"globals": "^17.8.0",
|
||||||
"guacamole-common-js": "^1.5.0",
|
"guacamole-common-js": "^1.5.0",
|
||||||
"husky": "^9.1.7",
|
"husky": "^9.1.7",
|
||||||
"i18next": "^26.3.6",
|
"i18next": "^26.3.6",
|
||||||
"i18next-browser-languagedetector": "^8.2.1",
|
"i18next-browser-languagedetector": "^8.2.1",
|
||||||
"jsdom": "^29.1.1",
|
"jsdom": "^29.1.1",
|
||||||
"lint-staged": "^17.0.8",
|
"lint-staged": "^17.2.0",
|
||||||
"lucide-react": "^1.20.0",
|
"lucide-react": "^1.28.0",
|
||||||
"prettier": "3.8.4",
|
"prettier": "3.9.6",
|
||||||
"radix-ui": "^1.6.3",
|
"radix-ui": "^1.6.7",
|
||||||
"react": "^19.2.7",
|
"react": "^19.2.8",
|
||||||
"react-cytoscapejs": "^2.0.0",
|
"react-cytoscapejs": "^2.0.0",
|
||||||
"react-dom": "^19.2.7",
|
"react-dom": "^19.2.8",
|
||||||
"react-h5-audio-player": "^3.10.2",
|
"react-h5-audio-player": "^3.10.2",
|
||||||
"react-hook-form": "^7.79.0",
|
"react-hook-form": "^7.79.0",
|
||||||
"react-i18next": "^17.0.10",
|
"react-i18next": "^17.0.11",
|
||||||
"react-icons": "^5.6.0",
|
"react-icons": "^5.6.0",
|
||||||
"react-markdown": "^10.1.0",
|
"react-markdown": "^10.1.0",
|
||||||
"react-pdf": "^10.4.1",
|
"react-pdf": "^10.4.1",
|
||||||
|
|||||||
@@ -0,0 +1,228 @@
|
|||||||
|
/**
|
||||||
|
* Generates the Postgres and MySQL schema modules from the SQLite one.
|
||||||
|
*
|
||||||
|
* ## These files produce DDL. They are not used at runtime.
|
||||||
|
*
|
||||||
|
* drizzle-kit reads them to emit the migrations in drizzle/postgres and
|
||||||
|
* drizzle/mysql. Nothing imports them to run a query.
|
||||||
|
*
|
||||||
|
* That is not an oversight. The query builder needs two things from a table
|
||||||
|
* object — the identifiers to interpolate, and the encoders that turn JS values
|
||||||
|
* into driver values — and the sqlite definitions supply both correctly for
|
||||||
|
* every engine, which is why all 44 repositories import schema.ts directly:
|
||||||
|
*
|
||||||
|
* - text and integer encode as themselves everywhere
|
||||||
|
* - integer({ mode: "boolean" }) writes 1/0, which Postgres and MySQL both
|
||||||
|
* accept for a boolean column, and reads back through `Number(v) === 1`,
|
||||||
|
* which is true for JS `true` as well as for 1
|
||||||
|
* - real is a plain number on all three
|
||||||
|
*
|
||||||
|
* What genuinely differs between the dialects is DDL — column types, key
|
||||||
|
* lengths, autoincrement syntax — and DDL is exactly what these files exist to
|
||||||
|
* generate. See scripts/verify-dialects.mjs, which asserts the round-trips
|
||||||
|
* above against real servers rather than trusting this comment.
|
||||||
|
*
|
||||||
|
* The schema is declared once, in sqlite-core, and the other two dialects are
|
||||||
|
* derived. Hand-maintaining three copies of 52 tables would mean a renamed
|
||||||
|
* table has to land in three places consistently or a foreign key silently
|
||||||
|
* points at the wrong one — and the schema is regular enough that the mapping
|
||||||
|
* is mechanical.
|
||||||
|
*
|
||||||
|
* What varies between dialects is small and closed:
|
||||||
|
* - booleans are integers on sqlite, native elsewhere
|
||||||
|
* - autoincrement keys are `integer primary key autoincrement`, `serial`,
|
||||||
|
* and `int auto_increment`
|
||||||
|
* - MySQL cannot index unbounded TEXT, so any column that is a primary key,
|
||||||
|
* is unique, or participates in a foreign key must be varchar
|
||||||
|
* - MySQL rejects a bare DEFAULT CURRENT_TIMESTAMP on a text column, so it is
|
||||||
|
* written as a parenthesised expression default
|
||||||
|
*
|
||||||
|
* Usage: node scripts/generate-dialect-schema.cjs [--check]
|
||||||
|
* --check verifies the committed files match what would be generated,
|
||||||
|
* for CI to catch a schema edit that forgot to regenerate.
|
||||||
|
*/
|
||||||
|
|
||||||
|
const fs = require("fs");
|
||||||
|
const path = require("path");
|
||||||
|
|
||||||
|
const ROOT = path.join(__dirname, "..");
|
||||||
|
const SOURCE = path.join(ROOT, "src/backend/database/db/schema.ts");
|
||||||
|
const TARGETS = {
|
||||||
|
postgres: path.join(ROOT, "src/backend/database/db/schema.pg.ts"),
|
||||||
|
mysql: path.join(ROOT, "src/backend/database/db/schema.mysql.ts"),
|
||||||
|
};
|
||||||
|
|
||||||
|
const KEY_LENGTH = 255;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Columns that must be varchar rather than text on MySQL. A column qualifies if
|
||||||
|
* it is a primary key, is unique, or is either end of a foreign key.
|
||||||
|
*/
|
||||||
|
function collectKeyColumns(source) {
|
||||||
|
const keyed = new Set();
|
||||||
|
|
||||||
|
// `name: text("col")....primaryKey()` / `.unique()` / `.references(...)`
|
||||||
|
const declaration =
|
||||||
|
/(\w+):\s*text\("([a-z0-9_]+)"\)((?:\s*\.\w+\([^)]*\))*)/g;
|
||||||
|
let match;
|
||||||
|
while ((match = declaration.exec(source)) !== null) {
|
||||||
|
const [, prop, column, modifiers] = match;
|
||||||
|
if (/\.(primaryKey|unique|references)\(/.test(modifiers)) {
|
||||||
|
keyed.add(column);
|
||||||
|
}
|
||||||
|
void prop;
|
||||||
|
}
|
||||||
|
|
||||||
|
// Multi-line form: the modifiers land on following lines.
|
||||||
|
const multiline =
|
||||||
|
/(\w+):\s*text\("([a-z0-9_]+)"\)\s*\n(\s*\.\w+\([\s\S]*?\),)/g;
|
||||||
|
while ((match = multiline.exec(source)) !== null) {
|
||||||
|
if (/\.(primaryKey|unique|references)\(/.test(match[3])) {
|
||||||
|
keyed.add(match[2]);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// A referenced column implies the referencing side too; both must match.
|
||||||
|
const reference = /\.references\(\(\)\s*=>\s*\w+\.(\w+)/g;
|
||||||
|
while ((match = reference.exec(source)) !== null) {
|
||||||
|
keyed.add(camelToSnake(match[1]));
|
||||||
|
}
|
||||||
|
|
||||||
|
// Table-level indexes: `(table) => [uniqueIndex("x").on(table.a, table.b)]`.
|
||||||
|
// These were invisible here at first, and MySQL rejected the migration with
|
||||||
|
// "BLOB/TEXT column used in key specification without a key length" — but
|
||||||
|
// only on MySQL 8; MariaDB took it.
|
||||||
|
const tableIndex = /uniqueIndex\("[a-z0-9_]+"\)\.on\(([^)]*)\)/g;
|
||||||
|
while ((match = tableIndex.exec(source)) !== null) {
|
||||||
|
for (const column of match[1].split(",")) {
|
||||||
|
const name = column.trim().replace(/^\w+\./, "");
|
||||||
|
if (name) keyed.add(camelToSnake(name));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return keyed;
|
||||||
|
}
|
||||||
|
|
||||||
|
function camelToSnake(value) {
|
||||||
|
return value.replace(/[A-Z]/g, (c) => `_${c.toLowerCase()}`);
|
||||||
|
}
|
||||||
|
|
||||||
|
function transform(source, dialect) {
|
||||||
|
const keyed = collectKeyColumns(source);
|
||||||
|
const isPg = dialect === "postgres";
|
||||||
|
let out = source;
|
||||||
|
|
||||||
|
// Autoincrement primary keys, before the plain integer rule below.
|
||||||
|
out = out.replace(
|
||||||
|
/integer\("([a-z0-9_]+)"\)\.primaryKey\(\{\s*autoIncrement:\s*true\s*\}\)/g,
|
||||||
|
(_, col) =>
|
||||||
|
isPg
|
||||||
|
? `serial("${col}").primaryKey()`
|
||||||
|
: `int("${col}").autoincrement().primaryKey()`,
|
||||||
|
);
|
||||||
|
|
||||||
|
// Integer-backed booleans become native ones. Prettier wraps the longer
|
||||||
|
// declarations across lines, so this has to span newlines too.
|
||||||
|
out = out.replace(
|
||||||
|
/integer\(\s*"([a-z0-9_]+)",\s*\{\s*mode:\s*"boolean",?\s*\},?\s*\)/g,
|
||||||
|
(_, col) => `boolean("${col}")`,
|
||||||
|
);
|
||||||
|
|
||||||
|
// Remaining integers.
|
||||||
|
if (!isPg) {
|
||||||
|
out = out.replace(
|
||||||
|
/\binteger\("([a-z0-9_]+)"\)/g,
|
||||||
|
(_, col) => `int("${col}")`,
|
||||||
|
);
|
||||||
|
|
||||||
|
// Timestamps are stored as text (see sql-timestamp.ts). MySQL only accepts
|
||||||
|
// DEFAULT CURRENT_TIMESTAMP on a DATETIME or TIMESTAMP column — on a TEXT
|
||||||
|
// one it is ER_INVALID_DEFAULT, "Invalid default value". Since 8.0.13 an
|
||||||
|
// expression default works on any type, and an expression is written
|
||||||
|
// parenthesised. MariaDB accepts the bare form, which is why this only
|
||||||
|
// surfaces against real MySQL.
|
||||||
|
out = out.replace(/sql`CURRENT_TIMESTAMP`/g, "sql`(CURRENT_TIMESTAMP)`");
|
||||||
|
}
|
||||||
|
|
||||||
|
// Floating point.
|
||||||
|
out = out.replace(/\breal\("([a-z0-9_]+)"\)/g, (_, col) =>
|
||||||
|
isPg ? `doublePrecision("${col}")` : `double("${col}")`,
|
||||||
|
);
|
||||||
|
|
||||||
|
// Key-bearing strings must be indexable.
|
||||||
|
out = out.replace(/\btext\("([a-z0-9_]+)"\)/g, (whole, col) =>
|
||||||
|
keyed.has(col) ? `varchar("${col}", { length: ${KEY_LENGTH} })` : whole,
|
||||||
|
);
|
||||||
|
|
||||||
|
// text("x", { length: n }) is sqlite-only sugar; drop the length.
|
||||||
|
out = out.replace(
|
||||||
|
/\btext\("([a-z0-9_]+)",\s*\{\s*length:\s*\d+\s*\}\)/g,
|
||||||
|
(_, col) => `text("${col}")`,
|
||||||
|
);
|
||||||
|
|
||||||
|
out = out.replace(/\bsqliteTable\(/g, isPg ? "pgTable(" : "mysqlTable(");
|
||||||
|
|
||||||
|
const imports = isPg
|
||||||
|
? `import {\n pgTable,\n text,\n varchar,\n integer,\n serial,\n boolean,\n doublePrecision,\n uniqueIndex,\n} from "drizzle-orm/pg-core";`
|
||||||
|
: `import {\n mysqlTable,\n text,\n varchar,\n int,\n boolean,\n double,\n uniqueIndex,\n} from "drizzle-orm/mysql-core";`;
|
||||||
|
|
||||||
|
out = out.replace(
|
||||||
|
/import\s*\{[^}]*\}\s*from\s*"drizzle-orm\/sqlite-core";/,
|
||||||
|
imports,
|
||||||
|
);
|
||||||
|
|
||||||
|
return `${header(dialect)}\n${out}`;
|
||||||
|
}
|
||||||
|
|
||||||
|
function header(dialect) {
|
||||||
|
return `// GENERATED FILE — do not edit.
|
||||||
|
//
|
||||||
|
// Produced from schema.ts by scripts/generate-dialect-schema.cjs.
|
||||||
|
// Edit the sqlite schema and re-run \`node scripts/generate-dialect-schema.cjs\`.
|
||||||
|
// Target dialect: ${dialect}.
|
||||||
|
//
|
||||||
|
// DDL source for drizzle-kit. NOT imported to run queries — repositories use
|
||||||
|
// schema.ts on every dialect. See the generator header for why that is correct.
|
||||||
|
`;
|
||||||
|
}
|
||||||
|
|
||||||
|
function main() {
|
||||||
|
const check = process.argv.includes("--check");
|
||||||
|
const source = fs.readFileSync(SOURCE, "utf8");
|
||||||
|
let drift = false;
|
||||||
|
|
||||||
|
for (const [dialect, target] of Object.entries(TARGETS)) {
|
||||||
|
const generated = transform(source, dialect);
|
||||||
|
|
||||||
|
if (check) {
|
||||||
|
const current = fs.existsSync(target)
|
||||||
|
? fs.readFileSync(target, "utf8")
|
||||||
|
: "";
|
||||||
|
if (current !== generated) {
|
||||||
|
console.error(
|
||||||
|
`[generate-dialect-schema] ${path.relative(ROOT, target)} is out of date`,
|
||||||
|
);
|
||||||
|
drift = true;
|
||||||
|
}
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
|
||||||
|
fs.writeFileSync(target, generated);
|
||||||
|
console.log(
|
||||||
|
`[generate-dialect-schema] wrote ${path.relative(ROOT, target)}`,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (drift) {
|
||||||
|
console.error(
|
||||||
|
"[generate-dialect-schema] run `node scripts/generate-dialect-schema.cjs` and commit the result",
|
||||||
|
);
|
||||||
|
process.exit(1);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
module.exports = { transform, collectKeyColumns };
|
||||||
|
|
||||||
|
if (require.main === module) {
|
||||||
|
main();
|
||||||
|
}
|
||||||
@@ -0,0 +1,140 @@
|
|||||||
|
import { describe, expect, it } from "vitest";
|
||||||
|
import { createRequire } from "node:module";
|
||||||
|
|
||||||
|
const require = createRequire(import.meta.url);
|
||||||
|
const { transform, collectKeyColumns } =
|
||||||
|
require("./generate-dialect-schema.cjs") as {
|
||||||
|
transform: (source: string, dialect: "postgres" | "mysql") => string;
|
||||||
|
collectKeyColumns: (source: string) => Set<string>;
|
||||||
|
};
|
||||||
|
|
||||||
|
const SOURCE = `import { sqliteTable, text, integer, real } from "drizzle-orm/sqlite-core";
|
||||||
|
import { sql } from "drizzle-orm";
|
||||||
|
|
||||||
|
export const users = sqliteTable("users", {
|
||||||
|
id: text("id").primaryKey(),
|
||||||
|
username: text("username").notNull(),
|
||||||
|
isAdmin: integer("is_admin", { mode: "boolean" }).notNull().default(false),
|
||||||
|
wrapped: integer("wrapped", {
|
||||||
|
mode: "boolean",
|
||||||
|
})
|
||||||
|
.notNull()
|
||||||
|
.default(true),
|
||||||
|
score: real("score"),
|
||||||
|
ssoProviderId: integer("sso_provider_id"),
|
||||||
|
});
|
||||||
|
|
||||||
|
export const folders = sqliteTable("folders", {
|
||||||
|
id: integer("id").primaryKey({ autoIncrement: true }),
|
||||||
|
userId: text("user_id")
|
||||||
|
.notNull()
|
||||||
|
.references(() => users.id, { onDelete: "cascade" }),
|
||||||
|
name: text("name").notNull(),
|
||||||
|
syncId: text("sync_id").unique(),
|
||||||
|
cert: text("cert", { length: 8192 }),
|
||||||
|
});
|
||||||
|
`;
|
||||||
|
|
||||||
|
describe("collectKeyColumns", () => {
|
||||||
|
it("finds columns that must be indexable", () => {
|
||||||
|
const keyed = collectKeyColumns(SOURCE);
|
||||||
|
|
||||||
|
// primary key, unique, and both ends of the foreign key
|
||||||
|
expect(keyed.has("id")).toBe(true);
|
||||||
|
expect(keyed.has("sync_id")).toBe(true);
|
||||||
|
expect(keyed.has("user_id")).toBe(true);
|
||||||
|
});
|
||||||
|
|
||||||
|
it("leaves ordinary strings alone", () => {
|
||||||
|
const keyed = collectKeyColumns(SOURCE);
|
||||||
|
|
||||||
|
expect(keyed.has("username")).toBe(false);
|
||||||
|
expect(keyed.has("name")).toBe(false);
|
||||||
|
expect(keyed.has("cert")).toBe(false);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe("postgres output", () => {
|
||||||
|
const out = transform(SOURCE, "postgres");
|
||||||
|
|
||||||
|
it("is marked generated", () => {
|
||||||
|
expect(out.startsWith("// GENERATED FILE")).toBe(true);
|
||||||
|
});
|
||||||
|
|
||||||
|
it("uses pg-core", () => {
|
||||||
|
expect(out).toContain('from "drizzle-orm/pg-core"');
|
||||||
|
expect(out).not.toContain("sqlite-core");
|
||||||
|
expect(out).toContain("pgTable(");
|
||||||
|
expect(out).not.toContain("sqliteTable(");
|
||||||
|
});
|
||||||
|
|
||||||
|
it("maps autoincrement keys to serial", () => {
|
||||||
|
expect(out).toContain('serial("id").primaryKey()');
|
||||||
|
expect(out).not.toContain("autoIncrement");
|
||||||
|
});
|
||||||
|
|
||||||
|
it("maps integer-backed booleans, including the wrapped form", () => {
|
||||||
|
expect(out).toContain('boolean("is_admin")');
|
||||||
|
// Prettier splits longer declarations across lines; both must convert.
|
||||||
|
expect(out).toContain('boolean("wrapped")');
|
||||||
|
expect(out).not.toMatch(/mode:\s*"boolean"/);
|
||||||
|
});
|
||||||
|
|
||||||
|
it("keeps plain integers and maps real", () => {
|
||||||
|
expect(out).toContain('integer("sso_provider_id")');
|
||||||
|
expect(out).toContain('doublePrecision("score")');
|
||||||
|
});
|
||||||
|
|
||||||
|
it("makes key columns varchar and leaves the rest text", () => {
|
||||||
|
expect(out).toContain('varchar("id", { length: 255 })');
|
||||||
|
expect(out).toContain('varchar("user_id", { length: 255 })');
|
||||||
|
expect(out).toContain('varchar("sync_id", { length: 255 })');
|
||||||
|
expect(out).toContain('text("username")');
|
||||||
|
expect(out).toContain('text("name")');
|
||||||
|
});
|
||||||
|
|
||||||
|
it("drops the sqlite-only text length", () => {
|
||||||
|
expect(out).toContain('text("cert")');
|
||||||
|
expect(out).not.toContain("length: 8192");
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe("mysql output", () => {
|
||||||
|
const out = transform(SOURCE, "mysql");
|
||||||
|
|
||||||
|
it("uses mysql-core", () => {
|
||||||
|
expect(out).toContain('from "drizzle-orm/mysql-core"');
|
||||||
|
expect(out).toContain("mysqlTable(");
|
||||||
|
});
|
||||||
|
|
||||||
|
it("maps autoincrement keys to int auto_increment", () => {
|
||||||
|
expect(out).toContain('int("id").autoincrement().primaryKey()');
|
||||||
|
});
|
||||||
|
|
||||||
|
it("renames integer to int", () => {
|
||||||
|
expect(out).toContain('int("sso_provider_id")');
|
||||||
|
expect(out).not.toMatch(/\binteger\(/);
|
||||||
|
});
|
||||||
|
|
||||||
|
it("maps real to double", () => {
|
||||||
|
expect(out).toContain('double("score")');
|
||||||
|
});
|
||||||
|
|
||||||
|
it("makes key columns varchar — MySQL cannot index unbounded TEXT", () => {
|
||||||
|
expect(out).toContain('varchar("user_id", { length: 255 })');
|
||||||
|
expect(out).toContain('text("name")');
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
describe("determinism", () => {
|
||||||
|
it("produces identical output for identical input", () => {
|
||||||
|
expect(transform(SOURCE, "postgres")).toBe(transform(SOURCE, "postgres"));
|
||||||
|
expect(transform(SOURCE, "mysql")).toBe(transform(SOURCE, "mysql"));
|
||||||
|
});
|
||||||
|
|
||||||
|
it("keeps foreign key behaviour verbatim", () => {
|
||||||
|
for (const dialect of ["postgres", "mysql"] as const) {
|
||||||
|
expect(transform(SOURCE, dialect)).toContain('onDelete: "cascade"');
|
||||||
|
}
|
||||||
|
});
|
||||||
|
});
|
||||||
@@ -35,6 +35,20 @@ if (
|
|||||||
process.exit(0);
|
process.exit(0);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Every patch below is required for correctness: protocol negotiation, the
|
||||||
|
// guacd 1.6.0 name handshake, dynamic argument answering, UTF-8 tokens and
|
||||||
|
// read-only joins. If an upstream release moves an anchor string, silently
|
||||||
|
// skipping would ship a Termix that looks fine and then drops VNC/RDP sessions
|
||||||
|
// at runtime, so a missing anchor has to stop the install instead.
|
||||||
|
function missingAnchor(patch) {
|
||||||
|
console.error(
|
||||||
|
`[patch-guacamole-lite] ${patch} anchor not found in guacamole-lite. ` +
|
||||||
|
"The upstream file has changed and this patch no longer applies — " +
|
||||||
|
"update scripts/patch-guacamole-lite.cjs to match the new source.",
|
||||||
|
);
|
||||||
|
process.exit(1);
|
||||||
|
}
|
||||||
|
|
||||||
let guacdClientContent = fs.readFileSync(guacdClientPath, "utf8");
|
let guacdClientContent = fs.readFileSync(guacdClientPath, "utf8");
|
||||||
let cryptContent = fs.readFileSync(cryptPath, "utf8");
|
let cryptContent = fs.readFileSync(cryptPath, "utf8");
|
||||||
let clientConnectionContent = fs.readFileSync(clientConnectionPath, "utf8");
|
let clientConnectionContent = fs.readFileSync(clientConnectionPath, "utf8");
|
||||||
@@ -157,18 +171,14 @@ if (!guacdClientContent.includes("} else if (/^1_\\d+_0$/.test(version)) {")) {
|
|||||||
newVersionBlock,
|
newVersionBlock,
|
||||||
);
|
);
|
||||||
} else {
|
} else {
|
||||||
console.log(
|
missingAnchor("Version check");
|
||||||
"[patch-guacamole-lite] Version check target not found, skipping",
|
|
||||||
);
|
|
||||||
process.exit(0);
|
|
||||||
}
|
}
|
||||||
patched = true;
|
patched = true;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (!guacdClientContent.includes(newTimezone)) {
|
if (!guacdClientContent.includes(newTimezone)) {
|
||||||
if (!guacdClientContent.includes(oldTimezone)) {
|
if (!guacdClientContent.includes(oldTimezone)) {
|
||||||
console.log("[patch-guacamole-lite] Timezone target not found, skipping");
|
missingAnchor("Timezone");
|
||||||
process.exit(0);
|
|
||||||
}
|
}
|
||||||
guacdClientContent = guacdClientContent.replace(oldTimezone, newTimezone);
|
guacdClientContent = guacdClientContent.replace(oldTimezone, newTimezone);
|
||||||
patched = true;
|
patched = true;
|
||||||
@@ -180,20 +190,14 @@ if (!guacdClientContent.includes(newConnect)) {
|
|||||||
} else if (guacdClientContent.includes(oldConnect)) {
|
} else if (guacdClientContent.includes(oldConnect)) {
|
||||||
guacdClientContent = guacdClientContent.replace(oldConnect, newConnect);
|
guacdClientContent = guacdClientContent.replace(oldConnect, newConnect);
|
||||||
} else {
|
} else {
|
||||||
console.log(
|
missingAnchor("Connect");
|
||||||
"[patch-guacamole-lite] Connect target not found, skipping name patch",
|
|
||||||
);
|
|
||||||
process.exit(0);
|
|
||||||
}
|
}
|
||||||
patched = true;
|
patched = true;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (!guacdClientContent.includes("this.nextArgumentStreamIndex = 0;")) {
|
if (!guacdClientContent.includes("this.nextArgumentStreamIndex = 0;")) {
|
||||||
if (!guacdClientContent.includes(oldSendBuffer)) {
|
if (!guacdClientContent.includes(oldSendBuffer)) {
|
||||||
console.log(
|
missingAnchor("Argument stream index");
|
||||||
"[patch-guacamole-lite] Argument stream index target not found, skipping",
|
|
||||||
);
|
|
||||||
process.exit(0);
|
|
||||||
}
|
}
|
||||||
guacdClientContent = guacdClientContent.replace(oldSendBuffer, newSendBuffer);
|
guacdClientContent = guacdClientContent.replace(oldSendBuffer, newSendBuffer);
|
||||||
patched = true;
|
patched = true;
|
||||||
@@ -201,10 +205,7 @@ if (!guacdClientContent.includes("this.nextArgumentStreamIndex = 0;")) {
|
|||||||
|
|
||||||
if (!guacdClientContent.includes("sendRequiredArguments(params) {")) {
|
if (!guacdClientContent.includes("sendRequiredArguments(params) {")) {
|
||||||
if (!guacdClientContent.includes(oldSendInstructionBlock)) {
|
if (!guacdClientContent.includes(oldSendInstructionBlock)) {
|
||||||
console.log(
|
missingAnchor("Required argument helper");
|
||||||
"[patch-guacamole-lite] Required argument helper target not found, skipping",
|
|
||||||
);
|
|
||||||
process.exit(0);
|
|
||||||
}
|
}
|
||||||
guacdClientContent = guacdClientContent.replace(
|
guacdClientContent = guacdClientContent.replace(
|
||||||
oldSendInstructionBlock,
|
oldSendInstructionBlock,
|
||||||
@@ -217,10 +218,7 @@ if (
|
|||||||
!guacdClientContent.includes("opcode === 'required' || opcode === 'require'")
|
!guacdClientContent.includes("opcode === 'required' || opcode === 'require'")
|
||||||
) {
|
) {
|
||||||
if (!guacdClientContent.includes(oldReadyHandler)) {
|
if (!guacdClientContent.includes(oldReadyHandler)) {
|
||||||
console.log(
|
missingAnchor("Required opcode");
|
||||||
"[patch-guacamole-lite] Required opcode target not found, skipping",
|
|
||||||
);
|
|
||||||
process.exit(0);
|
|
||||||
}
|
}
|
||||||
guacdClientContent = guacdClientContent.replace(
|
guacdClientContent = guacdClientContent.replace(
|
||||||
oldReadyHandler,
|
oldReadyHandler,
|
||||||
@@ -273,10 +271,7 @@ if (!cryptContent.includes(newDecryptBlock)) {
|
|||||||
newDecryptBlock,
|
newDecryptBlock,
|
||||||
);
|
);
|
||||||
} else {
|
} else {
|
||||||
console.log(
|
missingAnchor("UTF-8 token decrypt");
|
||||||
"[patch-guacamole-lite] UTF-8 token decrypt target not found, skipping",
|
|
||||||
);
|
|
||||||
process.exit(0);
|
|
||||||
}
|
}
|
||||||
patched = true;
|
patched = true;
|
||||||
}
|
}
|
||||||
@@ -329,10 +324,7 @@ const newSendMessageToGuacd =
|
|||||||
|
|
||||||
if (!clientConnectionContent.includes("isReadOnlyJoin()")) {
|
if (!clientConnectionContent.includes("isReadOnlyJoin()")) {
|
||||||
if (!clientConnectionContent.includes(oldSendMessageToGuacd)) {
|
if (!clientConnectionContent.includes(oldSendMessageToGuacd)) {
|
||||||
console.log(
|
missingAnchor("sendMessageToGuacd");
|
||||||
"[patch-guacamole-lite] sendMessageToGuacd target not found, skipping read-only patch",
|
|
||||||
);
|
|
||||||
process.exit(0);
|
|
||||||
}
|
}
|
||||||
clientConnectionContent = clientConnectionContent.replace(
|
clientConnectionContent = clientConnectionContent.replace(
|
||||||
oldSendMessageToGuacd,
|
oldSendMessageToGuacd,
|
||||||
@@ -357,10 +349,7 @@ const newPreserveJoin =
|
|||||||
|
|
||||||
if (!clientConnectionContent.includes("compiledSettings.readOnly")) {
|
if (!clientConnectionContent.includes("compiledSettings.readOnly")) {
|
||||||
if (!clientConnectionContent.includes(oldPreserveJoin)) {
|
if (!clientConnectionContent.includes(oldPreserveJoin)) {
|
||||||
console.log(
|
missingAnchor("join-preserve");
|
||||||
"[patch-guacamole-lite] join-preserve target not found, skipping readOnly propagation patch",
|
|
||||||
);
|
|
||||||
process.exit(0);
|
|
||||||
}
|
}
|
||||||
clientConnectionContent = clientConnectionContent.replace(
|
clientConnectionContent = clientConnectionContent.replace(
|
||||||
oldPreserveJoin,
|
oldPreserveJoin,
|
||||||
|
|||||||
@@ -0,0 +1,140 @@
|
|||||||
|
/**
|
||||||
|
* Runs the repository layer against a real Postgres or MySQL server.
|
||||||
|
*
|
||||||
|
* The unit tests only ever see SQLite, so the parts of this codebase that
|
||||||
|
* differ per engine — the RETURNING replacements, the read-then-write
|
||||||
|
* transactions, the value encoders — have no coverage there at all. This is
|
||||||
|
* what covers them, and it needs a live server, which is why it is a script
|
||||||
|
* rather than a test.
|
||||||
|
*
|
||||||
|
* Usage:
|
||||||
|
* npm run verify:dialect -- postgres://user:pass@host:5432/db
|
||||||
|
* npm run verify:dialect -- mysql://user:pass@host:3306/db
|
||||||
|
*
|
||||||
|
* Applies the migrations first, through the same runRemoteMigrations() the
|
||||||
|
* application uses at startup — so a broken migration fails here rather than in
|
||||||
|
* production. Writes real rows: point it at a scratch database.
|
||||||
|
*/
|
||||||
|
|
||||||
|
import { randomUUID } from "crypto";
|
||||||
|
|
||||||
|
const url = process.argv[2];
|
||||||
|
if (!url) {
|
||||||
|
console.error("usage: node scripts/verify-dialects.mjs <DATABASE_URL>");
|
||||||
|
process.exit(2);
|
||||||
|
}
|
||||||
|
|
||||||
|
const scheme = url.split("://", 1)[0].toLowerCase();
|
||||||
|
const dialect = scheme.startsWith("postgres")
|
||||||
|
? "postgres"
|
||||||
|
: scheme === "mysql" || scheme === "mariadb"
|
||||||
|
? "mysql"
|
||||||
|
: null;
|
||||||
|
|
||||||
|
if (!dialect) {
|
||||||
|
console.error(`unsupported URL scheme "${scheme}://"`);
|
||||||
|
process.exit(2);
|
||||||
|
}
|
||||||
|
|
||||||
|
const { drizzle } = await import(
|
||||||
|
dialect === "postgres" ? "drizzle-orm/node-postgres" : "drizzle-orm/mysql2"
|
||||||
|
);
|
||||||
|
|
||||||
|
// No schema option on purpose — see connect.ts.
|
||||||
|
const db = drizzle(url);
|
||||||
|
const context = { dialect, drizzle: db };
|
||||||
|
|
||||||
|
const { runRemoteMigrations } =
|
||||||
|
await import("../src/backend/database/db/migrate.js");
|
||||||
|
await runRemoteMigrations(dialect, db);
|
||||||
|
|
||||||
|
const { UserRepository } =
|
||||||
|
await import("../src/backend/database/repositories/user-repository.js");
|
||||||
|
const { HostRepository } =
|
||||||
|
await import("../src/backend/database/repositories/host-repository.js");
|
||||||
|
const { SettingsRepository } =
|
||||||
|
await import("../src/backend/database/repositories/settings-repository.js");
|
||||||
|
|
||||||
|
let failures = 0;
|
||||||
|
const check = (label, got, want) => {
|
||||||
|
const ok = JSON.stringify(got) === JSON.stringify(want);
|
||||||
|
if (!ok) failures++;
|
||||||
|
console.log(
|
||||||
|
` ${ok ? "ok " : "FAIL"} ${label}` +
|
||||||
|
(ok
|
||||||
|
? ""
|
||||||
|
: `\n got ${JSON.stringify(got)}, want ${JSON.stringify(want)}`),
|
||||||
|
);
|
||||||
|
};
|
||||||
|
|
||||||
|
console.log(`\nverifying ${dialect} at ${url.replace(/:[^:@]*@/, ":***@")}\n`);
|
||||||
|
|
||||||
|
const users = new UserRepository(context);
|
||||||
|
const userId = `verify-${randomUUID()}`;
|
||||||
|
|
||||||
|
// insertReturning: on MySQL this is an insert plus a read inside a transaction.
|
||||||
|
const created = await users.create({
|
||||||
|
id: userId,
|
||||||
|
username: "before",
|
||||||
|
passwordHash: "x",
|
||||||
|
isAdmin: true,
|
||||||
|
});
|
||||||
|
check("insert returns the stored row", created?.username, "before");
|
||||||
|
|
||||||
|
// The one non-identity value encoder in the schema. Booleans are integers in
|
||||||
|
// the sqlite definitions the repositories import, so this asserts that 1/0
|
||||||
|
// survives a round trip through a native boolean column.
|
||||||
|
check("boolean true survives the round trip", created?.isAdmin, true);
|
||||||
|
|
||||||
|
// updateReturning must report the state AFTER the write. Reading first would
|
||||||
|
// return the value the update replaced — silently, with no error.
|
||||||
|
const updated = await users.update(userId, { username: "after" });
|
||||||
|
check("update returns the new value", updated?.username, "after");
|
||||||
|
|
||||||
|
const hosts = new HostRepository(context);
|
||||||
|
const host = await hosts.create({
|
||||||
|
userId,
|
||||||
|
name: "verify",
|
||||||
|
ip: "127.0.0.1",
|
||||||
|
port: 22,
|
||||||
|
username: "root",
|
||||||
|
authType: "password",
|
||||||
|
enableTerminal: true,
|
||||||
|
});
|
||||||
|
check(
|
||||||
|
"autoincrement id came back",
|
||||||
|
typeof host?.id === "number" && host.id > 0,
|
||||||
|
true,
|
||||||
|
);
|
||||||
|
check(
|
||||||
|
"database-assigned createdAt came back",
|
||||||
|
typeof host?.createdAt === "string" && host.createdAt.length > 0,
|
||||||
|
true,
|
||||||
|
);
|
||||||
|
|
||||||
|
// deleteReturning must report the state BEFORE the write. Reading afterwards
|
||||||
|
// would find nothing at all.
|
||||||
|
const settings = new SettingsRepository(context);
|
||||||
|
const prefix = `verify-${randomUUID()}`;
|
||||||
|
await settings.set(`${prefix}-a`, "1");
|
||||||
|
await settings.set(`${prefix}-b`, "2");
|
||||||
|
check(
|
||||||
|
"delete reports the rows it removed",
|
||||||
|
await settings.deleteLike(`${prefix}-%`),
|
||||||
|
2,
|
||||||
|
);
|
||||||
|
check(
|
||||||
|
"and they are actually gone",
|
||||||
|
(await settings.listAll()).filter((row) => row.key.startsWith(prefix)).length,
|
||||||
|
0,
|
||||||
|
);
|
||||||
|
|
||||||
|
await hosts.deleteForUser(userId, host.id);
|
||||||
|
check("host really deleted", await hosts.findById(host.id), null);
|
||||||
|
|
||||||
|
console.log(
|
||||||
|
failures === 0
|
||||||
|
? `\n${dialect}: all checks passed\n`
|
||||||
|
: `\n${dialect}: ${failures} FAILED\n`,
|
||||||
|
);
|
||||||
|
process.exit(failures === 0 ? 0 : 1);
|
||||||
@@ -713,7 +713,7 @@ app.post("/database/export", authenticateJWT, async (req, res) => {
|
|||||||
}
|
}
|
||||||
|
|
||||||
const timestamp = new Date().toISOString().replace(/[:.]/g, "-");
|
const timestamp = new Date().toISOString().replace(/[:.]/g, "-");
|
||||||
const filename = `termix-export-${user[0].username}-${timestamp}.sqlite`;
|
const filename = `termix-export-${user.username}-${timestamp}.sqlite`;
|
||||||
const tempPath = path.join(tempDir, filename);
|
const tempPath = path.join(tempDir, filename);
|
||||||
|
|
||||||
apiLogger.info("Creating export database", {
|
apiLogger.info("Creating export database", {
|
||||||
@@ -882,7 +882,7 @@ app.post("/database/export", authenticateJWT, async (req, res) => {
|
|||||||
);
|
);
|
||||||
`);
|
`);
|
||||||
|
|
||||||
const userRecord = user[0];
|
const userRecord = user;
|
||||||
const insertUser = exportDb.prepare(`
|
const insertUser = exportDb.prepare(`
|
||||||
INSERT INTO users (id, username, password_hash, is_admin, is_oidc, oidc_identifier, client_id, client_secret, issuer_url, authorization_url, token_url, identifier_path, name_path, scopes, totp_secret, totp_enabled, totp_backup_codes)
|
INSERT INTO users (id, username, password_hash, is_admin, is_oidc, oidc_identifier, client_id, client_secret, issuer_url, authorization_url, token_url, identifier_path, name_path, scopes, totp_secret, totp_enabled, totp_backup_codes)
|
||||||
VALUES (?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?)
|
VALUES (?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?)
|
||||||
|
|||||||
@@ -0,0 +1,71 @@
|
|||||||
|
import * as sqlite from "drizzle-orm/sqlite-core";
|
||||||
|
import * as pg from "drizzle-orm/pg-core";
|
||||||
|
import * as mysql from "drizzle-orm/mysql-core";
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Per-dialect column constructors, so a table can be declared once instead of
|
||||||
|
* three times.
|
||||||
|
*
|
||||||
|
* The existing schema only uses three column types (text, integer, real) plus
|
||||||
|
* an integer-backed boolean, which is what makes this tractable — the surface
|
||||||
|
* to abstract is small and closed. Anything a dialect cannot express the same
|
||||||
|
* way is spelled out here rather than at 52 call sites.
|
||||||
|
*
|
||||||
|
* Notable differences this papers over:
|
||||||
|
* - booleans are integers in SQLite, native in Postgres and tinyint in MySQL
|
||||||
|
* - autoincrement keys are `integer primary key autoincrement`, `serial`, and
|
||||||
|
* `int auto_increment` respectively
|
||||||
|
* - MySQL cannot index an unbounded TEXT, so keyed/indexed strings must be
|
||||||
|
* varchar; `shortText` exists for columns used as keys or in unique indexes
|
||||||
|
*/
|
||||||
|
export interface ColumnKit {
|
||||||
|
table: typeof sqlite.sqliteTable | typeof pg.pgTable | typeof mysql.mysqlTable;
|
||||||
|
/** Free-form string; unbounded where the engine allows it. */
|
||||||
|
text: (name: string) => AnyColumnBuilder;
|
||||||
|
/** String used as a key, unique or indexed — bounded so MySQL can index it. */
|
||||||
|
shortText: (name: string, length?: number) => AnyColumnBuilder;
|
||||||
|
int: (name: string) => AnyColumnBuilder;
|
||||||
|
/** Auto-incrementing surrogate primary key. */
|
||||||
|
serial: (name: string) => AnyColumnBuilder;
|
||||||
|
bool: (name: string) => AnyColumnBuilder;
|
||||||
|
real: (name: string) => AnyColumnBuilder;
|
||||||
|
}
|
||||||
|
|
||||||
|
// drizzle's builders are heavily generic; the schema modules keep their own
|
||||||
|
// precise types, so this alias only exists to describe the kit's shape.
|
||||||
|
type AnyColumnBuilder = ReturnType<typeof sqlite.text>;
|
||||||
|
|
||||||
|
const DEFAULT_KEY_LENGTH = 255;
|
||||||
|
|
||||||
|
export const sqliteKit = {
|
||||||
|
table: sqlite.sqliteTable,
|
||||||
|
text: (name: string) => sqlite.text(name),
|
||||||
|
shortText: (name: string) => sqlite.text(name),
|
||||||
|
int: (name: string) => sqlite.integer(name),
|
||||||
|
serial: (name: string) =>
|
||||||
|
sqlite.integer(name).primaryKey({ autoIncrement: true }),
|
||||||
|
bool: (name: string) => sqlite.integer(name, { mode: "boolean" }),
|
||||||
|
real: (name: string) => sqlite.real(name),
|
||||||
|
} as const;
|
||||||
|
|
||||||
|
export const pgKit = {
|
||||||
|
table: pg.pgTable,
|
||||||
|
text: (name: string) => pg.text(name),
|
||||||
|
shortText: (name: string, length = DEFAULT_KEY_LENGTH) =>
|
||||||
|
pg.varchar(name, { length }),
|
||||||
|
int: (name: string) => pg.integer(name),
|
||||||
|
serial: (name: string) => pg.serial(name).primaryKey(),
|
||||||
|
bool: (name: string) => pg.boolean(name),
|
||||||
|
real: (name: string) => pg.doublePrecision(name),
|
||||||
|
} as const;
|
||||||
|
|
||||||
|
export const mysqlKit = {
|
||||||
|
table: mysql.mysqlTable,
|
||||||
|
text: (name: string) => mysql.text(name),
|
||||||
|
shortText: (name: string, length = DEFAULT_KEY_LENGTH) =>
|
||||||
|
mysql.varchar(name, { length }),
|
||||||
|
int: (name: string) => mysql.int(name),
|
||||||
|
serial: (name: string) => mysql.int(name).autoincrement().primaryKey(),
|
||||||
|
bool: (name: string) => mysql.boolean(name),
|
||||||
|
real: (name: string) => mysql.double(name),
|
||||||
|
} as const;
|
||||||
@@ -0,0 +1,74 @@
|
|||||||
|
import type { DatabaseDialect } from "./dialect.js";
|
||||||
|
import type { PortableDatabase } from "../repositories/database-context.js";
|
||||||
|
|
||||||
|
export const DATABASE_URL_ENV = "DATABASE_URL";
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Opens a connection to a client-server engine.
|
||||||
|
*
|
||||||
|
* SQLite is not handled here — it has its own lifecycle in db/index.ts, where
|
||||||
|
* the database is decrypted into memory and serialised back to a file. This
|
||||||
|
* covers the engines that connect to something already running.
|
||||||
|
*
|
||||||
|
* The returned handle is typed as PortableDatabase; see the note there on why
|
||||||
|
* that is an approximation and what guarantees it.
|
||||||
|
*/
|
||||||
|
export function databaseUrl(env: NodeJS.ProcessEnv = process.env): string | null {
|
||||||
|
const url = env[DATABASE_URL_ENV]?.trim();
|
||||||
|
return url ? url : null;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Checks the connection string suits the configured engine before trying to
|
||||||
|
* open it, so a mismatch fails with something readable rather than a driver
|
||||||
|
* error thirty frames down.
|
||||||
|
*/
|
||||||
|
export function assertUrlMatchesDialect(
|
||||||
|
url: string,
|
||||||
|
dialect: DatabaseDialect,
|
||||||
|
): void {
|
||||||
|
const scheme = url.split("://", 1)[0].toLowerCase();
|
||||||
|
|
||||||
|
const expected: Record<string, readonly string[]> = {
|
||||||
|
postgres: ["postgres", "postgresql"],
|
||||||
|
mysql: ["mysql", "mariadb"],
|
||||||
|
};
|
||||||
|
|
||||||
|
const allowed = expected[dialect];
|
||||||
|
if (!allowed) {
|
||||||
|
throw new Error(`${dialect} does not use ${DATABASE_URL_ENV}`);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!allowed.includes(scheme)) {
|
||||||
|
throw new Error(
|
||||||
|
`${DATABASE_URL_ENV} is a "${scheme}://" URL but DATABASE_DIALECT is "${dialect}". ` +
|
||||||
|
`Expected one of ${allowed.map((s) => `${s}://`).join(", ")}.`,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
export async function connectRemoteDatabase(
|
||||||
|
dialect: DatabaseDialect,
|
||||||
|
env: NodeJS.ProcessEnv = process.env,
|
||||||
|
): Promise<PortableDatabase> {
|
||||||
|
const url = databaseUrl(env);
|
||||||
|
if (!url) {
|
||||||
|
throw new Error(
|
||||||
|
`${DATABASE_URL_ENV} must be set when DATABASE_DIALECT is "${dialect}".`,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
assertUrlMatchesDialect(url, dialect);
|
||||||
|
|
||||||
|
// No `schema` option: it only feeds drizzle's relational query API
|
||||||
|
// (`db.query.*`), which nothing here uses. The query builder takes its table
|
||||||
|
// names and value encoders from the table objects the repositories import —
|
||||||
|
// see the note in schema.pg.ts on why the generated schemas are DDL-only.
|
||||||
|
if (dialect === "postgres") {
|
||||||
|
const { drizzle } = await import("drizzle-orm/node-postgres");
|
||||||
|
return drizzle(url) as unknown as PortableDatabase;
|
||||||
|
}
|
||||||
|
|
||||||
|
const { drizzle } = await import("drizzle-orm/mysql2");
|
||||||
|
return drizzle(url) as unknown as PortableDatabase;
|
||||||
|
}
|
||||||
@@ -0,0 +1,50 @@
|
|||||||
|
/**
|
||||||
|
* Which engine the schema and repositories are built against.
|
||||||
|
*
|
||||||
|
* SQLite is not going away: the desktop app embeds its backend and cannot ship
|
||||||
|
* a database server, so it will always run on SQLite. Postgres and MySQL are
|
||||||
|
* for self-hosted deployments that need more than one process to reach the
|
||||||
|
* data. This is a multi-backend story, not a migration off SQLite.
|
||||||
|
*/
|
||||||
|
export type DatabaseDialect = "sqlite" | "postgres" | "mysql";
|
||||||
|
|
||||||
|
export const DATABASE_DIALECT_ENV = "DATABASE_DIALECT";
|
||||||
|
|
||||||
|
const SUPPORTED: readonly DatabaseDialect[] = ["sqlite", "postgres", "mysql"];
|
||||||
|
|
||||||
|
export function isDatabaseDialect(value: unknown): value is DatabaseDialect {
|
||||||
|
return (
|
||||||
|
typeof value === "string" &&
|
||||||
|
(SUPPORTED as readonly string[]).includes(value)
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Resolves the configured dialect, defaulting to SQLite so existing
|
||||||
|
* deployments and the desktop build are unaffected by this being added.
|
||||||
|
*/
|
||||||
|
export function resolveDatabaseDialect(
|
||||||
|
env: NodeJS.ProcessEnv = process.env,
|
||||||
|
): DatabaseDialect {
|
||||||
|
const raw = env[DATABASE_DIALECT_ENV]?.trim().toLowerCase();
|
||||||
|
if (!raw) return "sqlite";
|
||||||
|
|
||||||
|
if (!isDatabaseDialect(raw)) {
|
||||||
|
throw new Error(
|
||||||
|
`Unsupported ${DATABASE_DIALECT_ENV}: "${raw}". Expected one of ${SUPPORTED.join(", ")}.`,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
return raw;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Whether a write has to be explicitly persisted after it commits.
|
||||||
|
*
|
||||||
|
* SQLite here is an in-memory database serialised back to an encrypted file, so
|
||||||
|
* every write needs a trigger to flush it. Client-server engines have already
|
||||||
|
* durably committed by the time the query returns — there is no file to write
|
||||||
|
* and nothing to schedule.
|
||||||
|
*/
|
||||||
|
export function needsExplicitPersist(dialect: DatabaseDialect): boolean {
|
||||||
|
return dialect === "sqlite";
|
||||||
|
}
|
||||||
@@ -7,8 +7,21 @@ import { databaseLogger } from "../../utils/logger.js";
|
|||||||
import { DatabaseFileEncryption } from "../../utils/database-file-encryption.js";
|
import { DatabaseFileEncryption } from "../../utils/database-file-encryption.js";
|
||||||
import { SystemCrypto } from "../../utils/system-crypto.js";
|
import { SystemCrypto } from "../../utils/system-crypto.js";
|
||||||
import { DatabaseMigration } from "../../utils/database-migration.js";
|
import { DatabaseMigration } from "../../utils/database-migration.js";
|
||||||
|
import {
|
||||||
|
ensureSharedHostAuthOverrideProtocolSchema,
|
||||||
|
migrateLegacySharedHostAuthOverrides,
|
||||||
|
} from "../../utils/shared-host-auth-override-migration.js";
|
||||||
import { DatabaseSaveTrigger } from "../../utils/database-save-trigger.js";
|
import { DatabaseSaveTrigger } from "../../utils/database-save-trigger.js";
|
||||||
|
import { migrateAuditRetention } from "../../utils/audit-retention-migration.js";
|
||||||
|
import {
|
||||||
|
assertDataDirIsNotMisconfigured,
|
||||||
|
DataDirMisconfiguredError,
|
||||||
|
} from "../../utils/data-dir-guard.js";
|
||||||
import { getDefaultGuacdUrl } from "../../utils/guacd-config.js";
|
import { getDefaultGuacdUrl } from "../../utils/guacd-config.js";
|
||||||
|
import { resolveDatabaseDialect, type DatabaseDialect } from "./dialect.js";
|
||||||
|
import { connectRemoteDatabase } from "./connect.js";
|
||||||
|
import { runRemoteMigrations } from "./migrate.js";
|
||||||
|
import type { PortableDatabase } from "../repositories/database-context.js";
|
||||||
|
|
||||||
const dataDir = process.env.DATA_DIR || "./db/data";
|
const dataDir = process.env.DATA_DIR || "./db/data";
|
||||||
const dbDir = path.resolve(dataDir);
|
const dbDir = path.resolve(dataDir);
|
||||||
@@ -104,11 +117,16 @@ async function initializeDatabaseAsync(): Promise<void> {
|
|||||||
);
|
);
|
||||||
}
|
}
|
||||||
} else {
|
} else {
|
||||||
|
assertDataDirIsNotMisconfigured(dataDir);
|
||||||
memoryDatabase = new Database(":memory:");
|
memoryDatabase = new Database(":memory:");
|
||||||
isNewDatabase = true;
|
isNewDatabase = true;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
|
// Not a decryption problem: the database is fine, we are pointed at the
|
||||||
|
// wrong directory. Surface that message as-is.
|
||||||
|
if (error instanceof DataDirMisconfiguredError) throw error;
|
||||||
|
|
||||||
databaseLogger.error("Failed to initialize memory database", error, {
|
databaseLogger.error("Failed to initialize memory database", error, {
|
||||||
operation: "db_memory_init_failed",
|
operation: "db_memory_init_failed",
|
||||||
errorMessage: error instanceof Error ? error.message : "Unknown error",
|
errorMessage: error instanceof Error ? error.message : "Unknown error",
|
||||||
@@ -145,8 +163,35 @@ async function initializeDatabaseAsync(): Promise<void> {
|
|||||||
);
|
);
|
||||||
}
|
}
|
||||||
} else {
|
} else {
|
||||||
memoryDatabase = new Database(":memory:");
|
assertDataDirIsNotMisconfigured(dataDir);
|
||||||
isNewDatabase = true;
|
|
||||||
|
// The database still lives in memory and is serialised out on every write;
|
||||||
|
// turning encryption off only changes whether that file is ciphertext. It
|
||||||
|
// has to be read back, or each restart starts empty and silently discards
|
||||||
|
// everything the previous run saved.
|
||||||
|
const existing = readPlainDatabaseFile();
|
||||||
|
if (existing) {
|
||||||
|
memoryDatabase = new Database(existing);
|
||||||
|
databaseLogger.info("Loaded unencrypted database from disk", {
|
||||||
|
operation: "db_load_plain",
|
||||||
|
path: dbPath,
|
||||||
|
bytes: existing.length,
|
||||||
|
});
|
||||||
|
} else {
|
||||||
|
memoryDatabase = new Database(":memory:");
|
||||||
|
isNewDatabase = true;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/** The plain database file, or null when there is nothing to restore. */
|
||||||
|
function readPlainDatabaseFile(): Buffer | null {
|
||||||
|
try {
|
||||||
|
const contents = fs.readFileSync(dbPath);
|
||||||
|
return contents.length > 0 ? contents : null;
|
||||||
|
} catch (error) {
|
||||||
|
if ((error as NodeJS.ErrnoException).code === "ENOENT") return null;
|
||||||
|
throw error;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -472,13 +517,14 @@ async function initializeCompleteDatabase(): Promise<void> {
|
|||||||
success INTEGER NOT NULL,
|
success INTEGER NOT NULL,
|
||||||
error_message TEXT,
|
error_message TEXT,
|
||||||
timestamp TEXT NOT NULL DEFAULT CURRENT_TIMESTAMP,
|
timestamp TEXT NOT NULL DEFAULT CURRENT_TIMESTAMP,
|
||||||
FOREIGN KEY (user_id) REFERENCES users (id) ON DELETE CASCADE
|
FOREIGN KEY (user_id) REFERENCES users (id) ON DELETE SET NULL
|
||||||
);
|
);
|
||||||
|
|
||||||
CREATE TABLE IF NOT EXISTS session_recordings (
|
CREATE TABLE IF NOT EXISTS session_recordings (
|
||||||
id INTEGER PRIMARY KEY AUTOINCREMENT,
|
id INTEGER PRIMARY KEY AUTOINCREMENT,
|
||||||
host_id INTEGER NOT NULL,
|
host_id INTEGER NOT NULL,
|
||||||
user_id TEXT NOT NULL,
|
user_id TEXT,
|
||||||
|
username TEXT,
|
||||||
access_id INTEGER,
|
access_id INTEGER,
|
||||||
started_at TEXT NOT NULL DEFAULT CURRENT_TIMESTAMP,
|
started_at TEXT NOT NULL DEFAULT CURRENT_TIMESTAMP,
|
||||||
ended_at TEXT,
|
ended_at TEXT,
|
||||||
@@ -491,7 +537,7 @@ async function initializeCompleteDatabase(): Promise<void> {
|
|||||||
terminated_by_owner INTEGER DEFAULT 0,
|
terminated_by_owner INTEGER DEFAULT 0,
|
||||||
termination_reason TEXT,
|
termination_reason TEXT,
|
||||||
FOREIGN KEY (host_id) REFERENCES ssh_data (id) ON DELETE CASCADE,
|
FOREIGN KEY (host_id) REFERENCES ssh_data (id) ON DELETE CASCADE,
|
||||||
FOREIGN KEY (user_id) REFERENCES users (id) ON DELETE CASCADE,
|
FOREIGN KEY (user_id) REFERENCES users (id) ON DELETE SET NULL,
|
||||||
FOREIGN KEY (access_id) REFERENCES host_access (id) ON DELETE SET NULL
|
FOREIGN KEY (access_id) REFERENCES host_access (id) ON DELETE SET NULL
|
||||||
);
|
);
|
||||||
|
|
||||||
@@ -1418,6 +1464,28 @@ const migrateSchema = () => {
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
try {
|
||||||
|
ensureSharedHostAuthOverrideProtocolSchema(sqlite);
|
||||||
|
} catch (schemaError) {
|
||||||
|
databaseLogger.warn("Failed to prepare shared_host_auth_overrides table", {
|
||||||
|
operation: "schema_migration",
|
||||||
|
error: schemaError,
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
try {
|
||||||
|
migrateLegacySharedHostAuthOverrides(
|
||||||
|
sqlite,
|
||||||
|
getRawSettingValue,
|
||||||
|
setRawSettingValue,
|
||||||
|
);
|
||||||
|
} catch (migrateError) {
|
||||||
|
databaseLogger.warn("Failed to migrate shared host auth overrides", {
|
||||||
|
operation: "schema_migration",
|
||||||
|
error: migrateError,
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
try {
|
try {
|
||||||
sqlite.prepare("SELECT credential_id FROM ssh_folders LIMIT 1").get();
|
sqlite.prepare("SELECT credential_id FROM ssh_folders LIMIT 1").get();
|
||||||
} catch {
|
} catch {
|
||||||
@@ -1448,6 +1516,7 @@ const migrateSchema = () => {
|
|||||||
{ column: "connection_type", sql: "ALTER TABLE ssh_data ADD COLUMN connection_type TEXT NOT NULL DEFAULT 'ssh'" },
|
{ column: "connection_type", sql: "ALTER TABLE ssh_data ADD COLUMN connection_type TEXT NOT NULL DEFAULT 'ssh'" },
|
||||||
{ column: "credential_id", sql: "ALTER TABLE ssh_data ADD COLUMN credential_id INTEGER" },
|
{ column: "credential_id", sql: "ALTER TABLE ssh_data ADD COLUMN credential_id INTEGER" },
|
||||||
{ column: "override_credential_username", sql: "ALTER TABLE ssh_data ADD COLUMN override_credential_username INTEGER" },
|
{ column: "override_credential_username", sql: "ALTER TABLE ssh_data ADD COLUMN override_credential_username INTEGER" },
|
||||||
|
{ column: "share_ssh_auth", sql: "ALTER TABLE ssh_data ADD COLUMN share_ssh_auth INTEGER NOT NULL DEFAULT 0" },
|
||||||
{ column: "jump_hosts", sql: "ALTER TABLE ssh_data ADD COLUMN jump_hosts TEXT" },
|
{ column: "jump_hosts", sql: "ALTER TABLE ssh_data ADD COLUMN jump_hosts TEXT" },
|
||||||
{ column: "show_terminal_in_sidebar", sql: "ALTER TABLE ssh_data ADD COLUMN show_terminal_in_sidebar INTEGER NOT NULL DEFAULT 1" },
|
{ column: "show_terminal_in_sidebar", sql: "ALTER TABLE ssh_data ADD COLUMN show_terminal_in_sidebar INTEGER NOT NULL DEFAULT 1" },
|
||||||
{ column: "show_file_manager_in_sidebar", sql: "ALTER TABLE ssh_data ADD COLUMN show_file_manager_in_sidebar INTEGER NOT NULL DEFAULT 0" },
|
{ column: "show_file_manager_in_sidebar", sql: "ALTER TABLE ssh_data ADD COLUMN show_file_manager_in_sidebar INTEGER NOT NULL DEFAULT 0" },
|
||||||
@@ -1637,7 +1706,7 @@ const migrateSchema = () => {
|
|||||||
sqlite.exec(`
|
sqlite.exec(`
|
||||||
CREATE TABLE IF NOT EXISTS audit_logs (
|
CREATE TABLE IF NOT EXISTS audit_logs (
|
||||||
id INTEGER PRIMARY KEY AUTOINCREMENT,
|
id INTEGER PRIMARY KEY AUTOINCREMENT,
|
||||||
user_id TEXT NOT NULL,
|
user_id TEXT,
|
||||||
username TEXT NOT NULL,
|
username TEXT NOT NULL,
|
||||||
action TEXT NOT NULL,
|
action TEXT NOT NULL,
|
||||||
resource_type TEXT NOT NULL,
|
resource_type TEXT NOT NULL,
|
||||||
@@ -1649,7 +1718,7 @@ const migrateSchema = () => {
|
|||||||
success INTEGER NOT NULL,
|
success INTEGER NOT NULL,
|
||||||
error_message TEXT,
|
error_message TEXT,
|
||||||
timestamp TEXT NOT NULL DEFAULT CURRENT_TIMESTAMP,
|
timestamp TEXT NOT NULL DEFAULT CURRENT_TIMESTAMP,
|
||||||
FOREIGN KEY (user_id) REFERENCES users (id) ON DELETE CASCADE
|
FOREIGN KEY (user_id) REFERENCES users (id) ON DELETE SET NULL
|
||||||
);
|
);
|
||||||
`);
|
`);
|
||||||
} catch (createError) {
|
} catch (createError) {
|
||||||
@@ -2497,6 +2566,10 @@ const migrateSchema = () => {
|
|||||||
}
|
}
|
||||||
// --- sync end ---
|
// --- sync end ---
|
||||||
|
|
||||||
|
// Audit trails and session recordings used to be deleted along with the user
|
||||||
|
// they referenced, which defeats the point of keeping them.
|
||||||
|
migrateAuditRetention(sqlite);
|
||||||
|
|
||||||
databaseLogger.success("Schema migration completed", {
|
databaseLogger.success("Schema migration completed", {
|
||||||
operation: "schema_migration",
|
operation: "schema_migration",
|
||||||
});
|
});
|
||||||
@@ -2580,10 +2653,54 @@ async function handlePostInitFileEncryption() {
|
|||||||
}
|
}
|
||||||
|
|
||||||
async function initializeDatabase(): Promise<void> {
|
async function initializeDatabase(): Promise<void> {
|
||||||
|
const dialect = resolveDatabaseDialect();
|
||||||
|
|
||||||
|
if (dialect !== "sqlite") {
|
||||||
|
await initializeRemoteDatabase(dialect);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
await initializeCompleteDatabase();
|
await initializeCompleteDatabase();
|
||||||
await handlePostInitFileEncryption();
|
await handlePostInitFileEncryption();
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Startup against Postgres or MySQL.
|
||||||
|
*
|
||||||
|
* Shorter than the SQLite path because most of what that one does has no
|
||||||
|
* counterpart here: there is no file to decrypt, no in-memory copy to keep in
|
||||||
|
* step with disk, and the schema comes from drizzle-kit migrations instead of
|
||||||
|
* the inline DDL below.
|
||||||
|
*
|
||||||
|
* What does carry over is the settings cache. 27 call sites read settings
|
||||||
|
* synchronously, which better-sqlite3 allows and no remote driver does, so the
|
||||||
|
* table is loaded once here before anything asks for it.
|
||||||
|
*/
|
||||||
|
async function initializeRemoteDatabase(
|
||||||
|
dialect: Exclude<DatabaseDialect, "sqlite">,
|
||||||
|
): Promise<void> {
|
||||||
|
databaseLogger.info(`Connecting to ${dialect} database`, {
|
||||||
|
operation: "db_init",
|
||||||
|
dialect,
|
||||||
|
});
|
||||||
|
|
||||||
|
db = await connectRemoteDatabase(dialect);
|
||||||
|
await runRemoteMigrations(dialect, db);
|
||||||
|
|
||||||
|
// Imported here rather than at the top: factory.ts imports getDb from this
|
||||||
|
// module, and a static import would close the cycle at module-load time.
|
||||||
|
const { primeCurrentSettingsCache, startSettingsCacheRefresh } = await import(
|
||||||
|
"../repositories/factory.js"
|
||||||
|
);
|
||||||
|
await primeCurrentSettingsCache();
|
||||||
|
startSettingsCacheRefresh();
|
||||||
|
|
||||||
|
databaseLogger.info(`${dialect} database ready`, {
|
||||||
|
operation: "db_init_complete",
|
||||||
|
dialect,
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
export { initializeDatabase };
|
export { initializeDatabase };
|
||||||
|
|
||||||
async function cleanupDatabase() {
|
async function cleanupDatabase() {
|
||||||
@@ -2661,9 +2778,9 @@ process.on("SIGTERM", async () => {
|
|||||||
process.exit(0);
|
process.exit(0);
|
||||||
});
|
});
|
||||||
|
|
||||||
let db: ReturnType<typeof drizzle<typeof schema>>;
|
let db: PortableDatabase;
|
||||||
|
|
||||||
export function getDb(): ReturnType<typeof drizzle<typeof schema>> {
|
export function getDb(): PortableDatabase {
|
||||||
if (!db) {
|
if (!db) {
|
||||||
throw new Error(
|
throw new Error(
|
||||||
"Database not initialized. Ensure initializeDatabase() is called before accessing db.",
|
"Database not initialized. Ensure initializeDatabase() is called before accessing db.",
|
||||||
@@ -2674,6 +2791,13 @@ export function getDb(): ReturnType<typeof drizzle<typeof schema>> {
|
|||||||
|
|
||||||
export function getSqlite(): Database.Database {
|
export function getSqlite(): Database.Database {
|
||||||
if (!sqlite) {
|
if (!sqlite) {
|
||||||
|
const dialect = resolveDatabaseDialect();
|
||||||
|
if (dialect !== "sqlite") {
|
||||||
|
throw new Error(
|
||||||
|
`No SQLite handle: DATABASE_DIALECT is "${dialect}". This caller needs a ` +
|
||||||
|
`synchronous query, which only SQLite offers — give it an async path instead.`,
|
||||||
|
);
|
||||||
|
}
|
||||||
throw new Error(
|
throw new Error(
|
||||||
"SQLite not initialized. Ensure initializeDatabase() is called before accessing sqlite.",
|
"SQLite not initialized. Ensure initializeDatabase() is called before accessing sqlite.",
|
||||||
);
|
);
|
||||||
|
|||||||
@@ -0,0 +1,51 @@
|
|||||||
|
import path from "path";
|
||||||
|
import type { DatabaseDialect } from "./dialect.js";
|
||||||
|
import type { PortableDatabase } from "../repositories/database-context.js";
|
||||||
|
|
||||||
|
export const MIGRATIONS_DIR_ENV = "DRIZZLE_MIGRATIONS_DIR";
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Where the generated migrations live.
|
||||||
|
*
|
||||||
|
* SQLite does not appear here: it builds its schema from the DDL in index.ts
|
||||||
|
* and patches it forward with migrateSchema(). Only the client-server engines
|
||||||
|
* use drizzle-kit migrations, and each has its own folder because the
|
||||||
|
* generated SQL differs per dialect.
|
||||||
|
*/
|
||||||
|
export function migrationsFolder(
|
||||||
|
dialect: DatabaseDialect,
|
||||||
|
env: NodeJS.ProcessEnv = process.env,
|
||||||
|
): string {
|
||||||
|
const override = env[MIGRATIONS_DIR_ENV]?.trim();
|
||||||
|
const root = override || path.resolve(process.cwd(), "drizzle");
|
||||||
|
return path.join(root, dialect);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Brings a remote database up to the current schema.
|
||||||
|
*
|
||||||
|
* drizzle's migrator records what it has applied in its own table, so this is
|
||||||
|
* safe to run on every start — including against a database another instance
|
||||||
|
* already migrated.
|
||||||
|
*/
|
||||||
|
export async function runRemoteMigrations(
|
||||||
|
dialect: DatabaseDialect,
|
||||||
|
db: PortableDatabase,
|
||||||
|
env: NodeJS.ProcessEnv = process.env,
|
||||||
|
): Promise<void> {
|
||||||
|
if (dialect === "sqlite") {
|
||||||
|
throw new Error("SQLite builds its schema in index.ts, not from drizzle/");
|
||||||
|
}
|
||||||
|
|
||||||
|
const folder = migrationsFolder(dialect, env);
|
||||||
|
|
||||||
|
const { migrate } =
|
||||||
|
dialect === "postgres"
|
||||||
|
? await import("drizzle-orm/node-postgres/migrator")
|
||||||
|
: await import("drizzle-orm/mysql2/migrator");
|
||||||
|
|
||||||
|
await (migrate as (db: unknown, config: { migrationsFolder: string }) => Promise<void>)(
|
||||||
|
db,
|
||||||
|
{ migrationsFolder: folder },
|
||||||
|
);
|
||||||
|
}
|
||||||
File diff suppressed because it is too large
Load Diff
File diff suppressed because it is too large
Load Diff
@@ -1,4 +1,10 @@
|
|||||||
import { sqliteTable, text, integer, real } from "drizzle-orm/sqlite-core";
|
import {
|
||||||
|
sqliteTable,
|
||||||
|
text,
|
||||||
|
integer,
|
||||||
|
real,
|
||||||
|
uniqueIndex,
|
||||||
|
} from "drizzle-orm/sqlite-core";
|
||||||
import { sql } from "drizzle-orm";
|
import { sql } from "drizzle-orm";
|
||||||
|
|
||||||
export const users = sqliteTable("users", {
|
export const users = sqliteTable("users", {
|
||||||
@@ -124,6 +130,9 @@ export const hosts = sqliteTable("ssh_data", {
|
|||||||
pin: integer("pin", { mode: "boolean" }).notNull().default(false),
|
pin: integer("pin", { mode: "boolean" }).notNull().default(false),
|
||||||
authType: text("auth_type").notNull(),
|
authType: text("auth_type").notNull(),
|
||||||
useWarpgate: integer("use_warpgate", { mode: "boolean" }).notNull().default(false),
|
useWarpgate: integer("use_warpgate", { mode: "boolean" }).notNull().default(false),
|
||||||
|
shareSshAuth: integer("share_ssh_auth", { mode: "boolean" })
|
||||||
|
.notNull()
|
||||||
|
.default(false),
|
||||||
forceKeyboardInteractive: text("force_keyboard_interactive"),
|
forceKeyboardInteractive: text("force_keyboard_interactive"),
|
||||||
|
|
||||||
password: text("password"),
|
password: text("password"),
|
||||||
@@ -560,46 +569,85 @@ export const hostAccess = sqliteTable("host_access", {
|
|||||||
.default(sql`CURRENT_TIMESTAMP`),
|
.default(sql`CURRENT_TIMESTAMP`),
|
||||||
lastAccessedAt: text("last_accessed_at"),
|
lastAccessedAt: text("last_accessed_at"),
|
||||||
accessCount: integer("access_count").notNull().default(0),
|
accessCount: integer("access_count").notNull().default(0),
|
||||||
overrideCredentialId: integer("override_credential_id").references(
|
|
||||||
() => sshCredentials.id,
|
|
||||||
{ onDelete: "set null" },
|
|
||||||
),
|
|
||||||
});
|
});
|
||||||
|
|
||||||
export const sharedHostSecrets = sqliteTable("shared_host_secrets", {
|
export const sharedHostAuthOverrides = sqliteTable(
|
||||||
id: integer("id").primaryKey({ autoIncrement: true }),
|
"shared_host_auth_overrides",
|
||||||
|
{
|
||||||
|
id: integer("id").primaryKey({ autoIncrement: true }),
|
||||||
|
hostId: integer("host_id")
|
||||||
|
.notNull()
|
||||||
|
.references(() => hosts.id, { onDelete: "cascade" }),
|
||||||
|
userId: text("user_id")
|
||||||
|
.notNull()
|
||||||
|
.references(() => users.id, { onDelete: "cascade" }),
|
||||||
|
protocol: text("protocol").notNull().default("ssh"),
|
||||||
|
credentialId: integer("credential_id")
|
||||||
|
.notNull()
|
||||||
|
.references(() => sshCredentials.id, { onDelete: "cascade" }),
|
||||||
|
createdAt: text("created_at")
|
||||||
|
.notNull()
|
||||||
|
.default(sql`CURRENT_TIMESTAMP`),
|
||||||
|
updatedAt: text("updated_at")
|
||||||
|
.notNull()
|
||||||
|
.default(sql`CURRENT_TIMESTAMP`),
|
||||||
|
},
|
||||||
|
(table) => [
|
||||||
|
uniqueIndex("shared_host_auth_overrides_host_user_protocol_unique").on(
|
||||||
|
table.hostId,
|
||||||
|
table.userId,
|
||||||
|
table.protocol,
|
||||||
|
),
|
||||||
|
],
|
||||||
|
);
|
||||||
|
|
||||||
hostAccessId: integer("host_access_id")
|
export const sharedHostSecrets = sqliteTable(
|
||||||
.notNull()
|
"shared_host_secrets",
|
||||||
.references(() => hostAccess.id, { onDelete: "cascade" }),
|
{
|
||||||
|
id: integer("id").primaryKey({ autoIncrement: true }),
|
||||||
|
|
||||||
targetUserId: text("target_user_id")
|
hostAccessId: integer("host_access_id")
|
||||||
.notNull()
|
.notNull()
|
||||||
.references(() => users.id, { onDelete: "cascade" }),
|
.references(() => hostAccess.id, { onDelete: "cascade" }),
|
||||||
|
|
||||||
protocol: text("protocol").notNull().default("ssh"),
|
targetUserId: text("target_user_id")
|
||||||
sourceType: text("source_type").notNull().default("credential"),
|
.notNull()
|
||||||
|
.references(() => users.id, { onDelete: "cascade" }),
|
||||||
|
|
||||||
originalCredentialId: integer("original_credential_id").references(
|
protocol: text("protocol").notNull().default("ssh"),
|
||||||
() => sshCredentials.id,
|
sourceType: text("source_type").notNull().default("credential"),
|
||||||
{ onDelete: "cascade" },
|
|
||||||
),
|
|
||||||
|
|
||||||
encryptedUsername: text("encrypted_username"),
|
originalCredentialId: integer("original_credential_id").references(
|
||||||
encryptedAuthType: text("encrypted_auth_type"),
|
() => sshCredentials.id,
|
||||||
encryptedPassword: text("encrypted_password"),
|
{ onDelete: "cascade" },
|
||||||
encryptedKey: text("encrypted_key", { length: 16384 }),
|
),
|
||||||
encryptedKeyPassword: text("encrypted_key_password"),
|
|
||||||
encryptedKeyType: text("encrypted_key_type"),
|
|
||||||
encryptedDomain: text("encrypted_domain"),
|
|
||||||
|
|
||||||
createdAt: text("created_at")
|
encryptedUsername: text("encrypted_username"),
|
||||||
.notNull()
|
encryptedAuthType: text("encrypted_auth_type"),
|
||||||
.default(sql`CURRENT_TIMESTAMP`),
|
encryptedPassword: text("encrypted_password"),
|
||||||
updatedAt: text("updated_at")
|
encryptedKey: text("encrypted_key", { length: 16384 }),
|
||||||
.notNull()
|
encryptedKeyPassword: text("encrypted_key_password"),
|
||||||
.default(sql`CURRENT_TIMESTAMP`),
|
encryptedKeyType: text("encrypted_key_type"),
|
||||||
});
|
encryptedDomain: text("encrypted_domain"),
|
||||||
|
|
||||||
|
createdAt: text("created_at")
|
||||||
|
.notNull()
|
||||||
|
.default(sql`CURRENT_TIMESTAMP`),
|
||||||
|
updatedAt: text("updated_at")
|
||||||
|
.notNull()
|
||||||
|
.default(sql`CURRENT_TIMESTAMP`),
|
||||||
|
},
|
||||||
|
// Declared inline in the production DDL as UNIQUE(...), but never here,
|
||||||
|
// so the generated Postgres and MySQL schemas allowed duplicates the
|
||||||
|
// SQLite deployment forbids — and the upsert had nothing to conflict on.
|
||||||
|
(table) => [
|
||||||
|
uniqueIndex("idx_shared_host_secrets_scope").on(
|
||||||
|
table.hostAccessId,
|
||||||
|
table.targetUserId,
|
||||||
|
table.protocol,
|
||||||
|
),
|
||||||
|
],
|
||||||
|
);
|
||||||
|
|
||||||
export const roles = sqliteTable("roles", {
|
export const roles = sqliteTable("roles", {
|
||||||
id: integer("id").primaryKey({ autoIncrement: true }),
|
id: integer("id").primaryKey({ autoIncrement: true }),
|
||||||
@@ -621,29 +669,36 @@ export const roles = sqliteTable("roles", {
|
|||||||
.default(sql`CURRENT_TIMESTAMP`),
|
.default(sql`CURRENT_TIMESTAMP`),
|
||||||
});
|
});
|
||||||
|
|
||||||
export const userRoles = sqliteTable("user_roles", {
|
export const userRoles = sqliteTable(
|
||||||
id: integer("id").primaryKey({ autoIncrement: true }),
|
"user_roles",
|
||||||
userId: text("user_id")
|
{
|
||||||
.notNull()
|
id: integer("id").primaryKey({ autoIncrement: true }),
|
||||||
.references(() => users.id, { onDelete: "cascade" }),
|
userId: text("user_id")
|
||||||
roleId: integer("role_id")
|
.notNull()
|
||||||
.notNull()
|
.references(() => users.id, { onDelete: "cascade" }),
|
||||||
.references(() => roles.id, { onDelete: "cascade" }),
|
roleId: integer("role_id")
|
||||||
|
.notNull()
|
||||||
|
.references(() => roles.id, { onDelete: "cascade" }),
|
||||||
|
|
||||||
grantedBy: text("granted_by").references(() => users.id, {
|
grantedBy: text("granted_by").references(() => users.id, {
|
||||||
onDelete: "set null",
|
onDelete: "set null",
|
||||||
}),
|
}),
|
||||||
grantedAt: text("granted_at")
|
grantedAt: text("granted_at")
|
||||||
.notNull()
|
.notNull()
|
||||||
.default(sql`CURRENT_TIMESTAMP`),
|
.default(sql`CURRENT_TIMESTAMP`),
|
||||||
});
|
},
|
||||||
|
// Declared inline in the production DDL as UNIQUE(...), but never here,
|
||||||
|
// so the generated Postgres and MySQL schemas allowed duplicates the
|
||||||
|
// SQLite deployment forbids — and the upsert had nothing to conflict on.
|
||||||
|
(table) => [uniqueIndex("idx_user_roles_user_role").on(table.userId, table.roleId)],
|
||||||
|
);
|
||||||
|
|
||||||
export const auditLogs = sqliteTable("audit_logs", {
|
export const auditLogs = sqliteTable("audit_logs", {
|
||||||
id: integer("id").primaryKey({ autoIncrement: true }),
|
id: integer("id").primaryKey({ autoIncrement: true }),
|
||||||
|
|
||||||
userId: text("user_id")
|
// Nullable on purpose: the trail outlives the account, and username keeps the
|
||||||
.notNull()
|
// entry attributable once the reference is gone.
|
||||||
.references(() => users.id, { onDelete: "cascade" }),
|
userId: text("user_id").references(() => users.id, { onDelete: "set null" }),
|
||||||
username: text("username").notNull(),
|
username: text("username").notNull(),
|
||||||
|
|
||||||
action: text("action").notNull(),
|
action: text("action").notNull(),
|
||||||
@@ -669,9 +724,10 @@ export const sessionRecordings = sqliteTable("session_recordings", {
|
|||||||
hostId: integer("host_id")
|
hostId: integer("host_id")
|
||||||
.notNull()
|
.notNull()
|
||||||
.references(() => hosts.id, { onDelete: "cascade" }),
|
.references(() => hosts.id, { onDelete: "cascade" }),
|
||||||
userId: text("user_id")
|
// Nullable on purpose: a recording is evidence about the host as much as the
|
||||||
.notNull()
|
// person, so it outlives the account. username keeps it attributable.
|
||||||
.references(() => users.id, { onDelete: "cascade" }),
|
userId: text("user_id").references(() => users.id, { onDelete: "set null" }),
|
||||||
|
username: text("username"),
|
||||||
accessId: integer("access_id").references(() => hostAccess.id, {
|
accessId: integer("access_id").references(() => hostAccess.id, {
|
||||||
onDelete: "set null",
|
onDelete: "set null",
|
||||||
}),
|
}),
|
||||||
@@ -750,29 +806,36 @@ export const sessionShareParticipants = sqliteTable(
|
|||||||
},
|
},
|
||||||
);
|
);
|
||||||
|
|
||||||
export const opksshTokens = sqliteTable("opkssh_tokens", {
|
export const opksshTokens = sqliteTable(
|
||||||
id: integer("id").primaryKey({ autoIncrement: true }),
|
"opkssh_tokens",
|
||||||
userId: text("user_id")
|
{
|
||||||
.notNull()
|
id: integer("id").primaryKey({ autoIncrement: true }),
|
||||||
.references(() => users.id, { onDelete: "cascade" }),
|
userId: text("user_id")
|
||||||
hostId: integer("host_id")
|
.notNull()
|
||||||
.notNull()
|
.references(() => users.id, { onDelete: "cascade" }),
|
||||||
.references(() => hosts.id, { onDelete: "cascade" }),
|
hostId: integer("host_id")
|
||||||
|
.notNull()
|
||||||
|
.references(() => hosts.id, { onDelete: "cascade" }),
|
||||||
|
|
||||||
sshCert: text("ssh_cert", { length: 8192 }).notNull(),
|
sshCert: text("ssh_cert", { length: 8192 }).notNull(),
|
||||||
privateKey: text("private_key", { length: 8192 }).notNull(),
|
privateKey: text("private_key", { length: 8192 }).notNull(),
|
||||||
|
|
||||||
email: text("email"),
|
email: text("email"),
|
||||||
sub: text("sub"),
|
sub: text("sub"),
|
||||||
issuer: text("issuer"),
|
issuer: text("issuer"),
|
||||||
audience: text("audience"),
|
audience: text("audience"),
|
||||||
|
|
||||||
createdAt: text("created_at")
|
createdAt: text("created_at")
|
||||||
.notNull()
|
.notNull()
|
||||||
.default(sql`CURRENT_TIMESTAMP`),
|
.default(sql`CURRENT_TIMESTAMP`),
|
||||||
expiresAt: text("expires_at").notNull(),
|
expiresAt: text("expires_at").notNull(),
|
||||||
lastUsed: text("last_used"),
|
lastUsed: text("last_used"),
|
||||||
});
|
},
|
||||||
|
// Declared inline in the production DDL as UNIQUE(...), but never here,
|
||||||
|
// so the generated Postgres and MySQL schemas allowed duplicates the
|
||||||
|
// SQLite deployment forbids — and the upsert had nothing to conflict on.
|
||||||
|
(table) => [uniqueIndex("idx_opkssh_tokens_user_host").on(table.userId, table.hostId)],
|
||||||
|
);
|
||||||
|
|
||||||
// Vault SSH signer profiles. These hold ONLY non-secret connection settings and
|
// Vault SSH signer profiles. These hold ONLY non-secret connection settings and
|
||||||
// are intended to be shared across users (shared === true makes a profile
|
// are intended to be shared across users (shared === true makes a profile
|
||||||
@@ -813,24 +876,31 @@ export const vaultProfiles = sqliteTable("vault_profiles", {
|
|||||||
// Per-user cache of the ephemeral SSH private key + Vault-signed certificate.
|
// Per-user cache of the ephemeral SSH private key + Vault-signed certificate.
|
||||||
// Transient: rows live only until the certificate expires. Secret fields are
|
// Transient: rows live only until the certificate expires. Secret fields are
|
||||||
// encrypted under the user's data-encryption key (see field-crypto.ts).
|
// encrypted under the user's data-encryption key (see field-crypto.ts).
|
||||||
export const vaultTokens = sqliteTable("vault_tokens", {
|
export const vaultTokens = sqliteTable(
|
||||||
id: integer("id").primaryKey({ autoIncrement: true }),
|
"vault_tokens",
|
||||||
userId: text("user_id")
|
{
|
||||||
.notNull()
|
id: integer("id").primaryKey({ autoIncrement: true }),
|
||||||
.references(() => users.id, { onDelete: "cascade" }),
|
userId: text("user_id")
|
||||||
profileId: integer("profile_id")
|
.notNull()
|
||||||
.notNull()
|
.references(() => users.id, { onDelete: "cascade" }),
|
||||||
.references(() => vaultProfiles.id, { onDelete: "cascade" }),
|
profileId: integer("profile_id")
|
||||||
|
.notNull()
|
||||||
|
.references(() => vaultProfiles.id, { onDelete: "cascade" }),
|
||||||
|
|
||||||
sshCert: text("ssh_cert", { length: 8192 }).notNull(),
|
sshCert: text("ssh_cert", { length: 8192 }).notNull(),
|
||||||
privateKey: text("private_key", { length: 8192 }).notNull(),
|
privateKey: text("private_key", { length: 8192 }).notNull(),
|
||||||
|
|
||||||
createdAt: text("created_at")
|
createdAt: text("created_at")
|
||||||
.notNull()
|
.notNull()
|
||||||
.default(sql`CURRENT_TIMESTAMP`),
|
.default(sql`CURRENT_TIMESTAMP`),
|
||||||
expiresAt: text("expires_at").notNull(),
|
expiresAt: text("expires_at").notNull(),
|
||||||
lastUsed: text("last_used"),
|
lastUsed: text("last_used"),
|
||||||
});
|
},
|
||||||
|
// Declared inline in the production DDL as UNIQUE(...), but never here,
|
||||||
|
// so the generated Postgres and MySQL schemas allowed duplicates the
|
||||||
|
// SQLite deployment forbids — and the upsert had nothing to conflict on.
|
||||||
|
(table) => [uniqueIndex("idx_vault_tokens_user_profile").on(table.userId, table.profileId)],
|
||||||
|
);
|
||||||
|
|
||||||
export const apiKeys = sqliteTable("api_keys", {
|
export const apiKeys = sqliteTable("api_keys", {
|
||||||
id: text("id").primaryKey(),
|
id: text("id").primaryKey(),
|
||||||
@@ -898,7 +968,9 @@ export const userPreferences = sqliteTable("user_preferences", {
|
|||||||
.default(sql`CURRENT_TIMESTAMP`),
|
.default(sql`CURRENT_TIMESTAMP`),
|
||||||
});
|
});
|
||||||
|
|
||||||
export const hostMetricsPreferences = sqliteTable("host_metrics_preferences", {
|
export const hostMetricsPreferences = sqliteTable(
|
||||||
|
"host_metrics_preferences",
|
||||||
|
{
|
||||||
id: integer("id").primaryKey({ autoIncrement: true }),
|
id: integer("id").primaryKey({ autoIncrement: true }),
|
||||||
userId: text("user_id")
|
userId: text("user_id")
|
||||||
.notNull()
|
.notNull()
|
||||||
@@ -915,9 +987,18 @@ export const hostMetricsPreferences = sqliteTable("host_metrics_preferences", {
|
|||||||
updatedAt: text("updated_at")
|
updatedAt: text("updated_at")
|
||||||
.notNull()
|
.notNull()
|
||||||
.default(sql`CURRENT_TIMESTAMP`),
|
.default(sql`CURRENT_TIMESTAMP`),
|
||||||
});
|
},
|
||||||
|
// One layout per user per host. Enforced in production since the inline DDL
|
||||||
|
// creates it, but it was never declared here, so the generated Postgres and
|
||||||
|
// MySQL schemas lacked it — and the upsert has nothing to conflict on.
|
||||||
|
(table) => [
|
||||||
|
uniqueIndex("idx_host_metrics_prefs_user_host").on(table.userId, table.hostId),
|
||||||
|
],
|
||||||
|
);
|
||||||
|
|
||||||
export const hostHealthChecks = sqliteTable("host_health_checks", {
|
export const hostHealthChecks = sqliteTable(
|
||||||
|
"host_health_checks",
|
||||||
|
{
|
||||||
id: integer("id").primaryKey({ autoIncrement: true }),
|
id: integer("id").primaryKey({ autoIncrement: true }),
|
||||||
userId: text("user_id")
|
userId: text("user_id")
|
||||||
.notNull()
|
.notNull()
|
||||||
@@ -934,7 +1015,12 @@ export const hostHealthChecks = sqliteTable("host_health_checks", {
|
|||||||
updatedAt: text("updated_at")
|
updatedAt: text("updated_at")
|
||||||
.notNull()
|
.notNull()
|
||||||
.default(sql`CURRENT_TIMESTAMP`),
|
.default(sql`CURRENT_TIMESTAMP`),
|
||||||
});
|
},
|
||||||
|
// Same as above: one set of checks per user per host.
|
||||||
|
(table) => [
|
||||||
|
uniqueIndex("idx_host_health_checks_user_host").on(table.userId, table.hostId),
|
||||||
|
],
|
||||||
|
);
|
||||||
|
|
||||||
export const hostHealthHistory = sqliteTable("host_health_history", {
|
export const hostHealthHistory = sqliteTable("host_health_history", {
|
||||||
id: integer("id").primaryKey({ autoIncrement: true }),
|
id: integer("id").primaryKey({ autoIncrement: true }),
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
import { and, count, desc, eq, inArray, isNull, or } from "drizzle-orm";
|
import { and, count, desc, eq, inArray, isNull, lt, or } from "drizzle-orm";
|
||||||
import {
|
import {
|
||||||
alertFirings,
|
alertFirings,
|
||||||
alertRuleChannels,
|
alertRuleChannels,
|
||||||
@@ -7,6 +7,9 @@ import {
|
|||||||
notificationChannels,
|
notificationChannels,
|
||||||
} from "../db/schema.js";
|
} from "../db/schema.js";
|
||||||
import type { DatabaseContext } from "./database-context.js";
|
import type { DatabaseContext } from "./database-context.js";
|
||||||
|
import { sqlTimestampDaysAgo } from "./sql-timestamp.js";
|
||||||
|
import { rowsAffected } from "./mutation-result.js";
|
||||||
|
import { insertReturning, updateReturning } from "./returning.js";
|
||||||
|
|
||||||
type AlertRuleRecord = typeof alertRules.$inferSelect;
|
type AlertRuleRecord = typeof alertRules.$inferSelect;
|
||||||
type NotificationChannelRecord = typeof notificationChannels.$inferSelect;
|
type NotificationChannelRecord = typeof notificationChannels.$inferSelect;
|
||||||
@@ -117,16 +120,17 @@ export class AlertRepository {
|
|||||||
config: string;
|
config: string;
|
||||||
enabled: boolean;
|
enabled: boolean;
|
||||||
}): Promise<NotificationChannelRow> {
|
}): Promise<NotificationChannelRow> {
|
||||||
const [created] = await this.context.drizzle
|
const [created] = await insertReturning(
|
||||||
.insert(notificationChannels)
|
this.context,
|
||||||
.values({
|
notificationChannels,
|
||||||
|
{
|
||||||
userId: input.userId,
|
userId: input.userId,
|
||||||
name: input.name,
|
name: input.name,
|
||||||
type: input.type,
|
type: input.type,
|
||||||
config: input.config,
|
config: input.config,
|
||||||
enabled: input.enabled,
|
enabled: input.enabled,
|
||||||
})
|
},
|
||||||
.returning();
|
);
|
||||||
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return mapChannelRow(created);
|
return mapChannelRow(created);
|
||||||
@@ -146,16 +150,15 @@ export class AlertRepository {
|
|||||||
return this.findNotificationChannelForUser(id, userId);
|
return this.findNotificationChannelForUser(id, userId);
|
||||||
}
|
}
|
||||||
|
|
||||||
const [updated] = await this.context.drizzle
|
const [updated] = await updateReturning(
|
||||||
.update(notificationChannels)
|
this.context,
|
||||||
.set(input)
|
notificationChannels,
|
||||||
.where(
|
input,
|
||||||
and(
|
and(
|
||||||
eq(notificationChannels.id, id),
|
eq(notificationChannels.id, id),
|
||||||
eq(notificationChannels.userId, userId),
|
eq(notificationChannels.userId, userId),
|
||||||
),
|
),
|
||||||
)
|
);
|
||||||
.returning();
|
|
||||||
|
|
||||||
if (!updated) return null;
|
if (!updated) return null;
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
@@ -166,17 +169,16 @@ export class AlertRepository {
|
|||||||
id: number,
|
id: number,
|
||||||
userId: string,
|
userId: string,
|
||||||
): Promise<boolean> {
|
): Promise<boolean> {
|
||||||
const deleted = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(notificationChannels)
|
.delete(notificationChannels)
|
||||||
.where(
|
.where(
|
||||||
and(
|
and(
|
||||||
eq(notificationChannels.id, id),
|
eq(notificationChannels.id, id),
|
||||||
eq(notificationChannels.userId, userId),
|
eq(notificationChannels.userId, userId),
|
||||||
),
|
),
|
||||||
)
|
);
|
||||||
.returning({ id: notificationChannels.id });
|
|
||||||
|
|
||||||
if (deleted.length === 0) return false;
|
if (rowsAffected(result) === 0) return false;
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return true;
|
return true;
|
||||||
}
|
}
|
||||||
@@ -210,21 +212,18 @@ export class AlertRepository {
|
|||||||
channels: number[];
|
channels: number[];
|
||||||
now: string;
|
now: string;
|
||||||
}): Promise<AlertRuleWithChannelsRow> {
|
}): Promise<AlertRuleWithChannelsRow> {
|
||||||
const [created] = await this.context.drizzle
|
const [created] = await insertReturning(this.context, alertRules, {
|
||||||
.insert(alertRules)
|
userId: input.userId,
|
||||||
.values({
|
hostId: input.hostId,
|
||||||
userId: input.userId,
|
name: input.name,
|
||||||
hostId: input.hostId,
|
enabled: input.enabled,
|
||||||
name: input.name,
|
triggerType: input.triggerType,
|
||||||
enabled: input.enabled,
|
thresholdValue: input.thresholdValue,
|
||||||
triggerType: input.triggerType,
|
thresholdDurationSeconds: input.thresholdDurationSeconds,
|
||||||
thresholdValue: input.thresholdValue,
|
cooldownMinutes: input.cooldownMinutes,
|
||||||
thresholdDurationSeconds: input.thresholdDurationSeconds,
|
createdAt: input.now,
|
||||||
cooldownMinutes: input.cooldownMinutes,
|
updatedAt: input.now,
|
||||||
createdAt: input.now,
|
});
|
||||||
updatedAt: input.now,
|
|
||||||
})
|
|
||||||
.returning();
|
|
||||||
|
|
||||||
const channels = await this.replaceRuleChannels(
|
const channels = await this.replaceRuleChannels(
|
||||||
created.id,
|
created.id,
|
||||||
@@ -263,9 +262,10 @@ export class AlertRepository {
|
|||||||
now: string;
|
now: string;
|
||||||
},
|
},
|
||||||
): Promise<AlertRuleWithChannelsRow | null> {
|
): Promise<AlertRuleWithChannelsRow | null> {
|
||||||
const [updated] = await this.context.drizzle
|
const [updated] = await updateReturning(
|
||||||
.update(alertRules)
|
this.context,
|
||||||
.set({
|
alertRules,
|
||||||
|
{
|
||||||
...(input.name !== undefined ? { name: input.name } : {}),
|
...(input.name !== undefined ? { name: input.name } : {}),
|
||||||
...(input.hostId !== undefined ? { hostId: input.hostId } : {}),
|
...(input.hostId !== undefined ? { hostId: input.hostId } : {}),
|
||||||
...(input.enabled !== undefined ? { enabled: input.enabled } : {}),
|
...(input.enabled !== undefined ? { enabled: input.enabled } : {}),
|
||||||
@@ -282,9 +282,9 @@ export class AlertRepository {
|
|||||||
? { cooldownMinutes: input.cooldownMinutes }
|
? { cooldownMinutes: input.cooldownMinutes }
|
||||||
: {}),
|
: {}),
|
||||||
updatedAt: input.now,
|
updatedAt: input.now,
|
||||||
})
|
},
|
||||||
.where(and(eq(alertRules.id, id), eq(alertRules.userId, userId)))
|
and(eq(alertRules.id, id), eq(alertRules.userId, userId)),
|
||||||
.returning();
|
);
|
||||||
|
|
||||||
if (!updated) return null;
|
if (!updated) return null;
|
||||||
|
|
||||||
@@ -298,12 +298,11 @@ export class AlertRepository {
|
|||||||
}
|
}
|
||||||
|
|
||||||
async deleteAlertRule(id: number, userId: string): Promise<boolean> {
|
async deleteAlertRule(id: number, userId: string): Promise<boolean> {
|
||||||
const deleted = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(alertRules)
|
.delete(alertRules)
|
||||||
.where(and(eq(alertRules.id, id), eq(alertRules.userId, userId)))
|
.where(and(eq(alertRules.id, id), eq(alertRules.userId, userId)));
|
||||||
.returning({ id: alertRules.id });
|
|
||||||
|
|
||||||
if (deleted.length === 0) return false;
|
if (rowsAffected(result) === 0) return false;
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return true;
|
return true;
|
||||||
}
|
}
|
||||||
@@ -411,12 +410,15 @@ export class AlertRepository {
|
|||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
pruneFiringsOlderThan(userId: string, days: number): void {
|
async pruneFiringsOlderThan(userId: string, days: number): Promise<void> {
|
||||||
this.context.sqlite
|
await this.context.drizzle
|
||||||
?.prepare(
|
.delete(alertFirings)
|
||||||
"DELETE FROM alert_firings WHERE user_id = ? AND fired_at < datetime('now', ?)",
|
.where(
|
||||||
)
|
and(
|
||||||
.run(userId, `-${days} days`);
|
eq(alertFirings.userId, userId),
|
||||||
|
lt(alertFirings.firedAt, sqlTimestampDaysAgo(days)),
|
||||||
|
),
|
||||||
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteByUserId(userId: string): Promise<{
|
async deleteByUserId(userId: string): Promise<{
|
||||||
@@ -438,10 +440,9 @@ export class AlertRepository {
|
|||||||
.where(eq(notificationChannels.userId, userId))
|
.where(eq(notificationChannels.userId, userId))
|
||||||
).map((row) => row.id);
|
).map((row) => row.id);
|
||||||
|
|
||||||
const firingRows = await this.context.drizzle
|
const firingResult = await this.context.drizzle
|
||||||
.delete(alertFirings)
|
.delete(alertFirings)
|
||||||
.where(eq(alertFirings.userId, userId))
|
.where(eq(alertFirings.userId, userId));
|
||||||
.returning({ id: alertFirings.id });
|
|
||||||
|
|
||||||
const linkFilters = [
|
const linkFilters = [
|
||||||
...(ruleIds.length > 0
|
...(ruleIds.length > 0
|
||||||
@@ -451,37 +452,34 @@ export class AlertRepository {
|
|||||||
? [inArray(alertRuleChannels.channelId, channelIds)]
|
? [inArray(alertRuleChannels.channelId, channelIds)]
|
||||||
: []),
|
: []),
|
||||||
];
|
];
|
||||||
const linkRows =
|
const linkResult =
|
||||||
linkFilters.length === 0
|
linkFilters.length === 0
|
||||||
? []
|
? null
|
||||||
: await this.context.drizzle
|
: await this.context.drizzle
|
||||||
.delete(alertRuleChannels)
|
.delete(alertRuleChannels)
|
||||||
.where(or(...linkFilters))
|
.where(or(...linkFilters));
|
||||||
.returning({ id: alertRuleChannels.id });
|
|
||||||
|
|
||||||
const ruleRows = await this.context.drizzle
|
const ruleResult = await this.context.drizzle
|
||||||
.delete(alertRules)
|
.delete(alertRules)
|
||||||
.where(eq(alertRules.userId, userId))
|
.where(eq(alertRules.userId, userId));
|
||||||
.returning({ id: alertRules.id });
|
const result = await this.context.drizzle
|
||||||
const channelRows = await this.context.drizzle
|
|
||||||
.delete(notificationChannels)
|
.delete(notificationChannels)
|
||||||
.where(eq(notificationChannels.userId, userId))
|
.where(eq(notificationChannels.userId, userId));
|
||||||
.returning({ id: notificationChannels.id });
|
|
||||||
|
|
||||||
if (
|
if (
|
||||||
firingRows.length > 0 ||
|
rowsAffected(firingResult) > 0 ||
|
||||||
linkRows.length > 0 ||
|
rowsAffected(linkResult) > 0 ||
|
||||||
ruleRows.length > 0 ||
|
rowsAffected(ruleResult) > 0 ||
|
||||||
channelRows.length > 0
|
rowsAffected(result) > 0
|
||||||
) {
|
) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return {
|
return {
|
||||||
firingsDeleted: firingRows.length,
|
firingsDeleted: rowsAffected(firingResult),
|
||||||
ruleLinksDeleted: linkRows.length,
|
ruleLinksDeleted: rowsAffected(linkResult),
|
||||||
rulesDeleted: ruleRows.length,
|
rulesDeleted: rowsAffected(ruleResult),
|
||||||
channelsDeleted: channelRows.length,
|
channelsDeleted: rowsAffected(result),
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -1,6 +1,8 @@
|
|||||||
import { eq, and } from "drizzle-orm";
|
import { eq, and } from "drizzle-orm";
|
||||||
import { apiKeys, users } from "../db/schema.js";
|
import { apiKeys, users } from "../db/schema.js";
|
||||||
import type { DatabaseContext } from "./database-context.js";
|
import type { DatabaseContext } from "./database-context.js";
|
||||||
|
import { rowsAffected } from "./mutation-result.js";
|
||||||
|
import { deleteReturning, insertReturning } from "./returning.js";
|
||||||
|
|
||||||
export type ApiKeyRecord = typeof apiKeys.$inferSelect;
|
export type ApiKeyRecord = typeof apiKeys.$inferSelect;
|
||||||
export type NewApiKeyRecord = typeof apiKeys.$inferInsert;
|
export type NewApiKeyRecord = typeof apiKeys.$inferInsert;
|
||||||
@@ -24,10 +26,7 @@ export class ApiKeyRepository {
|
|||||||
) {}
|
) {}
|
||||||
|
|
||||||
async create(apiKey: NewApiKeyRecord): Promise<ApiKeyRecord> {
|
async create(apiKey: NewApiKeyRecord): Promise<ApiKeyRecord> {
|
||||||
const rows = await this.context.drizzle
|
const rows = await insertReturning(this.context, apiKeys, apiKey);
|
||||||
.insert(apiKeys)
|
|
||||||
.values(apiKey)
|
|
||||||
.returning();
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return rows[0];
|
return rows[0];
|
||||||
}
|
}
|
||||||
@@ -78,23 +77,23 @@ export class ApiKeyRepository {
|
|||||||
}
|
}
|
||||||
|
|
||||||
async delete(id: string): Promise<ApiKeyRecord | null> {
|
async delete(id: string): Promise<ApiKeyRecord | null> {
|
||||||
const rows = await this.context.drizzle
|
const rows = await deleteReturning(
|
||||||
.delete(apiKeys)
|
this.context,
|
||||||
.where(eq(apiKeys.id, id))
|
apiKeys,
|
||||||
.returning();
|
eq(apiKeys.id, id),
|
||||||
|
);
|
||||||
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return rows[0] ?? null;
|
return rows[0] ?? null;
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteByUserId(userId: string): Promise<number> {
|
async deleteByUserId(userId: string): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(apiKeys)
|
.delete(apiKeys)
|
||||||
.where(eq(apiKeys.userId, userId))
|
.where(eq(apiKeys.userId, userId));
|
||||||
.returning({ id: apiKeys.id });
|
|
||||||
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
private async afterWrite(): Promise<void> {
|
private async afterWrite(): Promise<void> {
|
||||||
|
|||||||
@@ -1,6 +1,9 @@
|
|||||||
import { and, asc, desc, eq, gte, inArray, lte, sql } from "drizzle-orm";
|
import { and, asc, desc, eq, gte, inArray, lt, lte, sql } from "drizzle-orm";
|
||||||
import { auditLogs } from "../db/schema.js";
|
import { auditLogs } from "../db/schema.js";
|
||||||
import type { DatabaseContext } from "./database-context.js";
|
import type { DatabaseContext } from "./database-context.js";
|
||||||
|
import { sqlTimestampDaysAgo } from "./sql-timestamp.js";
|
||||||
|
import { databaseLogger } from "../../utils/logger.js";
|
||||||
|
import { countValue, rowsAffected } from "./mutation-result.js";
|
||||||
|
|
||||||
export type AuditLogRecord = typeof auditLogs.$inferSelect;
|
export type AuditLogRecord = typeof auditLogs.$inferSelect;
|
||||||
export type NewAuditLogRecord = typeof auditLogs.$inferInsert;
|
export type NewAuditLogRecord = typeof auditLogs.$inferInsert;
|
||||||
@@ -19,8 +22,31 @@ export type AuditLogPage = {
|
|||||||
total: number;
|
total: number;
|
||||||
};
|
};
|
||||||
|
|
||||||
const PRUNE_MAX = 10000;
|
export const AUDIT_RETENTION_DAYS_ENV = "AUDIT_LOG_RETENTION_DAYS";
|
||||||
const PRUNE_TARGET = 9000;
|
export const AUDIT_MAX_ENTRIES_ENV = "AUDIT_LOG_MAX_ENTRIES";
|
||||||
|
|
||||||
|
const DEFAULT_MAX_ENTRIES = 10000;
|
||||||
|
const PRUNE_TARGET_RATIO = 0.9;
|
||||||
|
|
||||||
|
function positiveIntEnv(key: string, env: NodeJS.ProcessEnv): number | null {
|
||||||
|
const raw = Number(env[key]);
|
||||||
|
return Number.isFinite(raw) && raw > 0 ? Math.floor(raw) : null;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* How long entries are kept. Unset means "no time limit", in which case only
|
||||||
|
* the row cap applies.
|
||||||
|
*/
|
||||||
|
export function auditRetentionDays(
|
||||||
|
env: NodeJS.ProcessEnv = process.env,
|
||||||
|
): number | null {
|
||||||
|
return positiveIntEnv(AUDIT_RETENTION_DAYS_ENV, env);
|
||||||
|
}
|
||||||
|
|
||||||
|
/** Hard ceiling on stored entries, so a busy install cannot fill the disk. */
|
||||||
|
export function auditMaxEntries(env: NodeJS.ProcessEnv = process.env): number {
|
||||||
|
return positiveIntEnv(AUDIT_MAX_ENTRIES_ENV, env) ?? DEFAULT_MAX_ENTRIES;
|
||||||
|
}
|
||||||
|
|
||||||
export class AuditLogRepository {
|
export class AuditLogRepository {
|
||||||
constructor(
|
constructor(
|
||||||
@@ -57,10 +83,31 @@ export class AuditLogRepository {
|
|||||||
|
|
||||||
return {
|
return {
|
||||||
logs,
|
logs,
|
||||||
total: totalResult[0]?.count ?? 0,
|
total: countValue(totalResult[0]?.count),
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Reads matching entries in ascending time order for export.
|
||||||
|
*
|
||||||
|
* Paged rather than fetched whole so an export cannot pull an unbounded
|
||||||
|
* result set into memory, and ascending so a resumed or appended export
|
||||||
|
* continues where the previous one stopped.
|
||||||
|
*/
|
||||||
|
async listForExport(input: {
|
||||||
|
filters: AuditLogFilters;
|
||||||
|
limit: number;
|
||||||
|
offset: number;
|
||||||
|
}): Promise<AuditLogRecord[]> {
|
||||||
|
return this.context.drizzle
|
||||||
|
.select()
|
||||||
|
.from(auditLogs)
|
||||||
|
.where(this.buildWhere(input.filters))
|
||||||
|
.orderBy(asc(auditLogs.timestamp), asc(auditLogs.id))
|
||||||
|
.limit(input.limit)
|
||||||
|
.offset(input.offset);
|
||||||
|
}
|
||||||
|
|
||||||
async listDistinctActions(): Promise<string[]> {
|
async listDistinctActions(): Promise<string[]> {
|
||||||
const rows = await this.context.drizzle
|
const rows = await this.context.drizzle
|
||||||
.selectDistinct({ action: auditLogs.action })
|
.selectDistinct({ action: auditLogs.action })
|
||||||
@@ -70,17 +117,38 @@ export class AuditLogRepository {
|
|||||||
return rows.map((row) => row.action);
|
return rows.map((row) => row.action);
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteByUserId(userId: string): Promise<number> {
|
/**
|
||||||
const rows = await this.context.drizzle
|
* Detaches entries from a user being deleted instead of removing them.
|
||||||
.delete(auditLogs)
|
*
|
||||||
.where(eq(auditLogs.userId, userId))
|
* The schema already relaxed this foreign key to ON DELETE SET NULL, but the
|
||||||
.returning({ id: auditLogs.id });
|
* account-deletion path deletes the rows explicitly, which undoes that. An
|
||||||
|
* audit trail that vanishes with the account it recorded cannot answer the
|
||||||
|
* question it exists for, and offboarding is exactly when that question gets
|
||||||
|
* asked. `username` is denormalised, so the entry stays attributable.
|
||||||
|
*/
|
||||||
|
async anonymizeByUserId(userId: string): Promise<number> {
|
||||||
|
const result = await this.context.drizzle
|
||||||
|
.update(auditLogs)
|
||||||
|
.set({ userId: null })
|
||||||
|
.where(eq(auditLogs.userId, userId));
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
|
}
|
||||||
|
|
||||||
|
async deleteByUserId(userId: string): Promise<number> {
|
||||||
|
const result = await this.context.drizzle
|
||||||
|
.delete(auditLogs)
|
||||||
|
.where(eq(auditLogs.userId, userId));
|
||||||
|
|
||||||
|
if (rowsAffected(result) > 0) {
|
||||||
|
await this.afterWrite();
|
||||||
|
}
|
||||||
|
|
||||||
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
private buildWhere(filters: AuditLogFilters) {
|
private buildWhere(filters: AuditLogFilters) {
|
||||||
@@ -105,28 +173,73 @@ export class AuditLogRepository {
|
|||||||
}
|
}
|
||||||
|
|
||||||
private async pruneIfNeeded(): Promise<void> {
|
private async pruneIfNeeded(): Promise<void> {
|
||||||
|
await this.pruneExpired();
|
||||||
|
await this.pruneOverflow();
|
||||||
|
}
|
||||||
|
|
||||||
|
/** Drops entries past the configured retention window. */
|
||||||
|
private async pruneExpired(): Promise<void> {
|
||||||
|
const days = auditRetentionDays();
|
||||||
|
if (days === null) return;
|
||||||
|
|
||||||
|
const cutoff = sqlTimestampDaysAgo(days);
|
||||||
|
const result = await this.context.drizzle
|
||||||
|
.delete(auditLogs)
|
||||||
|
.where(lt(auditLogs.timestamp, cutoff));
|
||||||
|
|
||||||
|
if (rowsAffected(result) > 0) {
|
||||||
|
databaseLogger.info(
|
||||||
|
`Pruned ${rowsAffected(result)} audit entries past retention`,
|
||||||
|
{
|
||||||
|
operation: "audit_retention_prune",
|
||||||
|
removed: rowsAffected(result),
|
||||||
|
retentionDays: days,
|
||||||
|
cutoff,
|
||||||
|
},
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Enforces the row cap. Unlike retention this discards entries that are still
|
||||||
|
* within the window, so it is reported as a warning: it means the ceiling is
|
||||||
|
* too low for how much this install audits, and evidence is being lost.
|
||||||
|
*/
|
||||||
|
private async pruneOverflow(): Promise<void> {
|
||||||
|
const max = auditMaxEntries();
|
||||||
const countResult = await this.context.drizzle
|
const countResult = await this.context.drizzle
|
||||||
.select({ count: sql<number>`COUNT(*)` })
|
.select({ count: sql<number>`COUNT(*)` })
|
||||||
.from(auditLogs);
|
.from(auditLogs);
|
||||||
const count = countResult[0]?.count ?? 0;
|
const count = countValue(countResult[0]?.count);
|
||||||
|
|
||||||
if (count < PRUNE_MAX) {
|
if (count < max) return;
|
||||||
return;
|
|
||||||
}
|
|
||||||
|
|
||||||
const deleteCount = count - PRUNE_TARGET;
|
const deleteCount = count - Math.floor(max * PRUNE_TARGET_RATIO);
|
||||||
const rows = await this.context.drizzle
|
const rows = await this.context.drizzle
|
||||||
.select({ id: auditLogs.id })
|
.select({ id: auditLogs.id, timestamp: auditLogs.timestamp })
|
||||||
.from(auditLogs)
|
.from(auditLogs)
|
||||||
.orderBy(asc(auditLogs.timestamp))
|
.orderBy(asc(auditLogs.timestamp))
|
||||||
.limit(deleteCount);
|
.limit(deleteCount);
|
||||||
const ids = rows.map((row) => row.id);
|
if (rows.length === 0) return;
|
||||||
|
|
||||||
if (ids.length > 0) {
|
await this.context.drizzle.delete(auditLogs).where(
|
||||||
await this.context.drizzle
|
inArray(
|
||||||
.delete(auditLogs)
|
auditLogs.id,
|
||||||
.where(inArray(auditLogs.id, ids));
|
rows.map((row) => row.id),
|
||||||
}
|
),
|
||||||
|
);
|
||||||
|
|
||||||
|
databaseLogger.warn(
|
||||||
|
`Audit log hit its ${max}-entry cap; discarded ${rows.length} entries`,
|
||||||
|
{
|
||||||
|
operation: "audit_overflow_prune",
|
||||||
|
removed: rows.length,
|
||||||
|
maxEntries: max,
|
||||||
|
oldestRemoved: rows[0]?.timestamp,
|
||||||
|
newestRemoved: rows[rows.length - 1]?.timestamp,
|
||||||
|
hint: `Raise ${AUDIT_MAX_ENTRIES_ENV}, or set ${AUDIT_RETENTION_DAYS_ENV} and export older entries before they are dropped.`,
|
||||||
|
},
|
||||||
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
private async afterWrite(): Promise<void> {
|
private async afterWrite(): Promise<void> {
|
||||||
|
|||||||
@@ -1,6 +1,8 @@
|
|||||||
import { and, asc, eq, sql } from "drizzle-orm";
|
import { and, asc, eq, sql } from "drizzle-orm";
|
||||||
import { c2sTunnelPresets } from "../db/schema.js";
|
import { c2sTunnelPresets } from "../db/schema.js";
|
||||||
import type { DatabaseContext } from "./database-context.js";
|
import type { DatabaseContext } from "./database-context.js";
|
||||||
|
import { rowsAffected } from "./mutation-result.js";
|
||||||
|
import { insertReturning, updateReturning } from "./returning.js";
|
||||||
|
|
||||||
export type C2sTunnelPresetRecord = typeof c2sTunnelPresets.$inferSelect;
|
export type C2sTunnelPresetRecord = typeof c2sTunnelPresets.$inferSelect;
|
||||||
|
|
||||||
@@ -64,16 +66,13 @@ export class C2sTunnelPresetRepository {
|
|||||||
userId: string,
|
userId: string,
|
||||||
input: C2sTunnelPresetCreateInput,
|
input: C2sTunnelPresetCreateInput,
|
||||||
): Promise<C2sTunnelPresetRecord> {
|
): Promise<C2sTunnelPresetRecord> {
|
||||||
const [created] = await this.context.drizzle
|
const [created] = await insertReturning(this.context, c2sTunnelPresets, {
|
||||||
.insert(c2sTunnelPresets)
|
userId,
|
||||||
.values({
|
name: input.name,
|
||||||
userId,
|
config: input.config,
|
||||||
name: input.name,
|
platform: input.platform ?? null,
|
||||||
config: input.config,
|
computerName: input.computerName ?? null,
|
||||||
platform: input.platform ?? null,
|
});
|
||||||
computerName: input.computerName ?? null,
|
|
||||||
})
|
|
||||||
.returning();
|
|
||||||
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return created;
|
return created;
|
||||||
@@ -84,16 +83,15 @@ export class C2sTunnelPresetRepository {
|
|||||||
id: number,
|
id: number,
|
||||||
updates: C2sTunnelPresetUpdateInput,
|
updates: C2sTunnelPresetUpdateInput,
|
||||||
): Promise<C2sTunnelPresetRecord | null> {
|
): Promise<C2sTunnelPresetRecord | null> {
|
||||||
const [updated] = await this.context.drizzle
|
const [updated] = await updateReturning(
|
||||||
.update(c2sTunnelPresets)
|
this.context,
|
||||||
.set({
|
c2sTunnelPresets,
|
||||||
|
{
|
||||||
...updates,
|
...updates,
|
||||||
updatedAt: sql`CURRENT_TIMESTAMP`,
|
updatedAt: sql`CURRENT_TIMESTAMP`,
|
||||||
})
|
},
|
||||||
.where(
|
and(eq(c2sTunnelPresets.id, id), eq(c2sTunnelPresets.userId, userId)),
|
||||||
and(eq(c2sTunnelPresets.id, id), eq(c2sTunnelPresets.userId, userId)),
|
);
|
||||||
)
|
|
||||||
.returning();
|
|
||||||
|
|
||||||
if (updated) {
|
if (updated) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
@@ -103,31 +101,29 @@ export class C2sTunnelPresetRepository {
|
|||||||
}
|
}
|
||||||
|
|
||||||
async deleteForUser(userId: string, id: number): Promise<boolean> {
|
async deleteForUser(userId: string, id: number): Promise<boolean> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(c2sTunnelPresets)
|
.delete(c2sTunnelPresets)
|
||||||
.where(
|
.where(
|
||||||
and(eq(c2sTunnelPresets.id, id), eq(c2sTunnelPresets.userId, userId)),
|
and(eq(c2sTunnelPresets.id, id), eq(c2sTunnelPresets.userId, userId)),
|
||||||
)
|
);
|
||||||
.returning({ id: c2sTunnelPresets.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length > 0;
|
return rowsAffected(result) > 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteByUserId(userId: string): Promise<number> {
|
async deleteByUserId(userId: string): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(c2sTunnelPresets)
|
.delete(c2sTunnelPresets)
|
||||||
.where(eq(c2sTunnelPresets.userId, userId))
|
.where(eq(c2sTunnelPresets.userId, userId));
|
||||||
.returning({ id: c2sTunnelPresets.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
private async afterWrite(): Promise<void> {
|
private async afterWrite(): Promise<void> {
|
||||||
|
|||||||
@@ -1,6 +1,8 @@
|
|||||||
import { and, desc, eq, inArray, sql } from "drizzle-orm";
|
import { and, desc, eq, inArray, sql } from "drizzle-orm";
|
||||||
import { commandHistory } from "../db/schema.js";
|
import { commandHistory } from "../db/schema.js";
|
||||||
import type { DatabaseContext } from "./database-context.js";
|
import type { DatabaseContext } from "./database-context.js";
|
||||||
|
import { rowsAffected } from "./mutation-result.js";
|
||||||
|
import { insertReturning } from "./returning.js";
|
||||||
|
|
||||||
export type CommandHistoryRecord = typeof commandHistory.$inferSelect;
|
export type CommandHistoryRecord = typeof commandHistory.$inferSelect;
|
||||||
|
|
||||||
@@ -16,10 +18,12 @@ export class CommandHistoryRepository {
|
|||||||
command: string,
|
command: string,
|
||||||
executedAt = new Date().toISOString(),
|
executedAt = new Date().toISOString(),
|
||||||
): Promise<CommandHistoryRecord> {
|
): Promise<CommandHistoryRecord> {
|
||||||
const [created] = await this.context.drizzle
|
const [created] = await insertReturning(this.context, commandHistory, {
|
||||||
.insert(commandHistory)
|
userId,
|
||||||
.values({ userId, hostId, command, executedAt })
|
hostId,
|
||||||
.returning();
|
command,
|
||||||
|
executedAt,
|
||||||
|
});
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return created;
|
return created;
|
||||||
}
|
}
|
||||||
@@ -76,7 +80,7 @@ export class CommandHistoryRepository {
|
|||||||
hostId: number,
|
hostId: number,
|
||||||
command: string,
|
command: string,
|
||||||
): Promise<number> {
|
): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(commandHistory)
|
.delete(commandHistory)
|
||||||
.where(
|
.where(
|
||||||
and(
|
and(
|
||||||
@@ -84,45 +88,42 @@ export class CommandHistoryRepository {
|
|||||||
eq(commandHistory.hostId, hostId),
|
eq(commandHistory.hostId, hostId),
|
||||||
eq(commandHistory.command, command),
|
eq(commandHistory.command, command),
|
||||||
),
|
),
|
||||||
)
|
);
|
||||||
.returning({ id: commandHistory.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteByUserAndHost(userId: string, hostId: number): Promise<number> {
|
async deleteByUserAndHost(userId: string, hostId: number): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(commandHistory)
|
.delete(commandHistory)
|
||||||
.where(
|
.where(
|
||||||
and(
|
and(
|
||||||
eq(commandHistory.userId, userId),
|
eq(commandHistory.userId, userId),
|
||||||
eq(commandHistory.hostId, hostId),
|
eq(commandHistory.hostId, hostId),
|
||||||
),
|
),
|
||||||
)
|
);
|
||||||
.returning({ id: commandHistory.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteByHostId(hostId: number): Promise<number> {
|
async deleteByHostId(hostId: number): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(commandHistory)
|
.delete(commandHistory)
|
||||||
.where(eq(commandHistory.hostId, hostId))
|
.where(eq(commandHistory.hostId, hostId));
|
||||||
.returning({ id: commandHistory.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteByHostIds(hostIds: number[]): Promise<number> {
|
async deleteByHostIds(hostIds: number[]): Promise<number> {
|
||||||
@@ -130,29 +131,27 @@ export class CommandHistoryRepository {
|
|||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(commandHistory)
|
.delete(commandHistory)
|
||||||
.where(inArray(commandHistory.hostId, hostIds))
|
.where(inArray(commandHistory.hostId, hostIds));
|
||||||
.returning({ id: commandHistory.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteByUserId(userId: string): Promise<number> {
|
async deleteByUserId(userId: string): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(commandHistory)
|
.delete(commandHistory)
|
||||||
.where(eq(commandHistory.userId, userId))
|
.where(eq(commandHistory.userId, userId));
|
||||||
.returning({ id: commandHistory.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
private async afterWrite(): Promise<void> {
|
private async afterWrite(): Promise<void> {
|
||||||
|
|||||||
@@ -3,6 +3,12 @@ import { randomUUID } from "crypto";
|
|||||||
import { sshCredentials, sshCredentialUsage } from "../db/schema.js";
|
import { sshCredentials, sshCredentialUsage } from "../db/schema.js";
|
||||||
import type { DatabaseContext } from "./database-context.js";
|
import type { DatabaseContext } from "./database-context.js";
|
||||||
import { DataCrypto } from "../../utils/data-crypto.js";
|
import { DataCrypto } from "../../utils/data-crypto.js";
|
||||||
|
import { rowsAffected } from "./mutation-result.js";
|
||||||
|
import {
|
||||||
|
deleteReturning,
|
||||||
|
insertReturning,
|
||||||
|
updateReturning,
|
||||||
|
} from "./returning.js";
|
||||||
|
|
||||||
export type CredentialRecord = typeof sshCredentials.$inferSelect;
|
export type CredentialRecord = typeof sshCredentials.$inferSelect;
|
||||||
export type NewCredentialRecord = typeof sshCredentials.$inferInsert;
|
export type NewCredentialRecord = typeof sshCredentials.$inferInsert;
|
||||||
@@ -17,10 +23,10 @@ export class CredentialRepository {
|
|||||||
) {}
|
) {}
|
||||||
|
|
||||||
async create(credential: NewCredentialRecord): Promise<CredentialRecord> {
|
async create(credential: NewCredentialRecord): Promise<CredentialRecord> {
|
||||||
const rows = await this.context.drizzle
|
const rows = await insertReturning(this.context, sshCredentials, {
|
||||||
.insert(sshCredentials)
|
syncId: randomUUID(),
|
||||||
.values({ syncId: randomUUID(), ...credential })
|
...credential,
|
||||||
.returning();
|
});
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return rows[0];
|
return rows[0];
|
||||||
}
|
}
|
||||||
@@ -46,10 +52,11 @@ export class CredentialRepository {
|
|||||||
delete (encryptedCredential as Partial<NewCredentialRecord>).id;
|
delete (encryptedCredential as Partial<NewCredentialRecord>).id;
|
||||||
}
|
}
|
||||||
|
|
||||||
const rows = await this.context.drizzle
|
const rows = await insertReturning(
|
||||||
.insert(sshCredentials)
|
this.context,
|
||||||
.values(encryptedCredential as NewCredentialRecord)
|
sshCredentials,
|
||||||
.returning();
|
encryptedCredential as NewCredentialRecord,
|
||||||
|
);
|
||||||
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return DataCrypto.decryptRecord(
|
return DataCrypto.decryptRecord(
|
||||||
@@ -143,7 +150,7 @@ export class CredentialRepository {
|
|||||||
oldName: string,
|
oldName: string,
|
||||||
newName: string,
|
newName: string,
|
||||||
): Promise<number> {
|
): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.update(sshCredentials)
|
.update(sshCredentials)
|
||||||
.set({ folder: newName, updatedAt: sql`CURRENT_TIMESTAMP` })
|
.set({ folder: newName, updatedAt: sql`CURRENT_TIMESTAMP` })
|
||||||
.where(
|
.where(
|
||||||
@@ -151,14 +158,13 @@ export class CredentialRepository {
|
|||||||
eq(sshCredentials.userId, userId),
|
eq(sshCredentials.userId, userId),
|
||||||
eq(sshCredentials.folder, oldName),
|
eq(sshCredentials.folder, oldName),
|
||||||
),
|
),
|
||||||
)
|
);
|
||||||
.returning({ id: sshCredentials.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
async updateForUser(
|
async updateForUser(
|
||||||
@@ -166,16 +172,15 @@ export class CredentialRepository {
|
|||||||
credentialId: number,
|
credentialId: number,
|
||||||
update: CredentialUpdate,
|
update: CredentialUpdate,
|
||||||
): Promise<CredentialRecord | null> {
|
): Promise<CredentialRecord | null> {
|
||||||
const rows = await this.context.drizzle
|
const rows = await updateReturning(
|
||||||
.update(sshCredentials)
|
this.context,
|
||||||
.set({ ...update, updatedAt: sql`CURRENT_TIMESTAMP` })
|
sshCredentials,
|
||||||
.where(
|
{ ...update, updatedAt: sql`CURRENT_TIMESTAMP` },
|
||||||
and(
|
and(
|
||||||
eq(sshCredentials.id, credentialId),
|
eq(sshCredentials.id, credentialId),
|
||||||
eq(sshCredentials.userId, userId),
|
eq(sshCredentials.userId, userId),
|
||||||
),
|
),
|
||||||
)
|
);
|
||||||
.returning();
|
|
||||||
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return rows[0] ?? null;
|
return rows[0] ?? null;
|
||||||
@@ -193,16 +198,15 @@ export class CredentialRepository {
|
|||||||
userDataKey,
|
userDataKey,
|
||||||
);
|
);
|
||||||
|
|
||||||
const rows = await this.context.drizzle
|
const rows = await updateReturning(
|
||||||
.update(sshCredentials)
|
this.context,
|
||||||
.set({ ...encryptedUpdate, updatedAt: sql`CURRENT_TIMESTAMP` })
|
sshCredentials,
|
||||||
.where(
|
{ ...encryptedUpdate, updatedAt: sql`CURRENT_TIMESTAMP` },
|
||||||
and(
|
and(
|
||||||
eq(sshCredentials.id, credentialId),
|
eq(sshCredentials.id, credentialId),
|
||||||
eq(sshCredentials.userId, userId),
|
eq(sshCredentials.userId, userId),
|
||||||
),
|
),
|
||||||
)
|
);
|
||||||
.returning();
|
|
||||||
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return this.decryptOne(rows[0] ?? null, userId);
|
return this.decryptOne(rows[0] ?? null, userId);
|
||||||
@@ -212,31 +216,29 @@ export class CredentialRepository {
|
|||||||
userId: string,
|
userId: string,
|
||||||
credentialId: number,
|
credentialId: number,
|
||||||
): Promise<{ syncId: string | null } | null> {
|
): Promise<{ syncId: string | null } | null> {
|
||||||
const rows = await this.context.drizzle
|
const rows = await deleteReturning(
|
||||||
.delete(sshCredentials)
|
this.context,
|
||||||
.where(
|
sshCredentials,
|
||||||
and(
|
and(
|
||||||
eq(sshCredentials.id, credentialId),
|
eq(sshCredentials.id, credentialId),
|
||||||
eq(sshCredentials.userId, userId),
|
eq(sshCredentials.userId, userId),
|
||||||
),
|
),
|
||||||
)
|
);
|
||||||
.returning({ syncId: sshCredentials.syncId });
|
|
||||||
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return rows[0] ?? null;
|
return rows[0] ? { syncId: rows[0].syncId } : null;
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteByUserId(userId: string): Promise<number> {
|
async deleteByUserId(userId: string): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(sshCredentials)
|
.delete(sshCredentials)
|
||||||
.where(eq(sshCredentials.userId, userId))
|
.where(eq(sshCredentials.userId, userId));
|
||||||
.returning({ id: sshCredentials.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
async recordUsage(
|
async recordUsage(
|
||||||
|
|||||||
@@ -2,6 +2,12 @@ import { and, asc, eq } from "drizzle-orm";
|
|||||||
import { randomUUID } from "crypto";
|
import { randomUUID } from "crypto";
|
||||||
import { dashboardServiceLinks } from "../db/schema.js";
|
import { dashboardServiceLinks } from "../db/schema.js";
|
||||||
import type { DatabaseContext } from "./database-context.js";
|
import type { DatabaseContext } from "./database-context.js";
|
||||||
|
import { rowsAffected } from "./mutation-result.js";
|
||||||
|
import {
|
||||||
|
deleteReturning,
|
||||||
|
insertReturning,
|
||||||
|
updateReturning,
|
||||||
|
} from "./returning.js";
|
||||||
|
|
||||||
export type DashboardServiceLinkRecord =
|
export type DashboardServiceLinkRecord =
|
||||||
typeof dashboardServiceLinks.$inferSelect;
|
typeof dashboardServiceLinks.$inferSelect;
|
||||||
@@ -38,9 +44,10 @@ export class DashboardServiceLinkRepository {
|
|||||||
const nextOrder =
|
const nextOrder =
|
||||||
existing.length > 0 ? existing[existing.length - 1].order + 1 : 0;
|
existing.length > 0 ? existing[existing.length - 1].order + 1 : 0;
|
||||||
|
|
||||||
const [created] = await this.context.drizzle
|
const [created] = await insertReturning(
|
||||||
.insert(dashboardServiceLinks)
|
this.context,
|
||||||
.values({
|
dashboardServiceLinks,
|
||||||
|
{
|
||||||
syncId: randomUUID(),
|
syncId: randomUUID(),
|
||||||
userId,
|
userId,
|
||||||
label: input.label,
|
label: input.label,
|
||||||
@@ -48,8 +55,8 @@ export class DashboardServiceLinkRepository {
|
|||||||
order: nextOrder,
|
order: nextOrder,
|
||||||
createdAt,
|
createdAt,
|
||||||
updatedAt: createdAt,
|
updatedAt: createdAt,
|
||||||
})
|
},
|
||||||
.returning();
|
);
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return created;
|
return created;
|
||||||
}
|
}
|
||||||
@@ -77,16 +84,15 @@ export class DashboardServiceLinkRepository {
|
|||||||
id: number,
|
id: number,
|
||||||
updates: DashboardServiceLinkUpdate,
|
updates: DashboardServiceLinkUpdate,
|
||||||
): Promise<DashboardServiceLinkRecord | null> {
|
): Promise<DashboardServiceLinkRecord | null> {
|
||||||
const [updated] = await this.context.drizzle
|
const [updated] = await updateReturning(
|
||||||
.update(dashboardServiceLinks)
|
this.context,
|
||||||
.set({ ...updates, updatedAt: new Date().toISOString() })
|
dashboardServiceLinks,
|
||||||
.where(
|
{ ...updates, updatedAt: new Date().toISOString() },
|
||||||
and(
|
and(
|
||||||
eq(dashboardServiceLinks.id, id),
|
eq(dashboardServiceLinks.id, id),
|
||||||
eq(dashboardServiceLinks.userId, userId),
|
eq(dashboardServiceLinks.userId, userId),
|
||||||
),
|
),
|
||||||
)
|
);
|
||||||
.returning();
|
|
||||||
|
|
||||||
if (updated) {
|
if (updated) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
@@ -99,32 +105,30 @@ export class DashboardServiceLinkRepository {
|
|||||||
userId: string,
|
userId: string,
|
||||||
id: number,
|
id: number,
|
||||||
): Promise<{ syncId: string | null } | null> {
|
): Promise<{ syncId: string | null } | null> {
|
||||||
const rows = await this.context.drizzle
|
const rows = await deleteReturning(
|
||||||
.delete(dashboardServiceLinks)
|
this.context,
|
||||||
.where(
|
dashboardServiceLinks,
|
||||||
and(
|
and(
|
||||||
eq(dashboardServiceLinks.id, id),
|
eq(dashboardServiceLinks.id, id),
|
||||||
eq(dashboardServiceLinks.userId, userId),
|
eq(dashboardServiceLinks.userId, userId),
|
||||||
),
|
),
|
||||||
)
|
);
|
||||||
.returning({ syncId: dashboardServiceLinks.syncId });
|
|
||||||
|
|
||||||
if (rows.length === 0) return null;
|
if (rows.length === 0) return null;
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return rows[0];
|
return { syncId: rows[0].syncId };
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteByUserId(userId: string): Promise<number> {
|
async deleteByUserId(userId: string): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(dashboardServiceLinks)
|
.delete(dashboardServiceLinks)
|
||||||
.where(eq(dashboardServiceLinks.userId, userId))
|
.where(eq(dashboardServiceLinks.userId, userId));
|
||||||
.returning({ id: dashboardServiceLinks.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
private async afterWrite(): Promise<void> {
|
private async afterWrite(): Promise<void> {
|
||||||
|
|||||||
@@ -1,9 +1,41 @@
|
|||||||
import type { BetterSQLite3Database } from "drizzle-orm/better-sqlite3";
|
import type { BetterSQLite3Database } from "drizzle-orm/better-sqlite3";
|
||||||
import type { Database as BetterSqliteDatabase } from "better-sqlite3";
|
|
||||||
import type * as schema from "../db/schema.js";
|
import type * as schema from "../db/schema.js";
|
||||||
|
|
||||||
|
// Re-exported so repositories can keep importing it from here, but defined in
|
||||||
|
// db/dialect.ts — a local copy that said "sqlite" survived here for a while and
|
||||||
|
// typed every context as SQLite-only while the runtime already carried all
|
||||||
|
// three, which silently made the dialect branches unreachable to the checker.
|
||||||
|
export type { DatabaseDialect } from "../db/dialect.js";
|
||||||
|
import type { DatabaseDialect } from "../db/dialect.js";
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The database handle repositories work against.
|
||||||
|
*
|
||||||
|
* Typed as the SQLite instance on purpose. drizzle's three Database classes
|
||||||
|
* share no base class and their signatures are incompatible: a union is not
|
||||||
|
* callable, and a generic would have to be threaded through all 43
|
||||||
|
* repositories and every method on them.
|
||||||
|
*
|
||||||
|
* This is a deliberate approximation, not an accident. The query-builder
|
||||||
|
* surface the repositories actually use is the same on all three engines, and
|
||||||
|
* that equivalence is asserted in multi-dialect.test.ts rather than assumed —
|
||||||
|
* identifier quoting, placeholder style and value coercion are all covered
|
||||||
|
* there. At runtime this may hold a Postgres or MySQL instance.
|
||||||
|
*
|
||||||
|
* The one place the surfaces genuinely differ is RETURNING, which MySQL lacks;
|
||||||
|
* see mutation-result.ts for how that is absorbed.
|
||||||
|
*/
|
||||||
|
export type PortableDatabase = BetterSQLite3Database<typeof schema>;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* What a repository is allowed to touch.
|
||||||
|
*
|
||||||
|
* Deliberately drizzle-only: with no raw driver handle here, no repository can
|
||||||
|
* reach for engine-specific SQL. Retention queries that previously needed
|
||||||
|
* `datetime('now', ?)` compute their cutoff in JS instead — see
|
||||||
|
* ./sql-timestamp.ts.
|
||||||
|
*/
|
||||||
export interface DatabaseContext {
|
export interface DatabaseContext {
|
||||||
dialect: "sqlite";
|
dialect: DatabaseDialect;
|
||||||
drizzle: BetterSQLite3Database<typeof schema>;
|
drizzle: PortableDatabase;
|
||||||
sqlite?: BetterSqliteDatabase;
|
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,6 +1,7 @@
|
|||||||
import { and, eq } from "drizzle-orm";
|
import { and, eq } from "drizzle-orm";
|
||||||
import { dismissedAlerts } from "../db/schema.js";
|
import { dismissedAlerts } from "../db/schema.js";
|
||||||
import type { DatabaseContext } from "./database-context.js";
|
import type { DatabaseContext } from "./database-context.js";
|
||||||
|
import { rowsAffected } from "./mutation-result.js";
|
||||||
|
|
||||||
export type DismissedAlertRecord = typeof dismissedAlerts.$inferSelect;
|
export type DismissedAlertRecord = typeof dismissedAlerts.$inferSelect;
|
||||||
|
|
||||||
@@ -72,34 +73,32 @@ export class DismissedAlertRepository {
|
|||||||
}
|
}
|
||||||
|
|
||||||
async deleteForUser(userId: string, alertId: string): Promise<boolean> {
|
async deleteForUser(userId: string, alertId: string): Promise<boolean> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(dismissedAlerts)
|
.delete(dismissedAlerts)
|
||||||
.where(
|
.where(
|
||||||
and(
|
and(
|
||||||
eq(dismissedAlerts.userId, userId),
|
eq(dismissedAlerts.userId, userId),
|
||||||
eq(dismissedAlerts.alertId, alertId),
|
eq(dismissedAlerts.alertId, alertId),
|
||||||
),
|
),
|
||||||
)
|
);
|
||||||
.returning({ id: dismissedAlerts.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length > 0;
|
return rowsAffected(result) > 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteByUserId(userId: string): Promise<number> {
|
async deleteByUserId(userId: string): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(dismissedAlerts)
|
.delete(dismissedAlerts)
|
||||||
.where(eq(dismissedAlerts.userId, userId))
|
.where(eq(dismissedAlerts.userId, userId));
|
||||||
.returning({ id: dismissedAlerts.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
private async afterWrite(): Promise<void> {
|
private async afterWrite(): Promise<void> {
|
||||||
|
|||||||
@@ -1,5 +1,7 @@
|
|||||||
import { DatabaseSaveTrigger } from "../../utils/database-save-trigger.js";
|
import { DatabaseSaveTrigger } from "../../utils/database-save-trigger.js";
|
||||||
import { getDb, getSqlite } from "../db/index.js";
|
import { getDb, getSqlite } from "../db/index.js";
|
||||||
|
import { needsExplicitPersist, resolveDatabaseDialect } from "../db/dialect.js";
|
||||||
|
import { primeSettingsCache, readCachedSetting } from "./settings-cache.js";
|
||||||
import type { DatabaseContext } from "./database-context.js";
|
import type { DatabaseContext } from "./database-context.js";
|
||||||
import { WebauthnCredentialRepository } from "./webauthn-credential-repository.js";
|
import { WebauthnCredentialRepository } from "./webauthn-credential-repository.js";
|
||||||
import { AlertRepository } from "./alert-repository.js";
|
import { AlertRepository } from "./alert-repository.js";
|
||||||
@@ -29,6 +31,7 @@ import { SessionRecordingRepository } from "./session-recording-repository.js";
|
|||||||
import { SessionRepository } from "./session-repository.js";
|
import { SessionRepository } from "./session-repository.js";
|
||||||
import { SessionShareRepository } from "./session-share-repository.js";
|
import { SessionShareRepository } from "./session-share-repository.js";
|
||||||
import { SettingsRepository } from "./settings-repository.js";
|
import { SettingsRepository } from "./settings-repository.js";
|
||||||
|
import { SharedHostAuthOverrideRepository } from "./shared-host-auth-override-repository.js";
|
||||||
import { SharedHostSecretsRepository } from "./shared-host-secrets-repository.js";
|
import { SharedHostSecretsRepository } from "./shared-host-secrets-repository.js";
|
||||||
import { SnippetRepository } from "./snippet-repository.js";
|
import { SnippetRepository } from "./snippet-repository.js";
|
||||||
import { SshCredentialUsageRepository } from "./ssh-credential-usage-repository.js";
|
import { SshCredentialUsageRepository } from "./ssh-credential-usage-repository.js";
|
||||||
@@ -45,25 +48,62 @@ import { UserRepository } from "./user-repository.js";
|
|||||||
import { VaultProfileRepository } from "./vault-profile-repository.js";
|
import { VaultProfileRepository } from "./vault-profile-repository.js";
|
||||||
import { VaultTokenRepository } from "./vault-token-repository.js";
|
import { VaultTokenRepository } from "./vault-token-repository.js";
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The context every repository runs against.
|
||||||
|
*
|
||||||
|
* The dialect has to be resolved, not assumed: it is what `returning.ts` reads
|
||||||
|
* to decide whether it can ask for RETURNING, and whether an upsert spells
|
||||||
|
* itself `onConflictDoUpdate` or `onDuplicateKeyUpdate`. Reporting "sqlite"
|
||||||
|
* while connected to MySQL makes the second of those a TypeError on the first
|
||||||
|
* write.
|
||||||
|
*
|
||||||
|
* Both cross-dialect harnesses build a DatabaseContext themselves, so neither
|
||||||
|
* exercises this function — see tests/database/repositories/factory-context.
|
||||||
|
*/
|
||||||
export function createCurrentRepositoryContext(): DatabaseContext {
|
export function createCurrentRepositoryContext(): DatabaseContext {
|
||||||
return {
|
return {
|
||||||
dialect: "sqlite",
|
dialect: resolveDatabaseDialect(),
|
||||||
drizzle: getDb(),
|
drizzle: getDb(),
|
||||||
sqlite: getSqlite(),
|
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Post-write hook handed to every repository.
|
||||||
|
*
|
||||||
|
* Only meaningful for SQLite, where the database lives in memory and has to be
|
||||||
|
* serialised back to its encrypted file. On Postgres and MySQL the write is
|
||||||
|
* already durable, so no hook is installed at all rather than one that does
|
||||||
|
* nothing — repositories call it as `this.onWrite?.()`.
|
||||||
|
*/
|
||||||
export function createCurrentRepositoryWriteHook(
|
export function createCurrentRepositoryWriteHook(
|
||||||
reason: string,
|
reason: string,
|
||||||
): () => Promise<void> {
|
): (() => Promise<void>) | undefined {
|
||||||
|
if (!needsExplicitPersist(resolveDatabaseDialect())) return undefined;
|
||||||
return () => DatabaseSaveTrigger.forceSave(reason);
|
return () => DatabaseSaveTrigger.forceSave(reason);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Raw driver handle for the few synchronous call sites that cannot await —
|
||||||
|
* getCurrentSettingValue below, and settings reads during startup. Repositories
|
||||||
|
* must not use this: they take a DatabaseContext, which is drizzle-only.
|
||||||
|
* Porting to another engine means giving these callers an async path first.
|
||||||
|
*/
|
||||||
export function getCurrentRepositorySqlite() {
|
export function getCurrentRepositorySqlite() {
|
||||||
return getSqlite();
|
return getSqlite();
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Synchronous settings read.
|
||||||
|
*
|
||||||
|
* SQLite can be queried synchronously, so it is read directly and stays
|
||||||
|
* authoritative. Other engines have no synchronous query, so the value comes
|
||||||
|
* from the cache primed at startup and kept current by SettingsRepository.
|
||||||
|
*/
|
||||||
export function getCurrentSettingValue(key: string): string | null {
|
export function getCurrentSettingValue(key: string): string | null {
|
||||||
|
if (!needsExplicitPersist(resolveDatabaseDialect())) {
|
||||||
|
return readCachedSetting(key);
|
||||||
|
}
|
||||||
|
|
||||||
const row = getCurrentRepositorySqlite()
|
const row = getCurrentRepositorySqlite()
|
||||||
.prepare("SELECT value FROM settings WHERE key = ?")
|
.prepare("SELECT value FROM settings WHERE key = ?")
|
||||||
.get(key) as { value?: string } | undefined;
|
.get(key) as { value?: string } | undefined;
|
||||||
@@ -283,6 +323,15 @@ export function createCurrentSharedHostSecretsRepository(): SharedHostSecretsRep
|
|||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
export function createCurrentSharedHostAuthOverrideRepository(): SharedHostAuthOverrideRepository {
|
||||||
|
return new SharedHostAuthOverrideRepository(
|
||||||
|
createCurrentRepositoryContext(),
|
||||||
|
createCurrentRepositoryWriteHook(
|
||||||
|
"shared_host_auth_override_repository_write",
|
||||||
|
),
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
export function createCurrentSnippetRepository(): SnippetRepository {
|
export function createCurrentSnippetRepository(): SnippetRepository {
|
||||||
return new SnippetRepository(
|
return new SnippetRepository(
|
||||||
createCurrentRepositoryContext(),
|
createCurrentRepositoryContext(),
|
||||||
@@ -370,3 +419,69 @@ export function createCurrentVaultTokenRepository(): VaultTokenRepository {
|
|||||||
createCurrentRepositoryWriteHook("vault_token_repository_write"),
|
createCurrentRepositoryWriteHook("vault_token_repository_write"),
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Loads the settings cache. Must run during startup on engines without a
|
||||||
|
* synchronous read, before anything calls getCurrentSettingValue.
|
||||||
|
*/
|
||||||
|
export async function primeCurrentSettingsCache(): Promise<void> {
|
||||||
|
const rows = await createCurrentSettingsRepository().listAll();
|
||||||
|
primeSettingsCache(rows);
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* How often a replica re-reads the settings table.
|
||||||
|
*
|
||||||
|
* Override with SETTINGS_CACHE_REFRESH_SECONDS; 0 disables the refresh.
|
||||||
|
*/
|
||||||
|
const REFRESH_SECONDS_ENV = "SETTINGS_CACHE_REFRESH_SECONDS";
|
||||||
|
const DEFAULT_REFRESH_SECONDS = 30;
|
||||||
|
|
||||||
|
let refreshTimer: NodeJS.Timeout | null = null;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Keeps the settings cache from drifting on a multi-replica deployment.
|
||||||
|
*
|
||||||
|
* The cache is per-process and updated in the process that writes. That is
|
||||||
|
* enough for SQLite, where there is only ever one process. On Postgres and
|
||||||
|
* MySQL — which exist here precisely so more than one instance can share the
|
||||||
|
* data — a setting changed on one replica would otherwise never reach the
|
||||||
|
* others, because the synchronous read has no way to go back to the database.
|
||||||
|
*
|
||||||
|
* Periodic re-priming does not make the value immediately consistent. It bounds
|
||||||
|
* how long it can be wrong, which is the difference between a setting that
|
||||||
|
* takes effect on the next tick and one that takes effect at the next restart.
|
||||||
|
*/
|
||||||
|
export function startSettingsCacheRefresh(
|
||||||
|
env = process.env,
|
||||||
|
refresh: () => Promise<void> = primeCurrentSettingsCache,
|
||||||
|
): void {
|
||||||
|
if (refreshTimer) return;
|
||||||
|
|
||||||
|
const seconds = refreshIntervalSeconds(env);
|
||||||
|
if (seconds === null) return;
|
||||||
|
|
||||||
|
refreshTimer = setInterval(() => {
|
||||||
|
void refresh().catch(() => {
|
||||||
|
// A failed refresh leaves the previous values in place, which is the
|
||||||
|
// right outcome: a transient database blip should not blank the cache.
|
||||||
|
// Every caller reads a missing setting as "use the default", so an empty
|
||||||
|
// cache would silently revert configuration across the deployment.
|
||||||
|
});
|
||||||
|
}, seconds * 1000);
|
||||||
|
|
||||||
|
refreshTimer.unref();
|
||||||
|
}
|
||||||
|
|
||||||
|
/** The configured interval, or null when refreshing is switched off. */
|
||||||
|
export function refreshIntervalSeconds(env = process.env): number | null {
|
||||||
|
const seconds = Number(env[REFRESH_SECONDS_ENV] ?? DEFAULT_REFRESH_SECONDS);
|
||||||
|
return Number.isFinite(seconds) && seconds > 0 ? seconds : null;
|
||||||
|
}
|
||||||
|
|
||||||
|
/** Test seam. */
|
||||||
|
export function stopSettingsCacheRefresh(): void {
|
||||||
|
if (!refreshTimer) return;
|
||||||
|
clearInterval(refreshTimer);
|
||||||
|
refreshTimer = null;
|
||||||
|
}
|
||||||
|
|||||||
@@ -1,158 +0,0 @@
|
|||||||
import { FieldCrypto } from "../../utils/field-crypto.js";
|
|
||||||
import { LazyFieldEncryption } from "../../utils/lazy-field-encryption.js";
|
|
||||||
|
|
||||||
const FIELD_ENCRYPTION_POLICY = {
|
|
||||||
users: {
|
|
||||||
sensitive: new Set([
|
|
||||||
"passwordHash",
|
|
||||||
"clientSecret",
|
|
||||||
"totpSecret",
|
|
||||||
"totpBackupCodes",
|
|
||||||
"oidcIdentifier",
|
|
||||||
]),
|
|
||||||
plaintext: new Set(["id", "username", "isAdmin", "isOidc"]),
|
|
||||||
},
|
|
||||||
ssh_data: {
|
|
||||||
sensitive: new Set([
|
|
||||||
"password",
|
|
||||||
"key",
|
|
||||||
"keyPassword",
|
|
||||||
"sudoPassword",
|
|
||||||
"autostartPassword",
|
|
||||||
"autostartKey",
|
|
||||||
"autostartKeyPassword",
|
|
||||||
"socks5Password",
|
|
||||||
"rdpPassword",
|
|
||||||
"vncPassword",
|
|
||||||
"telnetPassword",
|
|
||||||
]),
|
|
||||||
plaintext: new Set([
|
|
||||||
"id",
|
|
||||||
"userId",
|
|
||||||
"connectionType",
|
|
||||||
"name",
|
|
||||||
"ip",
|
|
||||||
"port",
|
|
||||||
"username",
|
|
||||||
"folder",
|
|
||||||
"tags",
|
|
||||||
"authType",
|
|
||||||
"credentialId",
|
|
||||||
]),
|
|
||||||
},
|
|
||||||
ssh_credentials: {
|
|
||||||
sensitive: new Set([
|
|
||||||
"password",
|
|
||||||
"key",
|
|
||||||
"privateKey",
|
|
||||||
"publicKey",
|
|
||||||
"keyPassword",
|
|
||||||
]),
|
|
||||||
plaintext: new Set([
|
|
||||||
"id",
|
|
||||||
"userId",
|
|
||||||
"name",
|
|
||||||
"description",
|
|
||||||
"folder",
|
|
||||||
"tags",
|
|
||||||
"authType",
|
|
||||||
"username",
|
|
||||||
"keyType",
|
|
||||||
"detectedKeyType",
|
|
||||||
"usageCount",
|
|
||||||
"lastUsed",
|
|
||||||
]),
|
|
||||||
},
|
|
||||||
opkssh_tokens: {
|
|
||||||
sensitive: new Set(["sshCert", "privateKey"]),
|
|
||||||
plaintext: new Set(["id", "userId", "hostId", "createdAt", "expiresAt"]),
|
|
||||||
},
|
|
||||||
termix_identity_ca: {
|
|
||||||
sensitive: new Set(["privateKey"]),
|
|
||||||
plaintext: new Set(["id", "publicKey", "createdAt", "updatedAt"]),
|
|
||||||
},
|
|
||||||
vault_tokens: {
|
|
||||||
sensitive: new Set(["sshCert", "privateKey"]),
|
|
||||||
plaintext: new Set(["id", "userId", "profileId", "expiresAt"]),
|
|
||||||
},
|
|
||||||
} as const;
|
|
||||||
|
|
||||||
type PolicyTable = keyof typeof FIELD_ENCRYPTION_POLICY;
|
|
||||||
export type FieldClassification = "sensitive" | "plaintext" | "unknown";
|
|
||||||
|
|
||||||
export class FieldEncryptionBoundary {
|
|
||||||
static classifyField(
|
|
||||||
tableName: string,
|
|
||||||
fieldName: string,
|
|
||||||
): FieldClassification {
|
|
||||||
const policy = this.getPolicy(tableName);
|
|
||||||
if (!policy) return "unknown";
|
|
||||||
if (policy.sensitive.has(fieldName)) return "sensitive";
|
|
||||||
if (policy.plaintext.has(fieldName)) return "plaintext";
|
|
||||||
return "unknown";
|
|
||||||
}
|
|
||||||
|
|
||||||
static getSensitiveFields(tableName: string): string[] {
|
|
||||||
const policy = this.getPolicy(tableName);
|
|
||||||
return policy ? [...policy.sensitive].sort() : [];
|
|
||||||
}
|
|
||||||
|
|
||||||
static encryptRecord<T extends Record<string, unknown>>(
|
|
||||||
tableName: string,
|
|
||||||
record: T,
|
|
||||||
userDataKey: Buffer,
|
|
||||||
recordId = record.id,
|
|
||||||
): T {
|
|
||||||
const id = this.requireRecordId(recordId);
|
|
||||||
const encryptedRecord: Record<string, unknown> = { ...record };
|
|
||||||
|
|
||||||
for (const fieldName of this.getSensitiveFields(tableName)) {
|
|
||||||
const value = encryptedRecord[fieldName];
|
|
||||||
if (typeof value === "string" && value) {
|
|
||||||
encryptedRecord[fieldName] = FieldCrypto.encryptField(
|
|
||||||
value,
|
|
||||||
userDataKey,
|
|
||||||
id,
|
|
||||||
fieldName,
|
|
||||||
);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
return encryptedRecord as T;
|
|
||||||
}
|
|
||||||
|
|
||||||
static decryptRecord<T extends Record<string, unknown>>(
|
|
||||||
tableName: string,
|
|
||||||
record: T,
|
|
||||||
userDataKey: Buffer,
|
|
||||||
recordId = record.id,
|
|
||||||
): T {
|
|
||||||
const id = this.requireRecordId(recordId);
|
|
||||||
const decryptedRecord: Record<string, unknown> = { ...record };
|
|
||||||
|
|
||||||
for (const fieldName of this.getSensitiveFields(tableName)) {
|
|
||||||
const value = decryptedRecord[fieldName];
|
|
||||||
if (typeof value === "string" && value) {
|
|
||||||
decryptedRecord[fieldName] = LazyFieldEncryption.safeGetFieldValue(
|
|
||||||
value,
|
|
||||||
userDataKey,
|
|
||||||
id,
|
|
||||||
fieldName,
|
|
||||||
);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
return decryptedRecord as T;
|
|
||||||
}
|
|
||||||
|
|
||||||
private static getPolicy(tableName: string) {
|
|
||||||
return FIELD_ENCRYPTION_POLICY[tableName as PolicyTable];
|
|
||||||
}
|
|
||||||
|
|
||||||
private static requireRecordId(recordId: unknown): string {
|
|
||||||
if (recordId === null || recordId === undefined || recordId === "") {
|
|
||||||
throw new Error("Field encryption requires a stable record id.");
|
|
||||||
}
|
|
||||||
return String(recordId);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -5,6 +5,7 @@ import {
|
|||||||
fileManagerShortcuts,
|
fileManagerShortcuts,
|
||||||
} from "../db/schema.js";
|
} from "../db/schema.js";
|
||||||
import type { DatabaseContext } from "./database-context.js";
|
import type { DatabaseContext } from "./database-context.js";
|
||||||
|
import { rowsAffected } from "./mutation-result.js";
|
||||||
|
|
||||||
export type FileManagerRecentRecord = typeof fileManagerRecent.$inferSelect;
|
export type FileManagerRecentRecord = typeof fileManagerRecent.$inferSelect;
|
||||||
export type FileManagerPinnedRecord = typeof fileManagerPinned.$inferSelect;
|
export type FileManagerPinnedRecord = typeof fileManagerPinned.$inferSelect;
|
||||||
@@ -112,7 +113,7 @@ export class FileManagerBookmarkRepository {
|
|||||||
userId: string,
|
userId: string,
|
||||||
input: Pick<FileManagerBookmarkInput, "hostId" | "path">,
|
input: Pick<FileManagerBookmarkInput, "hostId" | "path">,
|
||||||
): Promise<number> {
|
): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(fileManagerRecent)
|
.delete(fileManagerRecent)
|
||||||
.where(
|
.where(
|
||||||
and(
|
and(
|
||||||
@@ -120,14 +121,13 @@ export class FileManagerBookmarkRepository {
|
|||||||
eq(fileManagerRecent.hostId, input.hostId),
|
eq(fileManagerRecent.hostId, input.hostId),
|
||||||
eq(fileManagerRecent.path, input.path),
|
eq(fileManagerRecent.path, input.path),
|
||||||
),
|
),
|
||||||
)
|
);
|
||||||
.returning({ id: fileManagerRecent.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
async listPinnedForHost(
|
async listPinnedForHost(
|
||||||
@@ -199,7 +199,7 @@ export class FileManagerBookmarkRepository {
|
|||||||
userId: string,
|
userId: string,
|
||||||
input: Pick<FileManagerBookmarkInput, "hostId" | "path">,
|
input: Pick<FileManagerBookmarkInput, "hostId" | "path">,
|
||||||
): Promise<number> {
|
): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(fileManagerPinned)
|
.delete(fileManagerPinned)
|
||||||
.where(
|
.where(
|
||||||
and(
|
and(
|
||||||
@@ -207,14 +207,13 @@ export class FileManagerBookmarkRepository {
|
|||||||
eq(fileManagerPinned.hostId, input.hostId),
|
eq(fileManagerPinned.hostId, input.hostId),
|
||||||
eq(fileManagerPinned.path, input.path),
|
eq(fileManagerPinned.path, input.path),
|
||||||
),
|
),
|
||||||
)
|
);
|
||||||
.returning({ id: fileManagerPinned.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
async listShortcutsForHost(
|
async listShortcutsForHost(
|
||||||
@@ -288,7 +287,7 @@ export class FileManagerBookmarkRepository {
|
|||||||
userId: string,
|
userId: string,
|
||||||
input: Pick<FileManagerBookmarkInput, "hostId" | "path">,
|
input: Pick<FileManagerBookmarkInput, "hostId" | "path">,
|
||||||
): Promise<number> {
|
): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(fileManagerShortcuts)
|
.delete(fileManagerShortcuts)
|
||||||
.where(
|
.where(
|
||||||
and(
|
and(
|
||||||
@@ -296,14 +295,13 @@ export class FileManagerBookmarkRepository {
|
|||||||
eq(fileManagerShortcuts.hostId, input.hostId),
|
eq(fileManagerShortcuts.hostId, input.hostId),
|
||||||
eq(fileManagerShortcuts.path, input.path),
|
eq(fileManagerShortcuts.path, input.path),
|
||||||
),
|
),
|
||||||
)
|
);
|
||||||
.returning({ id: fileManagerShortcuts.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteByUserId(userId: string): Promise<number> {
|
async deleteByUserId(userId: string): Promise<number> {
|
||||||
@@ -456,75 +454,66 @@ export class FileManagerBookmarkRepository {
|
|||||||
}
|
}
|
||||||
|
|
||||||
private async deleteRecentByUserId(userId: string): Promise<number> {
|
private async deleteRecentByUserId(userId: string): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(fileManagerRecent)
|
.delete(fileManagerRecent)
|
||||||
.where(eq(fileManagerRecent.userId, userId))
|
.where(eq(fileManagerRecent.userId, userId));
|
||||||
.returning({ id: fileManagerRecent.id });
|
return rowsAffected(result);
|
||||||
return rows.length;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
private async deletePinnedByUserId(userId: string): Promise<number> {
|
private async deletePinnedByUserId(userId: string): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(fileManagerPinned)
|
.delete(fileManagerPinned)
|
||||||
.where(eq(fileManagerPinned.userId, userId))
|
.where(eq(fileManagerPinned.userId, userId));
|
||||||
.returning({ id: fileManagerPinned.id });
|
return rowsAffected(result);
|
||||||
return rows.length;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
private async deleteShortcutsByUserId(userId: string): Promise<number> {
|
private async deleteShortcutsByUserId(userId: string): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(fileManagerShortcuts)
|
.delete(fileManagerShortcuts)
|
||||||
.where(eq(fileManagerShortcuts.userId, userId))
|
.where(eq(fileManagerShortcuts.userId, userId));
|
||||||
.returning({ id: fileManagerShortcuts.id });
|
return rowsAffected(result);
|
||||||
return rows.length;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
private async deleteRecentByHostId(hostId: number): Promise<number> {
|
private async deleteRecentByHostId(hostId: number): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(fileManagerRecent)
|
.delete(fileManagerRecent)
|
||||||
.where(eq(fileManagerRecent.hostId, hostId))
|
.where(eq(fileManagerRecent.hostId, hostId));
|
||||||
.returning({ id: fileManagerRecent.id });
|
return rowsAffected(result);
|
||||||
return rows.length;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
private async deletePinnedByHostId(hostId: number): Promise<number> {
|
private async deletePinnedByHostId(hostId: number): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(fileManagerPinned)
|
.delete(fileManagerPinned)
|
||||||
.where(eq(fileManagerPinned.hostId, hostId))
|
.where(eq(fileManagerPinned.hostId, hostId));
|
||||||
.returning({ id: fileManagerPinned.id });
|
return rowsAffected(result);
|
||||||
return rows.length;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
private async deleteShortcutsByHostId(hostId: number): Promise<number> {
|
private async deleteShortcutsByHostId(hostId: number): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(fileManagerShortcuts)
|
.delete(fileManagerShortcuts)
|
||||||
.where(eq(fileManagerShortcuts.hostId, hostId))
|
.where(eq(fileManagerShortcuts.hostId, hostId));
|
||||||
.returning({ id: fileManagerShortcuts.id });
|
return rowsAffected(result);
|
||||||
return rows.length;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
private async deleteRecentByHostIds(hostIds: number[]): Promise<number> {
|
private async deleteRecentByHostIds(hostIds: number[]): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(fileManagerRecent)
|
.delete(fileManagerRecent)
|
||||||
.where(inArray(fileManagerRecent.hostId, hostIds))
|
.where(inArray(fileManagerRecent.hostId, hostIds));
|
||||||
.returning({ id: fileManagerRecent.id });
|
return rowsAffected(result);
|
||||||
return rows.length;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
private async deletePinnedByHostIds(hostIds: number[]): Promise<number> {
|
private async deletePinnedByHostIds(hostIds: number[]): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(fileManagerPinned)
|
.delete(fileManagerPinned)
|
||||||
.where(inArray(fileManagerPinned.hostId, hostIds))
|
.where(inArray(fileManagerPinned.hostId, hostIds));
|
||||||
.returning({ id: fileManagerPinned.id });
|
return rowsAffected(result);
|
||||||
return rows.length;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
private async deleteShortcutsByHostIds(hostIds: number[]): Promise<number> {
|
private async deleteShortcutsByHostIds(hostIds: number[]): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(fileManagerShortcuts)
|
.delete(fileManagerShortcuts)
|
||||||
.where(inArray(fileManagerShortcuts.hostId, hostIds))
|
.where(inArray(fileManagerShortcuts.hostId, hostIds));
|
||||||
.returning({ id: fileManagerShortcuts.id });
|
return rowsAffected(result);
|
||||||
return rows.length;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
private async afterWrite(): Promise<void> {
|
private async afterWrite(): Promise<void> {
|
||||||
|
|||||||
@@ -2,6 +2,12 @@ import { and, asc, eq } from "drizzle-orm";
|
|||||||
import { randomUUID } from "crypto";
|
import { randomUUID } from "crypto";
|
||||||
import { homepageItems } from "../db/schema.js";
|
import { homepageItems } from "../db/schema.js";
|
||||||
import type { DatabaseContext } from "./database-context.js";
|
import type { DatabaseContext } from "./database-context.js";
|
||||||
|
import { rowsAffected } from "./mutation-result.js";
|
||||||
|
import {
|
||||||
|
deleteReturning,
|
||||||
|
insertReturning,
|
||||||
|
updateReturning,
|
||||||
|
} from "./returning.js";
|
||||||
|
|
||||||
export type HomepageItemRecord = typeof homepageItems.$inferSelect;
|
export type HomepageItemRecord = typeof homepageItems.$inferSelect;
|
||||||
|
|
||||||
@@ -35,18 +41,15 @@ export class HomepageItemRepository {
|
|||||||
input: HomepageItemCreateInput,
|
input: HomepageItemCreateInput,
|
||||||
now = new Date().toISOString(),
|
now = new Date().toISOString(),
|
||||||
): Promise<HomepageItemRecord> {
|
): Promise<HomepageItemRecord> {
|
||||||
const [created] = await this.context.drizzle
|
const [created] = await insertReturning(this.context, homepageItems, {
|
||||||
.insert(homepageItems)
|
syncId: randomUUID(),
|
||||||
.values({
|
userId,
|
||||||
syncId: randomUUID(),
|
typeId: input.typeId,
|
||||||
userId,
|
title: input.title,
|
||||||
typeId: input.typeId,
|
config: input.config,
|
||||||
title: input.title,
|
createdAt: now,
|
||||||
config: input.config,
|
updatedAt: now,
|
||||||
createdAt: now,
|
});
|
||||||
updatedAt: now,
|
|
||||||
})
|
|
||||||
.returning();
|
|
||||||
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return created;
|
return created;
|
||||||
@@ -71,11 +74,12 @@ export class HomepageItemRepository {
|
|||||||
updates: HomepageItemUpdateInput,
|
updates: HomepageItemUpdateInput,
|
||||||
updatedAt = new Date().toISOString(),
|
updatedAt = new Date().toISOString(),
|
||||||
): Promise<HomepageItemRecord | null> {
|
): Promise<HomepageItemRecord | null> {
|
||||||
const [updated] = await this.context.drizzle
|
const [updated] = await updateReturning(
|
||||||
.update(homepageItems)
|
this.context,
|
||||||
.set({ ...updates, updatedAt })
|
homepageItems,
|
||||||
.where(and(eq(homepageItems.id, id), eq(homepageItems.userId, userId)))
|
{ ...updates, updatedAt },
|
||||||
.returning();
|
and(eq(homepageItems.id, id), eq(homepageItems.userId, userId)),
|
||||||
|
);
|
||||||
|
|
||||||
if (updated) {
|
if (updated) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
@@ -88,27 +92,27 @@ export class HomepageItemRepository {
|
|||||||
userId: string,
|
userId: string,
|
||||||
id: number,
|
id: number,
|
||||||
): Promise<{ syncId: string | null } | null> {
|
): Promise<{ syncId: string | null } | null> {
|
||||||
const rows = await this.context.drizzle
|
const rows = await deleteReturning(
|
||||||
.delete(homepageItems)
|
this.context,
|
||||||
.where(and(eq(homepageItems.id, id), eq(homepageItems.userId, userId)))
|
homepageItems,
|
||||||
.returning({ syncId: homepageItems.syncId });
|
and(eq(homepageItems.id, id), eq(homepageItems.userId, userId)),
|
||||||
|
);
|
||||||
|
|
||||||
if (rows.length === 0) return null;
|
if (rows.length === 0) return null;
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return rows[0];
|
return { syncId: rows[0].syncId };
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteByUserId(userId: string): Promise<number> {
|
async deleteByUserId(userId: string): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(homepageItems)
|
.delete(homepageItems)
|
||||||
.where(eq(homepageItems.userId, userId))
|
.where(eq(homepageItems.userId, userId));
|
||||||
.returning({ id: homepageItems.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
private async afterWrite(): Promise<void> {
|
private async afterWrite(): Promise<void> {
|
||||||
|
|||||||
@@ -1,6 +1,8 @@
|
|||||||
import { eq } from "drizzle-orm";
|
import { eq } from "drizzle-orm";
|
||||||
import { homepageLayouts } from "../db/schema.js";
|
import { homepageLayouts } from "../db/schema.js";
|
||||||
import type { DatabaseContext } from "./database-context.js";
|
import type { DatabaseContext } from "./database-context.js";
|
||||||
|
import { rowsAffected } from "./mutation-result.js";
|
||||||
|
import { insertReturning, updateReturning } from "./returning.js";
|
||||||
|
|
||||||
export type HomepageLayoutRecord = typeof homepageLayouts.$inferSelect;
|
export type HomepageLayoutRecord = typeof homepageLayouts.$inferSelect;
|
||||||
|
|
||||||
@@ -28,34 +30,35 @@ export class HomepageLayoutRepository {
|
|||||||
const existing = await this.findByUserId(userId);
|
const existing = await this.findByUserId(userId);
|
||||||
|
|
||||||
if (!existing) {
|
if (!existing) {
|
||||||
const [created] = await this.context.drizzle
|
const [created] = await insertReturning(this.context, homepageLayouts, {
|
||||||
.insert(homepageLayouts)
|
userId,
|
||||||
.values({ userId, layout, updatedAt })
|
layout,
|
||||||
.returning();
|
updatedAt,
|
||||||
|
});
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return created;
|
return created;
|
||||||
}
|
}
|
||||||
|
|
||||||
const [updated] = await this.context.drizzle
|
const [updated] = await updateReturning(
|
||||||
.update(homepageLayouts)
|
this.context,
|
||||||
.set({ layout, updatedAt })
|
homepageLayouts,
|
||||||
.where(eq(homepageLayouts.userId, userId))
|
{ layout, updatedAt },
|
||||||
.returning();
|
eq(homepageLayouts.userId, userId),
|
||||||
|
);
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return updated;
|
return updated;
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteByUserId(userId: string): Promise<number> {
|
async deleteByUserId(userId: string): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(homepageLayouts)
|
.delete(homepageLayouts)
|
||||||
.where(eq(homepageLayouts.userId, userId))
|
.where(eq(homepageLayouts.userId, userId));
|
||||||
.returning({ id: homepageLayouts.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
private async afterWrite(): Promise<void> {
|
private async afterWrite(): Promise<void> {
|
||||||
|
|||||||
@@ -3,6 +3,12 @@ import { randomUUID } from "crypto";
|
|||||||
import type { SQLiteColumn } from "drizzle-orm/sqlite-core";
|
import type { SQLiteColumn } from "drizzle-orm/sqlite-core";
|
||||||
import { hosts, sshCredentials, sshFolders } from "../db/schema.js";
|
import { hosts, sshCredentials, sshFolders } from "../db/schema.js";
|
||||||
import type { DatabaseContext } from "./database-context.js";
|
import type { DatabaseContext } from "./database-context.js";
|
||||||
|
import { rowsAffected } from "./mutation-result.js";
|
||||||
|
import {
|
||||||
|
deleteReturning,
|
||||||
|
insertReturning,
|
||||||
|
updateReturning,
|
||||||
|
} from "./returning.js";
|
||||||
|
|
||||||
export type HostFolderRecord = typeof sshFolders.$inferSelect;
|
export type HostFolderRecord = typeof sshFolders.$inferSelect;
|
||||||
export type HostFolderHostRecord = typeof hosts.$inferSelect;
|
export type HostFolderHostRecord = typeof hosts.$inferSelect;
|
||||||
@@ -24,19 +30,31 @@ export class HostFolderRepository {
|
|||||||
newName: string,
|
newName: string,
|
||||||
now = new Date().toISOString(),
|
now = new Date().toISOString(),
|
||||||
): Promise<RenameFolderResult> {
|
): Promise<RenameFolderResult> {
|
||||||
|
// CAST target: every engine spells the text type differently enough to
|
||||||
|
// matter here — MySQL has no `text` cast and wants `char`.
|
||||||
|
const textType = this.context.dialect === "mysql" ? "char" : "text";
|
||||||
const oldPrefix = `${oldName} / `;
|
const oldPrefix = `${oldName} / `;
|
||||||
const newPrefix = `${newName} / `;
|
const newPrefix = `${newName} / `;
|
||||||
const childLike = `${oldPrefix}%`;
|
const childLike = `${oldPrefix}%`;
|
||||||
|
// CONCAT, not `||`: MySQL reads `||` as logical OR unless the server runs
|
||||||
|
// with PIPES_AS_CONCAT, so the child paths would have been rewritten to 0.
|
||||||
|
// No error, just wrong folder names. CONCAT and SUBSTR mean the same thing
|
||||||
|
// on all three engines.
|
||||||
|
//
|
||||||
|
// The prefix is inlined rather than bound: CONCAT is variadic, so Postgres
|
||||||
|
// cannot infer a parameter's type from its position and rejects the
|
||||||
|
// statement with 42P18 before it runs. The value is a folder name the
|
||||||
|
// caller supplied, so it goes through a bound placeholder in a plain
|
||||||
|
// concatenation instead of sql.raw.
|
||||||
const renameExpr = (col: SQLiteColumn) =>
|
const renameExpr = (col: SQLiteColumn) =>
|
||||||
sql`CASE WHEN ${col} = ${oldName} THEN ${newName} ELSE ${newPrefix} || substr(${col}, ${oldPrefix.length + 1}) END`;
|
sql`CASE WHEN ${col} = ${oldName} THEN ${newName} ELSE CONCAT(CAST(${newPrefix} AS ${sql.raw(textType)}), SUBSTR(${col}, ${sql.raw(String(oldPrefix.length + 1))})) END`;
|
||||||
const folderMatch = (col: SQLiteColumn) =>
|
const folderMatch = (col: SQLiteColumn) =>
|
||||||
or(eq(col, oldName), like(col, childLike));
|
or(eq(col, oldName), like(col, childLike));
|
||||||
|
|
||||||
const updatedHosts = await this.context.drizzle
|
const updatedHosts = await this.context.drizzle
|
||||||
.update(hosts)
|
.update(hosts)
|
||||||
.set({ folder: renameExpr(hosts.folder), updatedAt: now })
|
.set({ folder: renameExpr(hosts.folder), updatedAt: now })
|
||||||
.where(and(eq(hosts.userId, userId), folderMatch(hosts.folder)))
|
.where(and(eq(hosts.userId, userId), folderMatch(hosts.folder)));
|
||||||
.returning({ id: hosts.id });
|
|
||||||
|
|
||||||
const updatedCredentials = await this.context.drizzle
|
const updatedCredentials = await this.context.drizzle
|
||||||
.update(sshCredentials)
|
.update(sshCredentials)
|
||||||
@@ -46,8 +64,7 @@ export class HostFolderRepository {
|
|||||||
eq(sshCredentials.userId, userId),
|
eq(sshCredentials.userId, userId),
|
||||||
folderMatch(sshCredentials.folder),
|
folderMatch(sshCredentials.folder),
|
||||||
),
|
),
|
||||||
)
|
);
|
||||||
.returning({ id: sshCredentials.id });
|
|
||||||
|
|
||||||
await this.context.drizzle
|
await this.context.drizzle
|
||||||
.update(sshFolders)
|
.update(sshFolders)
|
||||||
@@ -56,8 +73,8 @@ export class HostFolderRepository {
|
|||||||
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return {
|
return {
|
||||||
updatedHosts: updatedHosts.length,
|
updatedHosts: rowsAffected(updatedHosts),
|
||||||
updatedCredentials: updatedCredentials.length,
|
updatedCredentials: rowsAffected(updatedCredentials),
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -78,35 +95,33 @@ export class HostFolderRepository {
|
|||||||
): Promise<{ folder: HostFolderRecord; created: boolean }> {
|
): Promise<{ folder: HostFolderRecord; created: boolean }> {
|
||||||
const existing = await this.findFolder(userId, name);
|
const existing = await this.findFolder(userId, name);
|
||||||
if (existing) {
|
if (existing) {
|
||||||
const [updated] = await this.context.drizzle
|
const [updated] = await updateReturning(
|
||||||
.update(sshFolders)
|
this.context,
|
||||||
.set({
|
sshFolders,
|
||||||
|
{
|
||||||
color,
|
color,
|
||||||
icon,
|
icon,
|
||||||
credentialId:
|
credentialId:
|
||||||
credentialId === undefined ? existing.credentialId : credentialId,
|
credentialId === undefined ? existing.credentialId : credentialId,
|
||||||
updatedAt: now,
|
updatedAt: now,
|
||||||
})
|
},
|
||||||
.where(and(eq(sshFolders.userId, userId), eq(sshFolders.name, name)))
|
and(eq(sshFolders.userId, userId), eq(sshFolders.name, name)),
|
||||||
.returning();
|
);
|
||||||
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return { folder: updated, created: false };
|
return { folder: updated, created: false };
|
||||||
}
|
}
|
||||||
|
|
||||||
const [created] = await this.context.drizzle
|
const [created] = await insertReturning(this.context, sshFolders, {
|
||||||
.insert(sshFolders)
|
syncId: randomUUID(),
|
||||||
.values({
|
userId,
|
||||||
syncId: randomUUID(),
|
name,
|
||||||
userId,
|
color,
|
||||||
name,
|
icon,
|
||||||
color,
|
credentialId: credentialId ?? null,
|
||||||
icon,
|
createdAt: now,
|
||||||
credentialId: credentialId ?? null,
|
updatedAt: now,
|
||||||
createdAt: now,
|
});
|
||||||
updatedAt: now,
|
|
||||||
})
|
|
||||||
.returning();
|
|
||||||
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return { folder: created, created: true };
|
return { folder: created, created: true };
|
||||||
@@ -139,10 +154,11 @@ export class HostFolderRepository {
|
|||||||
.where(and(eq(hosts.userId, userId), folderMatch(hosts.folder)));
|
.where(and(eq(hosts.userId, userId), folderMatch(hosts.folder)));
|
||||||
}
|
}
|
||||||
|
|
||||||
const deletedFolders = await this.context.drizzle
|
const deletedFolders = await deleteReturning(
|
||||||
.delete(sshFolders)
|
this.context,
|
||||||
.where(and(eq(sshFolders.userId, userId), folderMatch(sshFolders.name)))
|
sshFolders,
|
||||||
.returning({ syncId: sshFolders.syncId });
|
and(eq(sshFolders.userId, userId), folderMatch(sshFolders.name)),
|
||||||
|
);
|
||||||
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
|
|
||||||
@@ -157,16 +173,15 @@ export class HostFolderRepository {
|
|||||||
}
|
}
|
||||||
|
|
||||||
async deleteByUserId(userId: string): Promise<number> {
|
async deleteByUserId(userId: string): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(sshFolders)
|
.delete(sshFolders)
|
||||||
.where(eq(sshFolders.userId, userId))
|
.where(eq(sshFolders.userId, userId));
|
||||||
.returning({ id: sshFolders.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
private async findFolder(
|
private async findFolder(
|
||||||
|
|||||||
@@ -1,6 +1,8 @@
|
|||||||
import { and, desc, eq } from "drizzle-orm";
|
import { and, desc, eq, notInArray } from "drizzle-orm";
|
||||||
import { hostHealthChecks, hostHealthHistory } from "../db/schema.js";
|
import { hostHealthChecks, hostHealthHistory } from "../db/schema.js";
|
||||||
import type { DatabaseContext } from "./database-context.js";
|
import type { DatabaseContext } from "./database-context.js";
|
||||||
|
import { rowsAffected } from "./mutation-result.js";
|
||||||
|
import { insertReturning, updateReturning } from "./returning.js";
|
||||||
|
|
||||||
export type HostHealthCheckRecord = typeof hostHealthChecks.$inferSelect;
|
export type HostHealthCheckRecord = typeof hostHealthChecks.$inferSelect;
|
||||||
export type HostHealthHistoryRecord = typeof hostHealthHistory.$inferSelect;
|
export type HostHealthHistoryRecord = typeof hostHealthHistory.$inferSelect;
|
||||||
@@ -45,27 +47,25 @@ export class HostHealthRepository {
|
|||||||
): Promise<HostHealthCheckRecord> {
|
): Promise<HostHealthCheckRecord> {
|
||||||
const existing = await this.findChecksByUserAndHost(userId, hostId);
|
const existing = await this.findChecksByUserAndHost(userId, hostId);
|
||||||
if (existing) {
|
if (existing) {
|
||||||
const [updated] = await this.context.drizzle
|
const [updated] = await updateReturning(
|
||||||
.update(hostHealthChecks)
|
this.context,
|
||||||
.set({ checks, intervalSeconds, updatedAt: now })
|
hostHealthChecks,
|
||||||
.where(eq(hostHealthChecks.id, existing.id))
|
{ checks, intervalSeconds, updatedAt: now },
|
||||||
.returning();
|
eq(hostHealthChecks.id, existing.id),
|
||||||
|
);
|
||||||
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return updated;
|
return updated;
|
||||||
}
|
}
|
||||||
|
|
||||||
const [created] = await this.context.drizzle
|
const [created] = await insertReturning(this.context, hostHealthChecks, {
|
||||||
.insert(hostHealthChecks)
|
userId,
|
||||||
.values({
|
hostId,
|
||||||
userId,
|
checks,
|
||||||
hostId,
|
intervalSeconds,
|
||||||
checks,
|
createdAt: now,
|
||||||
intervalSeconds,
|
updatedAt: now,
|
||||||
createdAt: now,
|
});
|
||||||
updatedAt: now,
|
|
||||||
})
|
|
||||||
.returning();
|
|
||||||
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return created;
|
return created;
|
||||||
@@ -94,7 +94,7 @@ export class HostHealthRepository {
|
|||||||
})),
|
})),
|
||||||
);
|
);
|
||||||
|
|
||||||
this.pruneHistory(userId, hostId, keep);
|
await this.pruneHistory(userId, hostId, keep);
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return results.length;
|
return results.length;
|
||||||
}
|
}
|
||||||
@@ -121,41 +121,55 @@ export class HostHealthRepository {
|
|||||||
checksDeleted: number;
|
checksDeleted: number;
|
||||||
historyDeleted: number;
|
historyDeleted: number;
|
||||||
}> {
|
}> {
|
||||||
const historyRows = await this.context.drizzle
|
const historyResult = await this.context.drizzle
|
||||||
.delete(hostHealthHistory)
|
.delete(hostHealthHistory)
|
||||||
.where(eq(hostHealthHistory.userId, userId))
|
.where(eq(hostHealthHistory.userId, userId));
|
||||||
.returning({ id: hostHealthHistory.id });
|
|
||||||
|
|
||||||
const checkRows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(hostHealthChecks)
|
.delete(hostHealthChecks)
|
||||||
.where(eq(hostHealthChecks.userId, userId))
|
.where(eq(hostHealthChecks.userId, userId));
|
||||||
.returning({ id: hostHealthChecks.id });
|
|
||||||
|
|
||||||
if (historyRows.length > 0 || checkRows.length > 0) {
|
if (rowsAffected(historyResult) > 0 || rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return {
|
return {
|
||||||
checksDeleted: checkRows.length,
|
checksDeleted: rowsAffected(result),
|
||||||
historyDeleted: historyRows.length,
|
historyDeleted: rowsAffected(historyResult),
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
private pruneHistory(userId: string, hostId: number, keep: number): void {
|
/** Keeps the newest `keep` rows for the host and drops the rest. */
|
||||||
this.context.sqlite
|
private async pruneHistory(
|
||||||
?.prepare(
|
userId: string,
|
||||||
`DELETE FROM host_health_history
|
hostId: number,
|
||||||
WHERE id IN (
|
keep: number,
|
||||||
SELECT id FROM host_health_history
|
): Promise<void> {
|
||||||
WHERE user_id = ? AND host_id = ?
|
const scope = and(
|
||||||
AND id NOT IN (
|
eq(hostHealthHistory.userId, userId),
|
||||||
SELECT id FROM host_health_history
|
eq(hostHealthHistory.hostId, hostId),
|
||||||
WHERE user_id = ? AND host_id = ?
|
);
|
||||||
ORDER BY ts DESC LIMIT ?
|
|
||||||
)
|
const retained = await this.context.drizzle
|
||||||
)`,
|
.select({ id: hostHealthHistory.id })
|
||||||
)
|
.from(hostHealthHistory)
|
||||||
.run(userId, hostId, userId, hostId, keep);
|
.where(scope)
|
||||||
|
.orderBy(desc(hostHealthHistory.ts))
|
||||||
|
.limit(keep);
|
||||||
|
|
||||||
|
// Nothing retained means nothing to keep back, so the scope alone is the
|
||||||
|
// delete condition.
|
||||||
|
await this.context.drizzle.delete(hostHealthHistory).where(
|
||||||
|
retained.length
|
||||||
|
? and(
|
||||||
|
scope,
|
||||||
|
notInArray(
|
||||||
|
hostHealthHistory.id,
|
||||||
|
retained.map((row) => row.id),
|
||||||
|
),
|
||||||
|
)
|
||||||
|
: scope,
|
||||||
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
private async afterWrite(): Promise<void> {
|
private async afterWrite(): Promise<void> {
|
||||||
|
|||||||
@@ -1,6 +1,7 @@
|
|||||||
import { and, asc, eq, gte, lte } from "drizzle-orm";
|
import { and, asc, eq, gte, lt, lte } from "drizzle-orm";
|
||||||
import { hostMetricsHistory } from "../db/schema.js";
|
import { hostMetricsHistory } from "../db/schema.js";
|
||||||
import type { DatabaseContext } from "./database-context.js";
|
import type { DatabaseContext } from "./database-context.js";
|
||||||
|
import { sqlTimestampDaysAgo } from "./sql-timestamp.js";
|
||||||
|
|
||||||
export type HostMetricsHistoryRecord = typeof hostMetricsHistory.$inferSelect;
|
export type HostMetricsHistoryRecord = typeof hostMetricsHistory.$inferSelect;
|
||||||
|
|
||||||
@@ -32,12 +33,15 @@ export class HostMetricsHistoryRepository {
|
|||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
pruneOlderThan(hostId: number, retentionDays: number): void {
|
async pruneOlderThan(hostId: number, retentionDays: number): Promise<void> {
|
||||||
this.context.sqlite
|
await this.context.drizzle
|
||||||
?.prepare(
|
.delete(hostMetricsHistory)
|
||||||
"DELETE FROM host_metrics_history WHERE host_id = ? AND ts < datetime('now', ?)",
|
.where(
|
||||||
)
|
and(
|
||||||
.run(hostId, `-${retentionDays} days`);
|
eq(hostMetricsHistory.hostId, hostId),
|
||||||
|
lt(hostMetricsHistory.ts, sqlTimestampDaysAgo(retentionDays)),
|
||||||
|
),
|
||||||
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
async listRange(
|
async listRange(
|
||||||
|
|||||||
@@ -1,6 +1,8 @@
|
|||||||
import { and, eq } from "drizzle-orm";
|
import { and, eq } from "drizzle-orm";
|
||||||
import { hostMetricsPreferences, hosts } from "../db/schema.js";
|
import { hostMetricsPreferences, hosts } from "../db/schema.js";
|
||||||
import type { DatabaseContext } from "./database-context.js";
|
import type { DatabaseContext } from "./database-context.js";
|
||||||
|
import { rowsAffected } from "./mutation-result.js";
|
||||||
|
import { insertReturning, updateReturning } from "./returning.js";
|
||||||
|
|
||||||
export type HostMetricsPreferenceRecord =
|
export type HostMetricsPreferenceRecord =
|
||||||
typeof hostMetricsPreferences.$inferSelect;
|
typeof hostMetricsPreferences.$inferSelect;
|
||||||
@@ -37,26 +39,28 @@ export class HostMetricsPreferenceRepository {
|
|||||||
): Promise<HostMetricsPreferenceRecord> {
|
): Promise<HostMetricsPreferenceRecord> {
|
||||||
const existing = await this.findByUserAndHost(userId, hostId);
|
const existing = await this.findByUserAndHost(userId, hostId);
|
||||||
if (existing) {
|
if (existing) {
|
||||||
const [updated] = await this.context.drizzle
|
const [updated] = await updateReturning(
|
||||||
.update(hostMetricsPreferences)
|
this.context,
|
||||||
.set({ layout, updatedAt: now })
|
hostMetricsPreferences,
|
||||||
.where(eq(hostMetricsPreferences.id, existing.id))
|
{ layout, updatedAt: now },
|
||||||
.returning();
|
eq(hostMetricsPreferences.id, existing.id),
|
||||||
|
);
|
||||||
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return updated;
|
return updated;
|
||||||
}
|
}
|
||||||
|
|
||||||
const [created] = await this.context.drizzle
|
const [created] = await insertReturning(
|
||||||
.insert(hostMetricsPreferences)
|
this.context,
|
||||||
.values({
|
hostMetricsPreferences,
|
||||||
|
{
|
||||||
userId,
|
userId,
|
||||||
hostId,
|
hostId,
|
||||||
layout,
|
layout,
|
||||||
createdAt: now,
|
createdAt: now,
|
||||||
updatedAt: now,
|
updatedAt: now,
|
||||||
})
|
},
|
||||||
.returning();
|
);
|
||||||
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return created;
|
return created;
|
||||||
@@ -67,28 +71,26 @@ export class HostMetricsPreferenceRepository {
|
|||||||
hostId: number,
|
hostId: number,
|
||||||
statsConfig: string,
|
statsConfig: string,
|
||||||
): Promise<boolean> {
|
): Promise<boolean> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.update(hosts)
|
.update(hosts)
|
||||||
.set({ statsConfig })
|
.set({ statsConfig })
|
||||||
.where(and(eq(hosts.id, hostId), eq(hosts.userId, userId)))
|
.where(and(eq(hosts.id, hostId), eq(hosts.userId, userId)));
|
||||||
.returning({ id: hosts.id });
|
|
||||||
|
|
||||||
if (rows.length === 0) return false;
|
if (rowsAffected(result) === 0) return false;
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return true;
|
return true;
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteByUserId(userId: string): Promise<number> {
|
async deleteByUserId(userId: string): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(hostMetricsPreferences)
|
.delete(hostMetricsPreferences)
|
||||||
.where(eq(hostMetricsPreferences.userId, userId))
|
.where(eq(hostMetricsPreferences.userId, userId));
|
||||||
.returning({ id: hostMetricsPreferences.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
private async afterWrite(): Promise<void> {
|
private async afterWrite(): Promise<void> {
|
||||||
|
|||||||
@@ -3,6 +3,12 @@ import { randomUUID } from "crypto";
|
|||||||
import { hostAccess, hosts } from "../db/schema.js";
|
import { hostAccess, hosts } from "../db/schema.js";
|
||||||
import type { DatabaseContext } from "./database-context.js";
|
import type { DatabaseContext } from "./database-context.js";
|
||||||
import { DataCrypto } from "../../utils/data-crypto.js";
|
import { DataCrypto } from "../../utils/data-crypto.js";
|
||||||
|
import { rowsAffected } from "./mutation-result.js";
|
||||||
|
import {
|
||||||
|
deleteReturning,
|
||||||
|
insertReturning,
|
||||||
|
updateReturning,
|
||||||
|
} from "./returning.js";
|
||||||
|
|
||||||
export type HostRecord = typeof hosts.$inferSelect;
|
export type HostRecord = typeof hosts.$inferSelect;
|
||||||
export type NewHostRecord = typeof hosts.$inferInsert;
|
export type NewHostRecord = typeof hosts.$inferInsert;
|
||||||
@@ -21,10 +27,10 @@ export class HostRepository {
|
|||||||
) {}
|
) {}
|
||||||
|
|
||||||
async create(host: NewHostRecord): Promise<HostRecord> {
|
async create(host: NewHostRecord): Promise<HostRecord> {
|
||||||
const rows = await this.context.drizzle
|
const rows = await insertReturning(this.context, hosts, {
|
||||||
.insert(hosts)
|
syncId: randomUUID(),
|
||||||
.values({ syncId: randomUUID(), ...host })
|
...host,
|
||||||
.returning();
|
});
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return rows[0];
|
return rows[0];
|
||||||
}
|
}
|
||||||
@@ -51,10 +57,11 @@ export class HostRepository {
|
|||||||
delete (encryptedHost as Partial<NewHostRecord>).id;
|
delete (encryptedHost as Partial<NewHostRecord>).id;
|
||||||
}
|
}
|
||||||
|
|
||||||
const rows = await this.context.drizzle
|
const rows = await insertReturning(
|
||||||
.insert(hosts)
|
this.context,
|
||||||
.values(encryptedHost as NewHostRecord)
|
hosts,
|
||||||
.returning();
|
encryptedHost as NewHostRecord,
|
||||||
|
);
|
||||||
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return DataCrypto.decryptRecord("ssh_data", rows[0], userId, userDataKey);
|
return DataCrypto.decryptRecord("ssh_data", rows[0], userId, userDataKey);
|
||||||
@@ -150,11 +157,12 @@ export class HostRepository {
|
|||||||
hostId: number,
|
hostId: number,
|
||||||
update: HostUpdate,
|
update: HostUpdate,
|
||||||
): Promise<HostRecord | null> {
|
): Promise<HostRecord | null> {
|
||||||
const rows = await this.context.drizzle
|
const rows = await updateReturning(
|
||||||
.update(hosts)
|
this.context,
|
||||||
.set({ ...update, updatedAt: sql`CURRENT_TIMESTAMP` })
|
hosts,
|
||||||
.where(and(eq(hosts.id, hostId), eq(hosts.userId, userId)))
|
{ ...update, updatedAt: sql`CURRENT_TIMESTAMP` },
|
||||||
.returning();
|
and(eq(hosts.id, hostId), eq(hosts.userId, userId)),
|
||||||
|
);
|
||||||
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return rows[0] ?? null;
|
return rows[0] ?? null;
|
||||||
@@ -173,11 +181,12 @@ export class HostRepository {
|
|||||||
userDataKey,
|
userDataKey,
|
||||||
);
|
);
|
||||||
|
|
||||||
const rows = await this.context.drizzle
|
const rows = await updateReturning(
|
||||||
.update(hosts)
|
this.context,
|
||||||
.set({ ...encryptedUpdate, updatedAt: sql`CURRENT_TIMESTAMP` })
|
hosts,
|
||||||
.where(and(eq(hosts.id, hostId), eq(hosts.userId, userId)))
|
{ ...encryptedUpdate, updatedAt: sql`CURRENT_TIMESTAMP` },
|
||||||
.returning();
|
and(eq(hosts.id, hostId), eq(hosts.userId, userId)),
|
||||||
|
);
|
||||||
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return rows[0]
|
return rows[0]
|
||||||
@@ -213,17 +222,16 @@ export class HostRepository {
|
|||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.update(hosts)
|
.update(hosts)
|
||||||
.set({ ...update, updatedAt: sql`CURRENT_TIMESTAMP` })
|
.set({ ...update, updatedAt: sql`CURRENT_TIMESTAMP` })
|
||||||
.where(and(inArray(hosts.id, hostIds), eq(hosts.userId, userId)))
|
.where(and(inArray(hosts.id, hostIds), eq(hosts.userId, userId)));
|
||||||
.returning({ id: hosts.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteForUser(
|
async deleteForUser(
|
||||||
@@ -232,39 +240,38 @@ export class HostRepository {
|
|||||||
): Promise<{ syncId: string | null } | null> {
|
): Promise<{ syncId: string | null } | null> {
|
||||||
await this.deleteAccessForHost(hostId);
|
await this.deleteAccessForHost(hostId);
|
||||||
|
|
||||||
const rows = await this.context.drizzle
|
const rows = await deleteReturning(
|
||||||
.delete(hosts)
|
this.context,
|
||||||
.where(and(eq(hosts.id, hostId), eq(hosts.userId, userId)))
|
hosts,
|
||||||
.returning({ syncId: hosts.syncId });
|
and(eq(hosts.id, hostId), eq(hosts.userId, userId)),
|
||||||
|
);
|
||||||
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return rows[0] ?? null;
|
return rows[0] ? { syncId: rows[0].syncId } : null;
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteByUserId(userId: string): Promise<number> {
|
async deleteByUserId(userId: string): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(hosts)
|
.delete(hosts)
|
||||||
.where(eq(hosts.userId, userId))
|
.where(eq(hosts.userId, userId));
|
||||||
.returning({ id: hosts.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteAccessForHost(hostId: number): Promise<number> {
|
async deleteAccessForHost(hostId: number): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(hostAccess)
|
.delete(hostAccess)
|
||||||
.where(eq(hostAccess.hostId, hostId))
|
.where(eq(hostAccess.hostId, hostId));
|
||||||
.returning({ id: hostAccess.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
private async afterWrite(): Promise<void> {
|
private async afterWrite(): Promise<void> {
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
import { and, eq, inArray, isNotNull } from "drizzle-orm";
|
import { and, eq, inArray, isNotNull } from "drizzle-orm";
|
||||||
import { hostAccess, hosts, sshCredentials, sshFolders } from "../db/schema.js";
|
import { hosts, sshCredentials, sshFolders } from "../db/schema.js";
|
||||||
import type { DatabaseContext } from "./database-context.js";
|
import type { DatabaseContext } from "./database-context.js";
|
||||||
import { DataCrypto } from "../../utils/data-crypto.js";
|
import { DataCrypto } from "../../utils/data-crypto.js";
|
||||||
|
|
||||||
@@ -26,6 +26,28 @@ export interface HostListAccessEntry {
|
|||||||
permissionLevel: string;
|
permissionLevel: string;
|
||||||
expiresAt: string | null;
|
expiresAt: string | null;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
const HOST_PERMISSION_RANK: Record<string, number> = {
|
||||||
|
connect: 1,
|
||||||
|
view: 2,
|
||||||
|
edit: 3,
|
||||||
|
manage: 4,
|
||||||
|
};
|
||||||
|
|
||||||
|
function preferHostAccess(
|
||||||
|
current: HostListAccessEntry,
|
||||||
|
candidate: HostListAccessEntry,
|
||||||
|
): HostListAccessEntry {
|
||||||
|
const currentRank = HOST_PERMISSION_RANK[current.permissionLevel] ?? 0;
|
||||||
|
const candidateRank = HOST_PERMISSION_RANK[candidate.permissionLevel] ?? 0;
|
||||||
|
if (candidateRank !== currentRank) {
|
||||||
|
return candidateRank > currentRank ? candidate : current;
|
||||||
|
}
|
||||||
|
if (current.expiresAt === null) return current;
|
||||||
|
if (candidate.expiresAt === null) return candidate;
|
||||||
|
return candidate.expiresAt > current.expiresAt ? candidate : current;
|
||||||
|
}
|
||||||
|
|
||||||
export type HostListRow = HostResolutionHostRecord & {
|
export type HostListRow = HostResolutionHostRecord & {
|
||||||
ownerId: string;
|
ownerId: string;
|
||||||
isShared: boolean;
|
isShared: boolean;
|
||||||
@@ -103,9 +125,15 @@ export class HostResolutionRepository {
|
|||||||
.from(hosts)
|
.from(hosts)
|
||||||
.where(eq(hosts.userId, userId));
|
.where(eq(hosts.userId, userId));
|
||||||
|
|
||||||
const sharedHostIds = Array.from(
|
const accessByHostId = new Map<number, HostListAccessEntry>();
|
||||||
new Set(accessEntries.map((access) => access.hostId)),
|
for (const access of accessEntries) {
|
||||||
);
|
const current = accessByHostId.get(access.hostId);
|
||||||
|
accessByHostId.set(
|
||||||
|
access.hostId,
|
||||||
|
current ? preferHostAccess(current, access) : access,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
const sharedHostIds = Array.from(accessByHostId.keys());
|
||||||
const sharedHostRows =
|
const sharedHostRows =
|
||||||
sharedHostIds.length > 0
|
sharedHostIds.length > 0
|
||||||
? await this.context.drizzle
|
? await this.context.drizzle
|
||||||
@@ -125,7 +153,7 @@ export class HostResolutionRepository {
|
|||||||
permissionLevel: undefined,
|
permissionLevel: undefined,
|
||||||
expiresAt: undefined,
|
expiresAt: undefined,
|
||||||
})),
|
})),
|
||||||
...accessEntries.flatMap((access) => {
|
...Array.from(accessByHostId.values()).flatMap((access) => {
|
||||||
const host = sharedHostsById.get(access.hostId);
|
const host = sharedHostsById.get(access.hostId);
|
||||||
if (!host || host.userId === userId) {
|
if (!host || host.userId === userId) {
|
||||||
return [];
|
return [];
|
||||||
@@ -302,19 +330,6 @@ export class HostResolutionRepository {
|
|||||||
return this.decryptOne("ssh_credentials", rows[0], decryptUserId);
|
return this.decryptOne("ssh_credentials", rows[0], decryptUserId);
|
||||||
}
|
}
|
||||||
|
|
||||||
async findOverrideCredentialId(
|
|
||||||
hostId: number,
|
|
||||||
userId: string,
|
|
||||||
): Promise<number | null> {
|
|
||||||
const rows = await this.context.drizzle
|
|
||||||
.select({ overrideCredentialId: hostAccess.overrideCredentialId })
|
|
||||||
.from(hostAccess)
|
|
||||||
.where(and(eq(hostAccess.hostId, hostId), eq(hostAccess.userId, userId)))
|
|
||||||
.limit(1);
|
|
||||||
|
|
||||||
return rows[0]?.overrideCredentialId ?? null;
|
|
||||||
}
|
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Resolve the nearest assigned credential for a folder path, walking up
|
* Resolve the nearest assigned credential for a folder path, walking up
|
||||||
* through parent folders (e.g. "Switches / Floor1" falls back to
|
* through parent folders (e.g. "Switches / Floor1" falls back to
|
||||||
|
|||||||
@@ -0,0 +1,157 @@
|
|||||||
|
import type { DatabaseDialect } from "../db/dialect.js";
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Reading the outcome of a write without depending on RETURNING.
|
||||||
|
*
|
||||||
|
* SQLite and Postgres can attach `.returning()` to a delete or update and get
|
||||||
|
* the affected rows back. **MySQL cannot** — it has no RETURNING clause, and
|
||||||
|
* drizzle's mysql-core does not expose the method at all, so the call is a
|
||||||
|
* TypeError rather than a bad query. 175 call sites here read a write's result,
|
||||||
|
* so the difference has to be absorbed somewhere.
|
||||||
|
*
|
||||||
|
* The split that matters is what the caller actually needs:
|
||||||
|
*
|
||||||
|
* - **How many rows changed** — the majority, and none of them need the rows.
|
||||||
|
* They used to ask for them anyway, via `.returning().length`. Dropping the
|
||||||
|
* `.returning()` and reading the driver's own count is both portable and one
|
||||||
|
* less thing for the database to send back.
|
||||||
|
* - **The rows themselves** — cannot be emulated on MySQL without reading
|
||||||
|
* first, which needs a transaction to stay correct under concurrency. Those
|
||||||
|
* call sites are handled individually rather than behind a helper that hides
|
||||||
|
* an extra round trip.
|
||||||
|
*/
|
||||||
|
|
||||||
|
/**
|
||||||
|
* The count each driver reports for a write, under its own name.
|
||||||
|
*
|
||||||
|
* Every engine says how many rows a write touched. None of them agree on what
|
||||||
|
* to call it:
|
||||||
|
*
|
||||||
|
* | driver | shape |
|
||||||
|
* |----------------|----------------------------------------|
|
||||||
|
* | better-sqlite3 | `{ changes, lastInsertRowid }` |
|
||||||
|
* | node-postgres | `{ rowCount, rows, command }` |
|
||||||
|
* | mysql2 | `[{ affectedRows, insertId }, fields]` |
|
||||||
|
*
|
||||||
|
* These are the shapes returned when NO `.returning()` is attached — which is
|
||||||
|
* the portable way to write, since MySQL has no RETURNING clause at all.
|
||||||
|
*/
|
||||||
|
interface WriteHeader {
|
||||||
|
changes?: number;
|
||||||
|
rowCount?: number;
|
||||||
|
affectedRows?: number;
|
||||||
|
lastInsertRowid?: number | bigint;
|
||||||
|
insertId?: number;
|
||||||
|
}
|
||||||
|
|
||||||
|
const COUNT_FIELDS = ["changes", "rowCount", "affectedRows"] as const;
|
||||||
|
|
||||||
|
/**
|
||||||
|
* mysql2 hands back `[ResultSetHeader, fields]`, which is itself an array — so
|
||||||
|
* "is it an array" cannot distinguish a write header from a returning() result.
|
||||||
|
* The header is identified by carrying one of the fields above instead.
|
||||||
|
*/
|
||||||
|
function asWriteHeader(result: unknown): WriteHeader | null {
|
||||||
|
const candidate =
|
||||||
|
Array.isArray(result) && result.length > 0 ? result[0] : result;
|
||||||
|
|
||||||
|
if (!candidate || typeof candidate !== "object") return null;
|
||||||
|
const header = candidate as WriteHeader;
|
||||||
|
|
||||||
|
const known =
|
||||||
|
COUNT_FIELDS.some((field) => typeof header[field] === "number") ||
|
||||||
|
typeof header.insertId === "number" ||
|
||||||
|
typeof header.lastInsertRowid === "number" ||
|
||||||
|
typeof header.lastInsertRowid === "bigint";
|
||||||
|
|
||||||
|
return known ? header : null;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Number of rows a write touched.
|
||||||
|
*
|
||||||
|
* Pass the result of the write itself — every driver's header is understood, so
|
||||||
|
* the caller neither branches on the dialect nor attaches `.returning()` just to
|
||||||
|
* count what came back.
|
||||||
|
*
|
||||||
|
* A `.returning()` array is still accepted, for the call sites that need the
|
||||||
|
* rows for their own reasons and would rather not count them twice.
|
||||||
|
*/
|
||||||
|
export function rowsAffected(result: unknown): number {
|
||||||
|
const header = asWriteHeader(result);
|
||||||
|
if (header) {
|
||||||
|
for (const field of COUNT_FIELDS) {
|
||||||
|
const count = header[field];
|
||||||
|
if (typeof count === "number") return count;
|
||||||
|
}
|
||||||
|
// A header with only insertId: one row went in.
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (Array.isArray(result)) return result.length;
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Id assigned by an insert.
|
||||||
|
*
|
||||||
|
* **Only meaningful on the result of an insert.** SQLite's `lastInsertRowid` and
|
||||||
|
* MySQL's `insertId` are connection-level values that survive the statement that
|
||||||
|
* set them — after a delete, SQLite still reports whatever the last insert
|
||||||
|
* produced. Passing an update or delete result here gets a stale id, not null.
|
||||||
|
*
|
||||||
|
* Returns null when the table has no autoincrement key.
|
||||||
|
*/
|
||||||
|
export function insertedId(result: unknown): number | null {
|
||||||
|
const header = asWriteHeader(result);
|
||||||
|
if (header) {
|
||||||
|
// MySQL and SQLite both use 0 for "no autoincrement column".
|
||||||
|
if (typeof header.insertId === "number") {
|
||||||
|
return header.insertId > 0 ? header.insertId : null;
|
||||||
|
}
|
||||||
|
if (typeof header.lastInsertRowid === "bigint") {
|
||||||
|
return header.lastInsertRowid > 0n
|
||||||
|
? Number(header.lastInsertRowid)
|
||||||
|
: null;
|
||||||
|
}
|
||||||
|
if (typeof header.lastInsertRowid === "number") {
|
||||||
|
return header.lastInsertRowid > 0 ? header.lastInsertRowid : null;
|
||||||
|
}
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
if (Array.isArray(result)) {
|
||||||
|
const first = result[0] as { id?: unknown } | undefined;
|
||||||
|
return typeof first?.id === "number" ? first.id : null;
|
||||||
|
}
|
||||||
|
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Whether `.returning()` can be attached to a write on this engine.
|
||||||
|
*
|
||||||
|
* Call sites that genuinely need the affected rows use this to choose between
|
||||||
|
* one statement and a read-then-write inside a transaction.
|
||||||
|
*/
|
||||||
|
export function supportsReturning(dialect: DatabaseDialect): boolean {
|
||||||
|
return dialect !== "mysql";
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Reads an aggregate count as a number.
|
||||||
|
*
|
||||||
|
* `sql<number>` is a type assertion, not a conversion. Postgres returns COUNT()
|
||||||
|
* as bigint, which node-postgres hands back as a **string** so that values past
|
||||||
|
* 2^53 survive — so the annotation is a lie there and comparisons like
|
||||||
|
* `count < max` compare a string to a number.
|
||||||
|
*/
|
||||||
|
export function countValue(value: unknown): number {
|
||||||
|
if (typeof value === "number") return value;
|
||||||
|
if (typeof value === "bigint") return Number(value);
|
||||||
|
if (typeof value === "string") {
|
||||||
|
const parsed = Number(value);
|
||||||
|
return Number.isFinite(parsed) ? parsed : 0;
|
||||||
|
}
|
||||||
|
return 0;
|
||||||
|
}
|
||||||
@@ -1,6 +1,7 @@
|
|||||||
import { eq } from "drizzle-orm";
|
import { eq } from "drizzle-orm";
|
||||||
import { networkTopology } from "../db/schema.js";
|
import { networkTopology } from "../db/schema.js";
|
||||||
import type { DatabaseContext } from "./database-context.js";
|
import type { DatabaseContext } from "./database-context.js";
|
||||||
|
import { rowsAffected } from "./mutation-result.js";
|
||||||
|
|
||||||
export type NetworkTopologyRecord = typeof networkTopology.$inferSelect;
|
export type NetworkTopologyRecord = typeof networkTopology.$inferSelect;
|
||||||
|
|
||||||
@@ -45,16 +46,15 @@ export class NetworkTopologyRepository {
|
|||||||
}
|
}
|
||||||
|
|
||||||
async deleteByUserId(userId: string): Promise<number> {
|
async deleteByUserId(userId: string): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(networkTopology)
|
.delete(networkTopology)
|
||||||
.where(eq(networkTopology.userId, userId))
|
.where(eq(networkTopology.userId, userId));
|
||||||
.returning({ id: networkTopology.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
private async afterWrite(): Promise<void> {
|
private async afterWrite(): Promise<void> {
|
||||||
|
|||||||
@@ -1,6 +1,7 @@
|
|||||||
import { and, eq, gt } from "drizzle-orm";
|
import { and, eq, gt } from "drizzle-orm";
|
||||||
import { userOpenTabs } from "../db/schema.js";
|
import { userOpenTabs } from "../db/schema.js";
|
||||||
import type { DatabaseContext } from "./database-context.js";
|
import type { DatabaseContext } from "./database-context.js";
|
||||||
|
import { rowsAffected } from "./mutation-result.js";
|
||||||
|
|
||||||
export type OpenTabRecord = typeof userOpenTabs.$inferSelect;
|
export type OpenTabRecord = typeof userOpenTabs.$inferSelect;
|
||||||
export type NewOpenTabRecord = typeof userOpenTabs.$inferInsert;
|
export type NewOpenTabRecord = typeof userOpenTabs.$inferInsert;
|
||||||
@@ -111,43 +112,40 @@ export class OpenTabRepository {
|
|||||||
update: OpenTabUpdate,
|
update: OpenTabUpdate,
|
||||||
updatedAt = new Date().toISOString(),
|
updatedAt = new Date().toISOString(),
|
||||||
): Promise<boolean> {
|
): Promise<boolean> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.update(userOpenTabs)
|
.update(userOpenTabs)
|
||||||
.set({ ...update, updatedAt })
|
.set({ ...update, updatedAt })
|
||||||
.where(and(eq(userOpenTabs.id, id), eq(userOpenTabs.userId, userId)))
|
.where(and(eq(userOpenTabs.id, id), eq(userOpenTabs.userId, userId)));
|
||||||
.returning({ id: userOpenTabs.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length > 0;
|
return rowsAffected(result) > 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteForUser(userId: string, id: string): Promise<number> {
|
async deleteForUser(userId: string, id: string): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(userOpenTabs)
|
.delete(userOpenTabs)
|
||||||
.where(and(eq(userOpenTabs.id, id), eq(userOpenTabs.userId, userId)))
|
.where(and(eq(userOpenTabs.id, id), eq(userOpenTabs.userId, userId)));
|
||||||
.returning({ id: userOpenTabs.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteByUserId(userId: string): Promise<number> {
|
async deleteByUserId(userId: string): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(userOpenTabs)
|
.delete(userOpenTabs)
|
||||||
.where(eq(userOpenTabs.userId, userId))
|
.where(eq(userOpenTabs.userId, userId));
|
||||||
.returning({ id: userOpenTabs.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
private async findByIdForUser(
|
private async findByIdForUser(
|
||||||
|
|||||||
@@ -1,6 +1,8 @@
|
|||||||
import { and, eq } from "drizzle-orm";
|
import { and, eq } from "drizzle-orm";
|
||||||
import { opksshTokens } from "../db/schema.js";
|
import { opksshTokens } from "../db/schema.js";
|
||||||
import type { DatabaseContext } from "./database-context.js";
|
import type { DatabaseContext } from "./database-context.js";
|
||||||
|
import { rowsAffected } from "./mutation-result.js";
|
||||||
|
import { upsert } from "./returning.js";
|
||||||
|
|
||||||
export type OpksshTokenRecord = typeof opksshTokens.$inferSelect;
|
export type OpksshTokenRecord = typeof opksshTokens.$inferSelect;
|
||||||
|
|
||||||
@@ -26,9 +28,10 @@ export class OpksshTokenRepository {
|
|||||||
async upsert(input: OpksshTokenUpsertInput): Promise<void> {
|
async upsert(input: OpksshTokenUpsertInput): Promise<void> {
|
||||||
const createdAt = input.createdAt ?? new Date().toISOString();
|
const createdAt = input.createdAt ?? new Date().toISOString();
|
||||||
|
|
||||||
await this.context.drizzle
|
await upsert(
|
||||||
.insert(opksshTokens)
|
this.context,
|
||||||
.values({
|
opksshTokens,
|
||||||
|
{
|
||||||
userId: input.userId,
|
userId: input.userId,
|
||||||
hostId: input.hostId,
|
hostId: input.hostId,
|
||||||
sshCert: input.sshCert,
|
sshCert: input.sshCert,
|
||||||
@@ -38,8 +41,8 @@ export class OpksshTokenRepository {
|
|||||||
issuer: input.issuer,
|
issuer: input.issuer,
|
||||||
audience: input.audience,
|
audience: input.audience,
|
||||||
expiresAt: input.expiresAt,
|
expiresAt: input.expiresAt,
|
||||||
})
|
},
|
||||||
.onConflictDoUpdate({
|
{
|
||||||
target: [opksshTokens.userId, opksshTokens.hostId],
|
target: [opksshTokens.userId, opksshTokens.hostId],
|
||||||
set: {
|
set: {
|
||||||
sshCert: input.sshCert,
|
sshCert: input.sshCert,
|
||||||
@@ -51,7 +54,8 @@ export class OpksshTokenRepository {
|
|||||||
expiresAt: input.expiresAt,
|
expiresAt: input.expiresAt,
|
||||||
createdAt,
|
createdAt,
|
||||||
},
|
},
|
||||||
});
|
},
|
||||||
|
);
|
||||||
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
@@ -76,47 +80,44 @@ export class OpksshTokenRepository {
|
|||||||
hostId: number,
|
hostId: number,
|
||||||
lastUsed = new Date().toISOString(),
|
lastUsed = new Date().toISOString(),
|
||||||
): Promise<boolean> {
|
): Promise<boolean> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.update(opksshTokens)
|
.update(opksshTokens)
|
||||||
.set({ lastUsed })
|
.set({ lastUsed })
|
||||||
.where(
|
.where(
|
||||||
and(eq(opksshTokens.userId, userId), eq(opksshTokens.hostId, hostId)),
|
and(eq(opksshTokens.userId, userId), eq(opksshTokens.hostId, hostId)),
|
||||||
)
|
);
|
||||||
.returning({ id: opksshTokens.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length > 0;
|
return rowsAffected(result) > 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteByUserAndHost(userId: string, hostId: number): Promise<boolean> {
|
async deleteByUserAndHost(userId: string, hostId: number): Promise<boolean> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(opksshTokens)
|
.delete(opksshTokens)
|
||||||
.where(
|
.where(
|
||||||
and(eq(opksshTokens.userId, userId), eq(opksshTokens.hostId, hostId)),
|
and(eq(opksshTokens.userId, userId), eq(opksshTokens.hostId, hostId)),
|
||||||
)
|
);
|
||||||
.returning({ id: opksshTokens.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length > 0;
|
return rowsAffected(result) > 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteByUserId(userId: string): Promise<number> {
|
async deleteByUserId(userId: string): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(opksshTokens)
|
.delete(opksshTokens)
|
||||||
.where(eq(opksshTokens.userId, userId))
|
.where(eq(opksshTokens.userId, userId));
|
||||||
.returning({ id: opksshTokens.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
private async afterWrite(): Promise<void> {
|
private async afterWrite(): Promise<void> {
|
||||||
|
|||||||
@@ -9,6 +9,8 @@ import {
|
|||||||
users,
|
users,
|
||||||
} from "../db/schema.js";
|
} from "../db/schema.js";
|
||||||
import type { DatabaseContext } from "./database-context.js";
|
import type { DatabaseContext } from "./database-context.js";
|
||||||
|
import { rowsAffected } from "./mutation-result.js";
|
||||||
|
import { insertReturning } from "./returning.js";
|
||||||
|
|
||||||
export type RbacAccessTargetType = "user" | "role";
|
export type RbacAccessTargetType = "user" | "role";
|
||||||
|
|
||||||
@@ -156,7 +158,7 @@ export class RbacAccessRepository {
|
|||||||
return { id: existing.id, created: false };
|
return { id: existing.id, created: false };
|
||||||
}
|
}
|
||||||
|
|
||||||
const result = await this.context.drizzle.insert(hostAccess).values({
|
const [created] = await insertReturning(this.context, hostAccess, {
|
||||||
hostId: input.hostId,
|
hostId: input.hostId,
|
||||||
userId: input.targetType === "user" ? input.targetUserId : null,
|
userId: input.targetType === "user" ? input.targetUserId : null,
|
||||||
roleId: input.targetType === "role" ? input.targetRoleId : null,
|
roleId: input.targetType === "role" ? input.targetRoleId : null,
|
||||||
@@ -166,7 +168,7 @@ export class RbacAccessRepository {
|
|||||||
});
|
});
|
||||||
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return { id: Number(result.lastInsertRowid), created: true };
|
return { id: created.id, created: true };
|
||||||
}
|
}
|
||||||
|
|
||||||
async revokeHostAccess(accessId: number, hostId: number): Promise<void> {
|
async revokeHostAccess(accessId: number, hostId: number): Promise<void> {
|
||||||
@@ -177,16 +179,15 @@ export class RbacAccessRepository {
|
|||||||
}
|
}
|
||||||
|
|
||||||
async deleteHostAccessForHost(hostId: number): Promise<number> {
|
async deleteHostAccessForHost(hostId: number): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(hostAccess)
|
.delete(hostAccess)
|
||||||
.where(eq(hostAccess.hostId, hostId))
|
.where(eq(hostAccess.hostId, hostId));
|
||||||
.returning({ id: hostAccess.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteHostAccessForHosts(hostIds: number[]): Promise<number> {
|
async deleteHostAccessForHosts(hostIds: number[]): Promise<number> {
|
||||||
@@ -194,30 +195,27 @@ export class RbacAccessRepository {
|
|||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(hostAccess)
|
.delete(hostAccess)
|
||||||
.where(inArray(hostAccess.hostId, hostIds))
|
.where(inArray(hostAccess.hostId, hostIds));
|
||||||
.returning({ id: hostAccess.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteHostAccessForUserReferences(userId: string): Promise<number> {
|
async deleteHostAccessForUserReferences(userId: string): Promise<number> {
|
||||||
const directRows = await this.context.drizzle
|
const directResult = await this.context.drizzle
|
||||||
.delete(hostAccess)
|
.delete(hostAccess)
|
||||||
.where(eq(hostAccess.userId, userId))
|
.where(eq(hostAccess.userId, userId));
|
||||||
.returning({ id: hostAccess.id });
|
|
||||||
|
|
||||||
const grantedRows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(hostAccess)
|
.delete(hostAccess)
|
||||||
.where(eq(hostAccess.grantedBy, userId))
|
.where(eq(hostAccess.grantedBy, userId));
|
||||||
.returning({ id: hostAccess.id });
|
|
||||||
|
|
||||||
const deletedCount = directRows.length + grantedRows.length;
|
const deletedCount = rowsAffected(directResult) + rowsAffected(result);
|
||||||
if (deletedCount > 0) {
|
if (deletedCount > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
@@ -238,17 +236,6 @@ export class RbacAccessRepository {
|
|||||||
return rows[0] ?? null;
|
return rows[0] ?? null;
|
||||||
}
|
}
|
||||||
|
|
||||||
async updateHostAccessOverrideCredential(
|
|
||||||
accessId: number,
|
|
||||||
credentialId: number | null,
|
|
||||||
): Promise<void> {
|
|
||||||
await this.context.drizzle
|
|
||||||
.update(hostAccess)
|
|
||||||
.set({ overrideCredentialId: credentialId })
|
|
||||||
.where(eq(hostAccess.id, accessId));
|
|
||||||
await this.afterWrite();
|
|
||||||
}
|
|
||||||
|
|
||||||
async listSnippetAccess(snippetId: number): Promise<RbacAccessListItem[]> {
|
async listSnippetAccess(snippetId: number): Promise<RbacAccessListItem[]> {
|
||||||
const rows = await this.context.drizzle
|
const rows = await this.context.drizzle
|
||||||
.select({
|
.select({
|
||||||
@@ -291,7 +278,7 @@ export class RbacAccessRepository {
|
|||||||
return { id: existing.id, created: false };
|
return { id: existing.id, created: false };
|
||||||
}
|
}
|
||||||
|
|
||||||
const result = await this.context.drizzle.insert(snippetAccess).values({
|
const [created] = await insertReturning(this.context, snippetAccess, {
|
||||||
snippetId: input.snippetId,
|
snippetId: input.snippetId,
|
||||||
userId: input.targetType === "user" ? input.targetUserId : null,
|
userId: input.targetType === "user" ? input.targetUserId : null,
|
||||||
roleId: input.targetType === "role" ? input.targetRoleId : null,
|
roleId: input.targetType === "role" ? input.targetRoleId : null,
|
||||||
@@ -301,7 +288,7 @@ export class RbacAccessRepository {
|
|||||||
});
|
});
|
||||||
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return { id: Number(result.lastInsertRowid), created: true };
|
return { id: created.id, created: true };
|
||||||
}
|
}
|
||||||
|
|
||||||
async revokeSnippetAccess(
|
async revokeSnippetAccess(
|
||||||
@@ -512,21 +499,20 @@ export class RbacAccessRepository {
|
|||||||
async deleteExpiredHostAccess(
|
async deleteExpiredHostAccess(
|
||||||
now = new Date().toISOString(),
|
now = new Date().toISOString(),
|
||||||
): Promise<number> {
|
): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(hostAccess)
|
.delete(hostAccess)
|
||||||
.where(
|
.where(
|
||||||
and(
|
and(
|
||||||
sql`${hostAccess.expiresAt} IS NOT NULL`,
|
sql`${hostAccess.expiresAt} IS NOT NULL`,
|
||||||
sql`${hostAccess.expiresAt} <= ${now}`,
|
sql`${hostAccess.expiresAt} <= ${now}`,
|
||||||
),
|
),
|
||||||
)
|
);
|
||||||
.returning({ id: hostAccess.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
async findActiveHostAccess(
|
async findActiveHostAccess(
|
||||||
@@ -635,17 +621,16 @@ export class RbacAccessRepository {
|
|||||||
hostId: number,
|
hostId: number,
|
||||||
update: { permissionLevel?: string; expiresAt?: string | null },
|
update: { permissionLevel?: string; expiresAt?: string | null },
|
||||||
): Promise<boolean> {
|
): Promise<boolean> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.update(hostAccess)
|
.update(hostAccess)
|
||||||
.set(update)
|
.set(update)
|
||||||
.where(and(eq(hostAccess.id, accessId), eq(hostAccess.hostId, hostId)))
|
.where(and(eq(hostAccess.id, accessId), eq(hostAccess.hostId, hostId)));
|
||||||
.returning({ id: hostAccess.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length > 0;
|
return rowsAffected(result) > 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
async findHostAccessOwnerId(hostAccessId: number): Promise<string | null> {
|
async findHostAccessOwnerId(hostAccessId: number): Promise<string | null> {
|
||||||
|
|||||||
@@ -1,6 +1,8 @@
|
|||||||
import { desc, eq, inArray } from "drizzle-orm";
|
import { desc, eq, inArray } from "drizzle-orm";
|
||||||
import { recentActivity } from "../db/schema.js";
|
import { recentActivity } from "../db/schema.js";
|
||||||
import type { DatabaseContext } from "./database-context.js";
|
import type { DatabaseContext } from "./database-context.js";
|
||||||
|
import { rowsAffected } from "./mutation-result.js";
|
||||||
|
import { insertReturning } from "./returning.js";
|
||||||
|
|
||||||
export type RecentActivityRecord = typeof recentActivity.$inferSelect;
|
export type RecentActivityRecord = typeof recentActivity.$inferSelect;
|
||||||
export type NewRecentActivityRecord = typeof recentActivity.$inferInsert;
|
export type NewRecentActivityRecord = typeof recentActivity.$inferInsert;
|
||||||
@@ -26,10 +28,7 @@ export class RecentActivityRepository {
|
|||||||
async create(
|
async create(
|
||||||
activity: NewRecentActivityRecord,
|
activity: NewRecentActivityRecord,
|
||||||
): Promise<RecentActivityRecord> {
|
): Promise<RecentActivityRecord> {
|
||||||
const rows = await this.context.drizzle
|
const rows = await insertReturning(this.context, recentActivity, activity);
|
||||||
.insert(recentActivity)
|
|
||||||
.values(activity)
|
|
||||||
.returning();
|
|
||||||
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return rows[0];
|
return rows[0];
|
||||||
@@ -51,42 +50,39 @@ export class RecentActivityRepository {
|
|||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
const deletedRows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(recentActivity)
|
.delete(recentActivity)
|
||||||
.where(inArray(recentActivity.id, idsToDelete))
|
.where(inArray(recentActivity.id, idsToDelete));
|
||||||
.returning({ id: recentActivity.id });
|
|
||||||
|
|
||||||
if (deletedRows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return deletedRows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteByUserId(userId: string): Promise<number> {
|
async deleteByUserId(userId: string): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(recentActivity)
|
.delete(recentActivity)
|
||||||
.where(eq(recentActivity.userId, userId))
|
.where(eq(recentActivity.userId, userId));
|
||||||
.returning({ id: recentActivity.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteByHostId(hostId: number): Promise<number> {
|
async deleteByHostId(hostId: number): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(recentActivity)
|
.delete(recentActivity)
|
||||||
.where(eq(recentActivity.hostId, hostId))
|
.where(eq(recentActivity.hostId, hostId));
|
||||||
.returning({ id: recentActivity.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteByHostIds(hostIds: number[]): Promise<number> {
|
async deleteByHostIds(hostIds: number[]): Promise<number> {
|
||||||
@@ -94,16 +90,15 @@ export class RecentActivityRepository {
|
|||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(recentActivity)
|
.delete(recentActivity)
|
||||||
.where(inArray(recentActivity.hostId, hostIds))
|
.where(inArray(recentActivity.hostId, hostIds));
|
||||||
.returning({ id: recentActivity.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
private async afterWrite(): Promise<void> {
|
private async afterWrite(): Promise<void> {
|
||||||
|
|||||||
@@ -0,0 +1,227 @@
|
|||||||
|
import { eq, type SQL } from "drizzle-orm";
|
||||||
|
import type { SQLiteColumn, SQLiteTable } from "drizzle-orm/sqlite-core";
|
||||||
|
import type { DatabaseContext } from "./database-context.js";
|
||||||
|
import {
|
||||||
|
insertedId,
|
||||||
|
rowsAffected,
|
||||||
|
supportsReturning,
|
||||||
|
} from "./mutation-result.js";
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Writes that need the affected rows back.
|
||||||
|
*
|
||||||
|
* `mutation-result.ts` covers the call sites that only wanted a count. These are
|
||||||
|
* the ones that genuinely read the rows — an updated record to return to the
|
||||||
|
* caller, a deleted row's fields to clean up alongside it.
|
||||||
|
*
|
||||||
|
* SQLite and Postgres do this in one statement with RETURNING. MySQL has no
|
||||||
|
* such clause, so the read is a second statement, and the pair has to be atomic:
|
||||||
|
*
|
||||||
|
* - **insert** — write, then read the row back by its key.
|
||||||
|
* - **update** — write, then read. Reading first would return the old values.
|
||||||
|
* - **delete** — read, then write. Reading after would return nothing.
|
||||||
|
*
|
||||||
|
* Both run in a transaction. Without one, a concurrent write between the two
|
||||||
|
* statements makes the returned rows describe a state that never existed, and
|
||||||
|
* with a connection pool the second statement might not even reach the same
|
||||||
|
* connection.
|
||||||
|
*
|
||||||
|
* ## The trap, and why it cannot bite silently
|
||||||
|
*
|
||||||
|
* On MySQL the update path re-reads using the same `where`. If the update
|
||||||
|
* changes a column that `where` tests, the read finds nothing — SQLite would
|
||||||
|
* have returned the row. Every current caller filters on an id it does not
|
||||||
|
* modify, but that is a convention, not a guarantee, so the mismatch is
|
||||||
|
* detected and thrown rather than returned as an empty array. Same for an
|
||||||
|
* insert whose row cannot be read back.
|
||||||
|
*
|
||||||
|
* Row types come from the table, so call sites keep the typing they had with
|
||||||
|
* `.returning()` and nothing has to be annotated by hand.
|
||||||
|
*/
|
||||||
|
|
||||||
|
/**
|
||||||
|
* What `.set()` accepts: a column's own type, or a SQL expression in its place —
|
||||||
|
* `updatedAt: sql`CURRENT_TIMESTAMP`` is the common one here.
|
||||||
|
*/
|
||||||
|
type UpdateValues<T extends SQLiteTable> = {
|
||||||
|
[K in keyof T["$inferInsert"]]?: T["$inferInsert"][K] | SQL;
|
||||||
|
};
|
||||||
|
|
||||||
|
export async function updateReturning<T extends SQLiteTable>(
|
||||||
|
context: DatabaseContext,
|
||||||
|
table: T,
|
||||||
|
values: UpdateValues<T>,
|
||||||
|
where: SQL,
|
||||||
|
): Promise<T["$inferSelect"][]> {
|
||||||
|
const db = context.drizzle;
|
||||||
|
|
||||||
|
if (supportsReturning(context.dialect)) {
|
||||||
|
// The cast resolves a conditional in drizzle's return type that TypeScript
|
||||||
|
// cannot narrow while T is still generic. The runtime shape is the rows.
|
||||||
|
return db.update(table).set(values).where(where).returning() as Promise<
|
||||||
|
T["$inferSelect"][]
|
||||||
|
>;
|
||||||
|
}
|
||||||
|
|
||||||
|
return db.transaction(async (tx) => {
|
||||||
|
const written = await tx.update(table).set(values).where(where);
|
||||||
|
const rows = await tx.select().from(table).where(where);
|
||||||
|
|
||||||
|
// The trap this catches: if the update changed a column that `where` tests,
|
||||||
|
// the read finds nothing and the caller gets [] — on MySQL only, with no
|
||||||
|
// error, where SQLite would have returned the row. Rows changed but none
|
||||||
|
// readable back is exactly that case, so make it loud instead.
|
||||||
|
if (rows.length === 0 && rowsAffected(written) > 0) {
|
||||||
|
throw new Error(
|
||||||
|
`updateReturning wrote ${rowsAffected(written)} row(s) but could not read ` +
|
||||||
|
`them back: the update changed a column the where clause filters on. ` +
|
||||||
|
`Read the rows first, or filter on a column the update leaves alone.`,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
return rows;
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
export async function deleteReturning<T extends SQLiteTable>(
|
||||||
|
context: DatabaseContext,
|
||||||
|
table: T,
|
||||||
|
where: SQL,
|
||||||
|
): Promise<T["$inferSelect"][]> {
|
||||||
|
const db = context.drizzle;
|
||||||
|
|
||||||
|
if (supportsReturning(context.dialect)) {
|
||||||
|
return db.delete(table).where(where).returning() as Promise<
|
||||||
|
T["$inferSelect"][]
|
||||||
|
>;
|
||||||
|
}
|
||||||
|
|
||||||
|
return db.transaction(async (tx) => {
|
||||||
|
const rows = await tx.select().from(table).where(where);
|
||||||
|
await tx.delete(table).where(where);
|
||||||
|
return rows;
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
/** A table this can read a single row back from. */
|
||||||
|
type Keyed = SQLiteTable & { id: SQLiteColumn };
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Inserts one row and returns it as stored, including whatever the database
|
||||||
|
* filled in — defaults, an autoincrement id, a CURRENT_TIMESTAMP.
|
||||||
|
*
|
||||||
|
* This is the one case Postgres cannot shortcut either: without RETURNING there
|
||||||
|
* is no id to read back by. Hence the split is genuinely three-way — except
|
||||||
|
* that sqlite and pg both have RETURNING, so it collapses to two again.
|
||||||
|
*
|
||||||
|
* On MySQL the key comes from one of two places:
|
||||||
|
*
|
||||||
|
* - the caller supplied it (tables keyed by a text id, like `users`)
|
||||||
|
* - the engine assigned it, reported as `insertId`
|
||||||
|
*
|
||||||
|
* Restricted to tables with an `id` column, so a table keyed some other way is
|
||||||
|
* a compile error here rather than a row that silently fails to come back.
|
||||||
|
*/
|
||||||
|
export async function insertReturning<T extends Keyed>(
|
||||||
|
context: DatabaseContext,
|
||||||
|
table: T,
|
||||||
|
values: T["$inferInsert"],
|
||||||
|
): Promise<T["$inferSelect"][]> {
|
||||||
|
const db = context.drizzle;
|
||||||
|
|
||||||
|
if (supportsReturning(context.dialect)) {
|
||||||
|
return db.insert(table).values(values).returning() as Promise<
|
||||||
|
T["$inferSelect"][]
|
||||||
|
>;
|
||||||
|
}
|
||||||
|
|
||||||
|
return db.transaction(async (tx) => {
|
||||||
|
const result = await tx.insert(table).values(values);
|
||||||
|
|
||||||
|
const supplied = (values as { id?: string | number }).id;
|
||||||
|
const key = supplied ?? insertedId(result);
|
||||||
|
if (key === null || key === undefined) {
|
||||||
|
throw new Error(
|
||||||
|
`Insert into ${String(table)} returned no id to read the row back by.`,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
const rows = await tx.select().from(table).where(eq(table.id, key));
|
||||||
|
if (rows.length === 0) {
|
||||||
|
throw new Error(
|
||||||
|
`Inserted into ${String(table)} but could not read the row back by id ${key}.`,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
return rows;
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Inserts one row into a table keyed by something other than `id`, reading it
|
||||||
|
* back by an explicit condition.
|
||||||
|
*
|
||||||
|
* `user_preferences` is keyed by `userId` and has no `id` column at all, so
|
||||||
|
* there is no insertId to read back by — the caller has to say what identifies
|
||||||
|
* the row it just wrote.
|
||||||
|
*/
|
||||||
|
export async function insertReturningWhere<T extends SQLiteTable>(
|
||||||
|
context: DatabaseContext,
|
||||||
|
table: T,
|
||||||
|
values: T["$inferInsert"],
|
||||||
|
where: SQL,
|
||||||
|
): Promise<T["$inferSelect"][]> {
|
||||||
|
const db = context.drizzle;
|
||||||
|
|
||||||
|
if (supportsReturning(context.dialect)) {
|
||||||
|
return db.insert(table).values(values).returning() as Promise<
|
||||||
|
T["$inferSelect"][]
|
||||||
|
>;
|
||||||
|
}
|
||||||
|
|
||||||
|
return db.transaction(async (tx) => {
|
||||||
|
await tx.insert(table).values(values);
|
||||||
|
const rows = await tx.select().from(table).where(where);
|
||||||
|
if (rows.length === 0) {
|
||||||
|
throw new Error(
|
||||||
|
`Inserted into ${String(table)} but the read-back condition matched nothing.`,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
return rows;
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Insert, or update the row that collides with it.
|
||||||
|
*
|
||||||
|
* The clause has three spellings. SQLite and Postgres take
|
||||||
|
* `ON CONFLICT (cols) DO UPDATE`; **MySQL takes `ON DUPLICATE KEY UPDATE` and
|
||||||
|
* names no columns** — it uses whichever unique key was violated. drizzle
|
||||||
|
* follows suit, so `onConflictDoUpdate` does not exist on mysql-core at all and
|
||||||
|
* calling it is a TypeError rather than a rejected query.
|
||||||
|
*
|
||||||
|
* The conflict target still has to be passed: it is what SQLite and Postgres
|
||||||
|
* need, and stating it keeps the caller honest about which unique constraint it
|
||||||
|
* is relying on — four of those were missing from the schema entirely until the
|
||||||
|
* cross-dialect tests went looking.
|
||||||
|
*/
|
||||||
|
export async function upsert<T extends SQLiteTable>(
|
||||||
|
context: DatabaseContext,
|
||||||
|
table: T,
|
||||||
|
values: T["$inferInsert"],
|
||||||
|
conflict: { target: SQLiteColumn[]; set: UpdateValues<T> },
|
||||||
|
): Promise<void> {
|
||||||
|
const db = context.drizzle;
|
||||||
|
|
||||||
|
if (context.dialect === "mysql") {
|
||||||
|
const insert = db.insert(table).values(values) as unknown as {
|
||||||
|
onDuplicateKeyUpdate: (config: { set: UpdateValues<T> }) => Promise<void>;
|
||||||
|
};
|
||||||
|
await insert.onDuplicateKeyUpdate({ set: conflict.set });
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
await db
|
||||||
|
.insert(table)
|
||||||
|
.values(values)
|
||||||
|
.onConflictDoUpdate({ target: conflict.target, set: conflict.set });
|
||||||
|
}
|
||||||
@@ -1,6 +1,8 @@
|
|||||||
import { and, eq, inArray } from "drizzle-orm";
|
import { and, eq, inArray } from "drizzle-orm";
|
||||||
import { hostAccess, roles, userRoles } from "../db/schema.js";
|
import { hostAccess, roles, userRoles } from "../db/schema.js";
|
||||||
import type { DatabaseContext } from "./database-context.js";
|
import type { DatabaseContext } from "./database-context.js";
|
||||||
|
import { rowsAffected } from "./mutation-result.js";
|
||||||
|
import { deleteReturning, insertReturning } from "./returning.js";
|
||||||
|
|
||||||
export type RoleRecord = typeof roles.$inferSelect;
|
export type RoleRecord = typeof roles.$inferSelect;
|
||||||
export type NewRoleRecord = typeof roles.$inferInsert;
|
export type NewRoleRecord = typeof roles.$inferInsert;
|
||||||
@@ -62,27 +64,27 @@ export class RoleRepository {
|
|||||||
}
|
}
|
||||||
|
|
||||||
async createRole(role: NewRoleRecord): Promise<number> {
|
async createRole(role: NewRoleRecord): Promise<number> {
|
||||||
const result = await this.context.drizzle.insert(roles).values(role);
|
const [created] = await insertReturning(this.context, roles, role);
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return Number(result.lastInsertRowid);
|
return created.id;
|
||||||
}
|
}
|
||||||
|
|
||||||
async updateRole(id: number, update: RoleUpdate): Promise<boolean> {
|
async updateRole(id: number, update: RoleUpdate): Promise<boolean> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.update(roles)
|
.update(roles)
|
||||||
.set(update)
|
.set(update)
|
||||||
.where(eq(roles.id, id))
|
.where(eq(roles.id, id));
|
||||||
.returning({ id: roles.id });
|
|
||||||
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return rows.length > 0;
|
return rowsAffected(result) > 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteRole(id: number): Promise<{ deletedUserIds: string[] }> {
|
async deleteRole(id: number): Promise<{ deletedUserIds: string[] }> {
|
||||||
const deletedUserRoles = await this.context.drizzle
|
const deletedUserRoles = await deleteReturning(
|
||||||
.delete(userRoles)
|
this.context,
|
||||||
.where(eq(userRoles.roleId, id))
|
userRoles,
|
||||||
.returning({ userId: userRoles.userId });
|
eq(userRoles.roleId, id),
|
||||||
|
);
|
||||||
|
|
||||||
await this.context.drizzle
|
await this.context.drizzle
|
||||||
.delete(hostAccess)
|
.delete(hostAccess)
|
||||||
@@ -169,16 +171,15 @@ export class RoleRepository {
|
|||||||
}
|
}
|
||||||
|
|
||||||
if (removeRole) {
|
if (removeRole) {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(userRoles)
|
.delete(userRoles)
|
||||||
.where(
|
.where(
|
||||||
and(
|
and(
|
||||||
eq(userRoles.userId, input.userId),
|
eq(userRoles.userId, input.userId),
|
||||||
eq(userRoles.roleId, removeRole.id),
|
eq(userRoles.roleId, removeRole.id),
|
||||||
),
|
),
|
||||||
)
|
);
|
||||||
.returning({ id: userRoles.id });
|
removed = rowsAffected(result) > 0;
|
||||||
removed = rows.length > 0;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
if (added || removed) {
|
if (added || removed) {
|
||||||
@@ -196,16 +197,15 @@ export class RoleRepository {
|
|||||||
}
|
}
|
||||||
|
|
||||||
async removeAllRolesFromUser(userId: string): Promise<number> {
|
async removeAllRolesFromUser(userId: string): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(userRoles)
|
.delete(userRoles)
|
||||||
.where(eq(userRoles.userId, userId))
|
.where(eq(userRoles.userId, userId));
|
||||||
.returning({ id: userRoles.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
async listUserRoleIds(userId: string): Promise<number[]> {
|
async listUserRoleIds(userId: string): Promise<number[]> {
|
||||||
|
|||||||
@@ -1,6 +1,8 @@
|
|||||||
import { and, desc, eq, inArray, lt } from "drizzle-orm";
|
import { and, desc, eq, inArray, lt } from "drizzle-orm";
|
||||||
import { hosts, sessionRecordings } from "../db/schema.js";
|
import { hosts, sessionRecordings } from "../db/schema.js";
|
||||||
import type { DatabaseContext } from "./database-context.js";
|
import type { DatabaseContext } from "./database-context.js";
|
||||||
|
import { rowsAffected } from "./mutation-result.js";
|
||||||
|
import { insertReturning } from "./returning.js";
|
||||||
|
|
||||||
export type SessionRecordingRecord = typeof sessionRecordings.$inferSelect;
|
export type SessionRecordingRecord = typeof sessionRecordings.$inferSelect;
|
||||||
|
|
||||||
@@ -47,10 +49,11 @@ export class SessionRecordingRepository {
|
|||||||
async create(
|
async create(
|
||||||
input: SessionRecordingCreateInput,
|
input: SessionRecordingCreateInput,
|
||||||
): Promise<SessionRecordingRecord> {
|
): Promise<SessionRecordingRecord> {
|
||||||
const [created] = await this.context.drizzle
|
const [created] = await insertReturning(
|
||||||
.insert(sessionRecordings)
|
this.context,
|
||||||
.values(input)
|
sessionRecordings,
|
||||||
.returning();
|
input,
|
||||||
|
);
|
||||||
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return created;
|
return created;
|
||||||
@@ -170,57 +173,71 @@ export class SessionRecordingRepository {
|
|||||||
}
|
}
|
||||||
|
|
||||||
async deleteById(id: number): Promise<boolean> {
|
async deleteById(id: number): Promise<boolean> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(sessionRecordings)
|
.delete(sessionRecordings)
|
||||||
.where(eq(sessionRecordings.id, id))
|
.where(eq(sessionRecordings.id, id));
|
||||||
.returning({ id: sessionRecordings.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length > 0;
|
return rowsAffected(result) > 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteForUser(userId: string, id: number): Promise<boolean> {
|
async deleteForUser(userId: string, id: number): Promise<boolean> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(sessionRecordings)
|
.delete(sessionRecordings)
|
||||||
.where(
|
.where(
|
||||||
and(eq(sessionRecordings.id, id), eq(sessionRecordings.userId, userId)),
|
and(eq(sessionRecordings.id, id), eq(sessionRecordings.userId, userId)),
|
||||||
)
|
);
|
||||||
.returning({ id: sessionRecordings.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length > 0;
|
return rowsAffected(result) > 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Detaches recordings from a user being deleted instead of removing them.
|
||||||
|
* A recording is evidence about the host as much as about the person, and the
|
||||||
|
* file stays on disk regardless — deleting only the row would orphan it.
|
||||||
|
*/
|
||||||
|
async anonymizeByUserId(userId: string): Promise<number> {
|
||||||
|
const result = await this.context.drizzle
|
||||||
|
.update(sessionRecordings)
|
||||||
|
.set({ userId: null })
|
||||||
|
.where(eq(sessionRecordings.userId, userId));
|
||||||
|
|
||||||
|
if (rowsAffected(result) > 0) {
|
||||||
|
await this.afterWrite();
|
||||||
|
}
|
||||||
|
|
||||||
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteByUserId(userId: string): Promise<number> {
|
async deleteByUserId(userId: string): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(sessionRecordings)
|
.delete(sessionRecordings)
|
||||||
.where(eq(sessionRecordings.userId, userId))
|
.where(eq(sessionRecordings.userId, userId));
|
||||||
.returning({ id: sessionRecordings.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteByHostId(hostId: number): Promise<number> {
|
async deleteByHostId(hostId: number): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(sessionRecordings)
|
.delete(sessionRecordings)
|
||||||
.where(eq(sessionRecordings.hostId, hostId))
|
.where(eq(sessionRecordings.hostId, hostId));
|
||||||
.returning({ id: sessionRecordings.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteByHostIds(hostIds: number[]): Promise<number> {
|
async deleteByHostIds(hostIds: number[]): Promise<number> {
|
||||||
@@ -228,16 +245,15 @@ export class SessionRecordingRepository {
|
|||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(sessionRecordings)
|
.delete(sessionRecordings)
|
||||||
.where(inArray(sessionRecordings.hostId, hostIds))
|
.where(inArray(sessionRecordings.hostId, hostIds));
|
||||||
.returning({ id: sessionRecordings.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
private async afterWrite(): Promise<void> {
|
private async afterWrite(): Promise<void> {
|
||||||
|
|||||||
@@ -1,6 +1,8 @@
|
|||||||
import { and, eq, lte, ne } from "drizzle-orm";
|
import { and, eq, lte, ne } from "drizzle-orm";
|
||||||
import { sessions } from "../db/schema.js";
|
import { sessions } from "../db/schema.js";
|
||||||
import type { DatabaseContext } from "./database-context.js";
|
import type { DatabaseContext } from "./database-context.js";
|
||||||
|
import { rowsAffected } from "./mutation-result.js";
|
||||||
|
import { insertReturning } from "./returning.js";
|
||||||
|
|
||||||
export type SessionRecord = typeof sessions.$inferSelect;
|
export type SessionRecord = typeof sessions.$inferSelect;
|
||||||
export type NewSessionRecord = typeof sessions.$inferInsert;
|
export type NewSessionRecord = typeof sessions.$inferInsert;
|
||||||
@@ -12,10 +14,7 @@ export class SessionRepository {
|
|||||||
) {}
|
) {}
|
||||||
|
|
||||||
async create(session: NewSessionRecord): Promise<SessionRecord> {
|
async create(session: NewSessionRecord): Promise<SessionRecord> {
|
||||||
const rows = await this.context.drizzle
|
const rows = await insertReturning(this.context, sessions, session);
|
||||||
.insert(sessions)
|
|
||||||
.values(session)
|
|
||||||
.returning();
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return rows[0];
|
return rows[0];
|
||||||
}
|
}
|
||||||
@@ -72,13 +71,12 @@ export class SessionRepository {
|
|||||||
}
|
}
|
||||||
|
|
||||||
async revoke(id: string): Promise<boolean> {
|
async revoke(id: string): Promise<boolean> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(sessions)
|
.delete(sessions)
|
||||||
.where(eq(sessions.id, id))
|
.where(eq(sessions.id, id));
|
||||||
.returning({ id: sessions.id });
|
|
||||||
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return rows.length > 0;
|
return rowsAffected(result) > 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
async revokeAllForUser(
|
async revokeAllForUser(
|
||||||
@@ -89,23 +87,19 @@ export class SessionRepository {
|
|||||||
? and(eq(sessions.userId, userId), ne(sessions.id, exceptSessionId))
|
? and(eq(sessions.userId, userId), ne(sessions.id, exceptSessionId))
|
||||||
: eq(sessions.userId, userId);
|
: eq(sessions.userId, userId);
|
||||||
|
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle.delete(sessions).where(where);
|
||||||
.delete(sessions)
|
|
||||||
.where(where)
|
|
||||||
.returning({ id: sessions.id });
|
|
||||||
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteExpired(now = new Date()): Promise<number> {
|
async deleteExpired(now = new Date()): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(sessions)
|
.delete(sessions)
|
||||||
.where(lte(sessions.expiresAt, now.toISOString()))
|
.where(lte(sessions.expiresAt, now.toISOString()));
|
||||||
.returning({ id: sessions.id });
|
|
||||||
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
private async afterWrite(): Promise<void> {
|
private async afterWrite(): Promise<void> {
|
||||||
|
|||||||
@@ -6,6 +6,8 @@ import {
|
|||||||
users,
|
users,
|
||||||
} from "../db/schema.js";
|
} from "../db/schema.js";
|
||||||
import type { DatabaseContext } from "./database-context.js";
|
import type { DatabaseContext } from "./database-context.js";
|
||||||
|
import { rowsAffected } from "./mutation-result.js";
|
||||||
|
import { insertReturning } from "./returning.js";
|
||||||
|
|
||||||
export type SessionShareRecord = typeof sessionShares.$inferSelect;
|
export type SessionShareRecord = typeof sessionShares.$inferSelect;
|
||||||
export type SessionShareParticipantRecord =
|
export type SessionShareParticipantRecord =
|
||||||
@@ -49,22 +51,19 @@ export class SessionShareRepository {
|
|||||||
) {}
|
) {}
|
||||||
|
|
||||||
async create(input: SessionShareCreateInput): Promise<SessionShareRecord> {
|
async create(input: SessionShareCreateInput): Promise<SessionShareRecord> {
|
||||||
const [created] = await this.context.drizzle
|
const [created] = await insertReturning(this.context, sessionShares, {
|
||||||
.insert(sessionShares)
|
id: input.id,
|
||||||
.values({
|
hostId: input.hostId,
|
||||||
id: input.id,
|
ownerUserId: input.ownerUserId,
|
||||||
hostId: input.hostId,
|
protocol: input.protocol,
|
||||||
ownerUserId: input.ownerUserId,
|
sessionId: input.sessionId,
|
||||||
protocol: input.protocol,
|
tabInstanceId: input.tabInstanceId ?? null,
|
||||||
sessionId: input.sessionId,
|
shareType: input.shareType,
|
||||||
tabInstanceId: input.tabInstanceId ?? null,
|
targetUserId: input.targetUserId ?? null,
|
||||||
shareType: input.shareType,
|
linkToken: input.linkToken ?? null,
|
||||||
targetUserId: input.targetUserId ?? null,
|
permissionLevel: input.permissionLevel,
|
||||||
linkToken: input.linkToken ?? null,
|
expiresAt: input.expiresAt,
|
||||||
permissionLevel: input.permissionLevel,
|
});
|
||||||
expiresAt: input.expiresAt,
|
|
||||||
})
|
|
||||||
.returning();
|
|
||||||
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return created;
|
return created;
|
||||||
@@ -151,7 +150,7 @@ export class SessionShareRepository {
|
|||||||
}
|
}
|
||||||
|
|
||||||
async revoke(shareId: string, requestingUserId: string): Promise<boolean> {
|
async revoke(shareId: string, requestingUserId: string): Promise<boolean> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.update(sessionShares)
|
.update(sessionShares)
|
||||||
.set({ revokedAt: new Date().toISOString() })
|
.set({ revokedAt: new Date().toISOString() })
|
||||||
.where(
|
.where(
|
||||||
@@ -159,38 +158,35 @@ export class SessionShareRepository {
|
|||||||
eq(sessionShares.id, shareId),
|
eq(sessionShares.id, shareId),
|
||||||
eq(sessionShares.ownerUserId, requestingUserId),
|
eq(sessionShares.ownerUserId, requestingUserId),
|
||||||
),
|
),
|
||||||
)
|
);
|
||||||
.returning({ id: sessionShares.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
return rows.length > 0;
|
return rowsAffected(result) > 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
async revokeAsAdmin(shareId: string): Promise<boolean> {
|
async revokeAsAdmin(shareId: string): Promise<boolean> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.update(sessionShares)
|
.update(sessionShares)
|
||||||
.set({ revokedAt: new Date().toISOString() })
|
.set({ revokedAt: new Date().toISOString() })
|
||||||
.where(eq(sessionShares.id, shareId))
|
.where(eq(sessionShares.id, shareId));
|
||||||
.returning({ id: sessionShares.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
return rows.length > 0;
|
return rowsAffected(result) > 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteExpiredShares(now = new Date().toISOString()): Promise<number> {
|
async deleteExpiredShares(now = new Date().toISOString()): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(sessionShares)
|
.delete(sessionShares)
|
||||||
.where(lt(sessionShares.expiresAt, now))
|
.where(lt(sessionShares.expiresAt, now));
|
||||||
.returning({ id: sessionShares.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
async touchShareUsage(
|
async touchShareUsage(
|
||||||
@@ -213,10 +209,11 @@ export class SessionShareRepository {
|
|||||||
userId: string | null,
|
userId: string | null,
|
||||||
guestLabel: string | null,
|
guestLabel: string | null,
|
||||||
): Promise<SessionShareParticipantRecord> {
|
): Promise<SessionShareParticipantRecord> {
|
||||||
const [created] = await this.context.drizzle
|
const [created] = await insertReturning(
|
||||||
.insert(sessionShareParticipants)
|
this.context,
|
||||||
.values({ shareId, userId, guestLabel })
|
sessionShareParticipants,
|
||||||
.returning();
|
{ shareId, userId, guestLabel },
|
||||||
|
);
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return created;
|
return created;
|
||||||
}
|
}
|
||||||
@@ -230,15 +227,14 @@ export class SessionShareRepository {
|
|||||||
}
|
}
|
||||||
|
|
||||||
async deleteSharesForHost(hostId: number): Promise<number> {
|
async deleteSharesForHost(hostId: number): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(sessionShares)
|
.delete(sessionShares)
|
||||||
.where(eq(sessionShares.hostId, hostId))
|
.where(eq(sessionShares.hostId, hostId));
|
||||||
.returning({ id: sessionShares.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
private async afterWrite(): Promise<void> {
|
private async afterWrite(): Promise<void> {
|
||||||
|
|||||||
@@ -0,0 +1,52 @@
|
|||||||
|
/**
|
||||||
|
* Synchronous read-through cache for the settings table.
|
||||||
|
*
|
||||||
|
* 27 call sites read settings synchronously — during startup, inside request
|
||||||
|
* handlers, and from the guacd server bootstrap. On SQLite that works because
|
||||||
|
* better-sqlite3 is synchronous; on Postgres or MySQL there is no synchronous
|
||||||
|
* query at all, and making all 27 async would push `await` through code paths
|
||||||
|
* that have no business being asynchronous.
|
||||||
|
*
|
||||||
|
* Settings are a handful of low-cardinality configuration rows that change
|
||||||
|
* rarely and are read constantly, so they are cached in full. Writes go through
|
||||||
|
* SettingsRepository, which updates the cache in the same call, and the cache is
|
||||||
|
* primed once at startup.
|
||||||
|
*/
|
||||||
|
|
||||||
|
let cache: Map<string, string> | null = null;
|
||||||
|
|
||||||
|
export function isSettingsCachePrimed(): boolean {
|
||||||
|
return cache !== null;
|
||||||
|
}
|
||||||
|
|
||||||
|
/** Loads the full settings table. Called once during startup. */
|
||||||
|
export function primeSettingsCache(
|
||||||
|
rows: { key: string; value: string }[],
|
||||||
|
): void {
|
||||||
|
cache = new Map(rows.map((row) => [row.key, row.value]));
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Reads a cached setting.
|
||||||
|
*
|
||||||
|
* Returns null both for "not set" and "cache not primed yet" — every caller
|
||||||
|
* already treats a missing setting as "use the default", and startup ordering
|
||||||
|
* means a read before priming should behave the same way rather than throw.
|
||||||
|
*/
|
||||||
|
export function readCachedSetting(key: string): string | null {
|
||||||
|
return cache?.get(key) ?? null;
|
||||||
|
}
|
||||||
|
|
||||||
|
/** Keeps the cache in step with a write. */
|
||||||
|
export function updateCachedSetting(key: string, value: string): void {
|
||||||
|
cache?.set(key, value);
|
||||||
|
}
|
||||||
|
|
||||||
|
export function forgetCachedSetting(key: string): void {
|
||||||
|
cache?.delete(key);
|
||||||
|
}
|
||||||
|
|
||||||
|
/** Test seam. */
|
||||||
|
export function resetSettingsCache(): void {
|
||||||
|
cache = null;
|
||||||
|
}
|
||||||
@@ -1,6 +1,8 @@
|
|||||||
import { eq, like } from "drizzle-orm";
|
import { eq, like } from "drizzle-orm";
|
||||||
import { settings } from "../db/schema.js";
|
import { settings } from "../db/schema.js";
|
||||||
import type { DatabaseContext } from "./database-context.js";
|
import type { DatabaseContext } from "./database-context.js";
|
||||||
|
import { forgetCachedSetting, updateCachedSetting } from "./settings-cache.js";
|
||||||
|
import { deleteReturning } from "./returning.js";
|
||||||
|
|
||||||
export class SettingsRepository {
|
export class SettingsRepository {
|
||||||
constructor(
|
constructor(
|
||||||
@@ -34,6 +36,9 @@ export class SettingsRepository {
|
|||||||
const existing = await this.get(key);
|
const existing = await this.get(key);
|
||||||
if (existing === null) {
|
if (existing === null) {
|
||||||
await this.context.drizzle.insert(settings).values({ key, value });
|
await this.context.drizzle.insert(settings).values({ key, value });
|
||||||
|
// Kept in step here so the synchronous readers cannot observe a stale
|
||||||
|
// value after a write in the same process.
|
||||||
|
updateCachedSetting(key, value);
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
@@ -42,6 +47,7 @@ export class SettingsRepository {
|
|||||||
.update(settings)
|
.update(settings)
|
||||||
.set({ value })
|
.set({ value })
|
||||||
.where(eq(settings.key, key));
|
.where(eq(settings.key, key));
|
||||||
|
updateCachedSetting(key, value);
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -51,14 +57,17 @@ export class SettingsRepository {
|
|||||||
|
|
||||||
async delete(key: string): Promise<void> {
|
async delete(key: string): Promise<void> {
|
||||||
await this.context.drizzle.delete(settings).where(eq(settings.key, key));
|
await this.context.drizzle.delete(settings).where(eq(settings.key, key));
|
||||||
|
forgetCachedSetting(key);
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteLike(pattern: string): Promise<number> {
|
async deleteLike(pattern: string): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const rows = await deleteReturning(
|
||||||
.delete(settings)
|
this.context,
|
||||||
.where(like(settings.key, pattern))
|
settings,
|
||||||
.returning({ key: settings.key });
|
like(settings.key, pattern),
|
||||||
|
);
|
||||||
|
for (const row of rows) forgetCachedSetting(row.key);
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return rows.length;
|
return rows.length;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -0,0 +1,102 @@
|
|||||||
|
import { and, eq } from "drizzle-orm";
|
||||||
|
import type { AuthOverrideProtocol } from "../../../types/auth-protocols.js";
|
||||||
|
import { sharedHostAuthOverrides } from "../db/schema.js";
|
||||||
|
import type { DatabaseContext } from "./database-context.js";
|
||||||
|
import { deleteReturning, upsert } from "./returning.js";
|
||||||
|
|
||||||
|
export type SharedHostAuthOverrideRecord =
|
||||||
|
typeof sharedHostAuthOverrides.$inferSelect;
|
||||||
|
|
||||||
|
export class SharedHostAuthOverrideRepository {
|
||||||
|
constructor(
|
||||||
|
private readonly context: DatabaseContext,
|
||||||
|
private readonly onWrite?: () => void | Promise<void>,
|
||||||
|
) {}
|
||||||
|
|
||||||
|
async findForHostUser(
|
||||||
|
hostId: number,
|
||||||
|
userId: string,
|
||||||
|
protocol: AuthOverrideProtocol,
|
||||||
|
): Promise<SharedHostAuthOverrideRecord | null> {
|
||||||
|
const rows = await this.context.drizzle
|
||||||
|
.select()
|
||||||
|
.from(sharedHostAuthOverrides)
|
||||||
|
.where(
|
||||||
|
and(
|
||||||
|
eq(sharedHostAuthOverrides.hostId, hostId),
|
||||||
|
eq(sharedHostAuthOverrides.userId, userId),
|
||||||
|
eq(sharedHostAuthOverrides.protocol, protocol),
|
||||||
|
),
|
||||||
|
)
|
||||||
|
.limit(1);
|
||||||
|
|
||||||
|
return rows[0] ?? null;
|
||||||
|
}
|
||||||
|
|
||||||
|
async findCredentialId(
|
||||||
|
hostId: number,
|
||||||
|
userId: string,
|
||||||
|
protocol: AuthOverrideProtocol,
|
||||||
|
): Promise<number | null> {
|
||||||
|
return (
|
||||||
|
(await this.findForHostUser(hostId, userId, protocol))?.credentialId ??
|
||||||
|
null
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
async setCredential(
|
||||||
|
hostId: number,
|
||||||
|
userId: string,
|
||||||
|
protocol: AuthOverrideProtocol,
|
||||||
|
credentialId: number,
|
||||||
|
): Promise<void> {
|
||||||
|
await upsert(
|
||||||
|
this.context,
|
||||||
|
sharedHostAuthOverrides,
|
||||||
|
{
|
||||||
|
hostId,
|
||||||
|
userId,
|
||||||
|
protocol,
|
||||||
|
credentialId,
|
||||||
|
},
|
||||||
|
{
|
||||||
|
target: [
|
||||||
|
sharedHostAuthOverrides.hostId,
|
||||||
|
sharedHostAuthOverrides.userId,
|
||||||
|
sharedHostAuthOverrides.protocol,
|
||||||
|
],
|
||||||
|
set: {
|
||||||
|
credentialId,
|
||||||
|
updatedAt: new Date().toISOString(),
|
||||||
|
},
|
||||||
|
},
|
||||||
|
);
|
||||||
|
|
||||||
|
await this.afterWrite();
|
||||||
|
}
|
||||||
|
|
||||||
|
async clearCredential(
|
||||||
|
hostId: number,
|
||||||
|
userId: string,
|
||||||
|
protocol: AuthOverrideProtocol,
|
||||||
|
): Promise<boolean> {
|
||||||
|
const rows = await deleteReturning(
|
||||||
|
this.context,
|
||||||
|
sharedHostAuthOverrides,
|
||||||
|
and(
|
||||||
|
eq(sharedHostAuthOverrides.hostId, hostId),
|
||||||
|
eq(sharedHostAuthOverrides.userId, userId),
|
||||||
|
eq(sharedHostAuthOverrides.protocol, protocol),
|
||||||
|
),
|
||||||
|
);
|
||||||
|
|
||||||
|
if (rows.length > 0) {
|
||||||
|
await this.afterWrite();
|
||||||
|
}
|
||||||
|
return rows.length > 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
private async afterWrite(): Promise<void> {
|
||||||
|
await this.onWrite?.();
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -1,6 +1,7 @@
|
|||||||
import { and, eq, inArray, or } from "drizzle-orm";
|
import { and, eq, inArray, or } from "drizzle-orm";
|
||||||
import { hostAccess, hosts, sharedHostSecrets } from "../db/schema.js";
|
import { hostAccess, hosts, sharedHostSecrets } from "../db/schema.js";
|
||||||
import type { DatabaseContext } from "./database-context.js";
|
import type { DatabaseContext } from "./database-context.js";
|
||||||
|
import { rowsAffected } from "./mutation-result.js";
|
||||||
|
|
||||||
export type SharedHostSecretRecord = typeof sharedHostSecrets.$inferSelect;
|
export type SharedHostSecretRecord = typeof sharedHostSecrets.$inferSelect;
|
||||||
export type NewSharedHostSecretRecord = typeof sharedHostSecrets.$inferInsert;
|
export type NewSharedHostSecretRecord = typeof sharedHostSecrets.$inferInsert;
|
||||||
@@ -108,16 +109,15 @@ export class SharedHostSecretsRepository {
|
|||||||
}
|
}
|
||||||
|
|
||||||
async deleteByHostAccessId(hostAccessId: number): Promise<number> {
|
async deleteByHostAccessId(hostAccessId: number): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(sharedHostSecrets)
|
.delete(sharedHostSecrets)
|
||||||
.where(eq(sharedHostSecrets.hostAccessId, hostAccessId))
|
.where(eq(sharedHostSecrets.hostAccessId, hostAccessId));
|
||||||
.returning({ id: sharedHostSecrets.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteForRoleMember(
|
async deleteForRoleMember(
|
||||||
@@ -148,29 +148,27 @@ export class SharedHostSecretsRepository {
|
|||||||
}
|
}
|
||||||
|
|
||||||
async deleteByOriginalCredentialId(credentialId: number): Promise<number> {
|
async deleteByOriginalCredentialId(credentialId: number): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(sharedHostSecrets)
|
.delete(sharedHostSecrets)
|
||||||
.where(eq(sharedHostSecrets.originalCredentialId, credentialId))
|
.where(eq(sharedHostSecrets.originalCredentialId, credentialId));
|
||||||
.returning({ id: sharedHostSecrets.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteByTargetUserId(userId: string): Promise<number> {
|
async deleteByTargetUserId(userId: string): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(sharedHostSecrets)
|
.delete(sharedHostSecrets)
|
||||||
.where(eq(sharedHostSecrets.targetUserId, userId))
|
.where(eq(sharedHostSecrets.targetUserId, userId));
|
||||||
.returning({ id: sharedHostSecrets.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
async findHostIdsReferencingCredential(
|
async findHostIdsReferencingCredential(
|
||||||
|
|||||||
@@ -2,6 +2,12 @@ import { and, asc, eq, sql } from "drizzle-orm";
|
|||||||
import { randomUUID } from "crypto";
|
import { randomUUID } from "crypto";
|
||||||
import { snippetFolders, snippets } from "../db/schema.js";
|
import { snippetFolders, snippets } from "../db/schema.js";
|
||||||
import type { DatabaseContext } from "./database-context.js";
|
import type { DatabaseContext } from "./database-context.js";
|
||||||
|
import { rowsAffected } from "./mutation-result.js";
|
||||||
|
import {
|
||||||
|
deleteReturning,
|
||||||
|
insertReturning,
|
||||||
|
updateReturning,
|
||||||
|
} from "./returning.js";
|
||||||
|
|
||||||
export type SnippetRecord = typeof snippets.$inferSelect;
|
export type SnippetRecord = typeof snippets.$inferSelect;
|
||||||
export type SnippetFolderRecord = typeof snippetFolders.$inferSelect;
|
export type SnippetFolderRecord = typeof snippetFolders.$inferSelect;
|
||||||
@@ -84,11 +90,16 @@ export class SnippetRepository {
|
|||||||
}
|
}
|
||||||
|
|
||||||
async listSnippetsForExport(userId: string): Promise<SnippetRecord[]> {
|
async listSnippetsForExport(userId: string): Promise<SnippetRecord[]> {
|
||||||
return this.context.drizzle
|
return (
|
||||||
.select()
|
this.context.drizzle
|
||||||
.from(snippets)
|
.select()
|
||||||
.where(eq(snippets.userId, userId))
|
.from(snippets)
|
||||||
.orderBy(asc(snippets.folder), asc(snippets.order));
|
.where(eq(snippets.userId, userId))
|
||||||
|
// coalesce, not asc(folder): folder is nullable, and NULLs sort first on
|
||||||
|
// SQLite and MySQL but last on Postgres. An export whose row order depends
|
||||||
|
// on the engine is not much of an export.
|
||||||
|
.orderBy(sql`coalesce(${snippets.folder}, '')`, asc(snippets.order))
|
||||||
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
async listFoldersForExport(userId: string): Promise<SnippetFolderRecord[]> {
|
async listFoldersForExport(userId: string): Promise<SnippetFolderRecord[]> {
|
||||||
@@ -149,19 +160,16 @@ export class SnippetRepository {
|
|||||||
? await this.nextOrderForFolder(userId, folderValue)
|
? await this.nextOrderForFolder(userId, folderValue)
|
||||||
: input.order;
|
: input.order;
|
||||||
|
|
||||||
const rows = await this.context.drizzle
|
const rows = await insertReturning(this.context, snippets, {
|
||||||
.insert(snippets)
|
syncId: randomUUID(),
|
||||||
.values({
|
userId,
|
||||||
syncId: randomUUID(),
|
name: input.name.trim(),
|
||||||
userId,
|
content: input.content.trim(),
|
||||||
name: input.name.trim(),
|
description: input.description?.trim() || null,
|
||||||
content: input.content.trim(),
|
folder: input.folder?.trim() || null,
|
||||||
description: input.description?.trim() || null,
|
order,
|
||||||
folder: input.folder?.trim() || null,
|
hostFilter: input.hostFilter ? JSON.stringify(input.hostFilter) : null,
|
||||||
order,
|
});
|
||||||
hostFilter: input.hostFilter ? JSON.stringify(input.hostFilter) : null,
|
|
||||||
})
|
|
||||||
.returning();
|
|
||||||
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return rows[0];
|
return rows[0];
|
||||||
@@ -200,11 +208,12 @@ export class SnippetRepository {
|
|||||||
? JSON.stringify(input.hostFilter)
|
? JSON.stringify(input.hostFilter)
|
||||||
: null;
|
: null;
|
||||||
|
|
||||||
const rows = await this.context.drizzle
|
const rows = await updateReturning(
|
||||||
.update(snippets)
|
this.context,
|
||||||
.set(updateFields)
|
snippets,
|
||||||
.where(and(eq(snippets.id, snippetId), eq(snippets.userId, userId)))
|
updateFields,
|
||||||
.returning();
|
and(eq(snippets.id, snippetId), eq(snippets.userId, userId)),
|
||||||
|
);
|
||||||
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return { existing, updated: rows[0] };
|
return { existing, updated: rows[0] };
|
||||||
@@ -229,23 +238,21 @@ export class SnippetRepository {
|
|||||||
snippetsDeleted: number;
|
snippetsDeleted: number;
|
||||||
foldersDeleted: number;
|
foldersDeleted: number;
|
||||||
}> {
|
}> {
|
||||||
const deletedSnippets = await this.context.drizzle
|
const snippetResult = await this.context.drizzle
|
||||||
.delete(snippets)
|
.delete(snippets)
|
||||||
.where(eq(snippets.userId, userId))
|
.where(eq(snippets.userId, userId));
|
||||||
.returning({ id: snippets.id });
|
|
||||||
|
|
||||||
const deletedFolders = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(snippetFolders)
|
.delete(snippetFolders)
|
||||||
.where(eq(snippetFolders.userId, userId))
|
.where(eq(snippetFolders.userId, userId));
|
||||||
.returning({ id: snippetFolders.id });
|
|
||||||
|
|
||||||
if (deletedSnippets.length > 0 || deletedFolders.length > 0) {
|
if (rowsAffected(snippetResult) > 0 || rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return {
|
return {
|
||||||
snippetsDeleted: deletedSnippets.length,
|
snippetsDeleted: rowsAffected(snippetResult),
|
||||||
foldersDeleted: deletedFolders.length,
|
foldersDeleted: rowsAffected(result),
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -377,16 +384,13 @@ export class SnippetRepository {
|
|||||||
const existing = await this.findFolderByName(userId, name);
|
const existing = await this.findFolderByName(userId, name);
|
||||||
if (existing) return null;
|
if (existing) return null;
|
||||||
|
|
||||||
const rows = await this.context.drizzle
|
const rows = await insertReturning(this.context, snippetFolders, {
|
||||||
.insert(snippetFolders)
|
syncId: randomUUID(),
|
||||||
.values({
|
userId,
|
||||||
syncId: randomUUID(),
|
name: name.trim(),
|
||||||
userId,
|
color: color?.trim() || null,
|
||||||
name: name.trim(),
|
icon: icon?.trim() || null,
|
||||||
color: color?.trim() || null,
|
});
|
||||||
icon: icon?.trim() || null,
|
|
||||||
})
|
|
||||||
.returning();
|
|
||||||
|
|
||||||
if (triggerSave) {
|
if (triggerSave) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
@@ -414,13 +418,12 @@ export class SnippetRepository {
|
|||||||
if (color !== undefined) updateFields.color = color?.trim() || null;
|
if (color !== undefined) updateFields.color = color?.trim() || null;
|
||||||
if (icon !== undefined) updateFields.icon = icon?.trim() || null;
|
if (icon !== undefined) updateFields.icon = icon?.trim() || null;
|
||||||
|
|
||||||
const rows = await this.context.drizzle
|
const rows = await updateReturning(
|
||||||
.update(snippetFolders)
|
this.context,
|
||||||
.set(updateFields)
|
snippetFolders,
|
||||||
.where(
|
updateFields,
|
||||||
and(eq(snippetFolders.userId, userId), eq(snippetFolders.name, name)),
|
and(eq(snippetFolders.userId, userId), eq(snippetFolders.name, name)),
|
||||||
)
|
);
|
||||||
.returning();
|
|
||||||
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return rows[0] ?? null;
|
return rows[0] ?? null;
|
||||||
@@ -465,15 +468,14 @@ export class SnippetRepository {
|
|||||||
.set({ folder: null })
|
.set({ folder: null })
|
||||||
.where(and(eq(snippets.userId, userId), eq(snippets.folder, name)));
|
.where(and(eq(snippets.userId, userId), eq(snippets.folder, name)));
|
||||||
|
|
||||||
const rows = await this.context.drizzle
|
const rows = await deleteReturning(
|
||||||
.delete(snippetFolders)
|
this.context,
|
||||||
.where(
|
snippetFolders,
|
||||||
and(eq(snippetFolders.userId, userId), eq(snippetFolders.name, name)),
|
and(eq(snippetFolders.userId, userId), eq(snippetFolders.name, name)),
|
||||||
)
|
);
|
||||||
.returning({ syncId: snippetFolders.syncId });
|
|
||||||
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return rows[0] ?? null;
|
return rows[0] ? { syncId: rows[0].syncId } : null;
|
||||||
}
|
}
|
||||||
|
|
||||||
private async findFolderByName(
|
private async findFolderByName(
|
||||||
|
|||||||
@@ -0,0 +1,20 @@
|
|||||||
|
/**
|
||||||
|
* Timestamp columns are stored as text defaulting to `CURRENT_TIMESTAMP`, which
|
||||||
|
* every supported engine writes as `YYYY-MM-DD HH:MM:SS` in UTC. That format
|
||||||
|
* sorts lexicographically in time order, so retention cutoffs can be plain
|
||||||
|
* string comparisons.
|
||||||
|
*
|
||||||
|
* Computing the cutoff here rather than with `datetime('now', ?)` keeps the
|
||||||
|
* queries free of engine-specific date functions.
|
||||||
|
*/
|
||||||
|
export function sqlTimestampDaysAgo(
|
||||||
|
days: number,
|
||||||
|
now: Date = new Date(),
|
||||||
|
): string {
|
||||||
|
const cutoff = new Date(now.getTime() - days * 24 * 60 * 60 * 1000);
|
||||||
|
return formatSqlTimestamp(cutoff);
|
||||||
|
}
|
||||||
|
|
||||||
|
export function formatSqlTimestamp(date: Date): string {
|
||||||
|
return date.toISOString().slice(0, 19).replace("T", " ");
|
||||||
|
}
|
||||||
@@ -1,4 +1,5 @@
|
|||||||
import { getCurrentRepositorySqlite } from "./factory.js";
|
import { getCurrentRepositorySqlite } from "./factory.js";
|
||||||
|
import { needsExplicitPersist, resolveDatabaseDialect } from "../db/dialect.js";
|
||||||
|
|
||||||
export interface SqliteForeignKeyClient {
|
export interface SqliteForeignKeyClient {
|
||||||
exec(sql: string): unknown;
|
exec(sql: string): unknown;
|
||||||
@@ -16,8 +17,28 @@ export async function withSqliteForeignKeysDisabled<T>(
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Runs a bulk import with foreign keys relaxed.
|
||||||
|
*
|
||||||
|
* Backup restore writes tables in an order that is not dependency-safe, so the
|
||||||
|
* constraints have to stand down for the duration.
|
||||||
|
*
|
||||||
|
* **This has no equivalent on Postgres or MySQL here.** Postgres needs
|
||||||
|
* superuser to disable triggers, and MySQL's `SET FOREIGN_KEY_CHECKS = 0` is
|
||||||
|
* per-connection, which a pool does not guarantee. Rather than run the import
|
||||||
|
* with constraints enforced and have it fail partway through — leaving a
|
||||||
|
* half-restored database — it refuses with a message that says why.
|
||||||
|
*/
|
||||||
export async function withCurrentSqliteForeignKeysDisabled<T>(
|
export async function withCurrentSqliteForeignKeysDisabled<T>(
|
||||||
operation: () => Promise<T>,
|
operation: () => Promise<T>,
|
||||||
): Promise<T> {
|
): Promise<T> {
|
||||||
|
const dialect = resolveDatabaseDialect();
|
||||||
|
if (!needsExplicitPersist(dialect)) {
|
||||||
|
throw new Error(
|
||||||
|
`Importing a backup is only supported on SQLite; this deployment uses ${dialect}. ` +
|
||||||
|
`Restore into the database directly with its own tooling instead.`,
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
return withSqliteForeignKeysDisabled(getCurrentRepositorySqlite(), operation);
|
return withSqliteForeignKeysDisabled(getCurrentRepositorySqlite(), operation);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,6 +1,8 @@
|
|||||||
import { eq, inArray } from "drizzle-orm";
|
import { eq, inArray } from "drizzle-orm";
|
||||||
import { sshCredentialUsage } from "../db/schema.js";
|
import { sshCredentialUsage } from "../db/schema.js";
|
||||||
import type { DatabaseContext } from "./database-context.js";
|
import type { DatabaseContext } from "./database-context.js";
|
||||||
|
import { rowsAffected } from "./mutation-result.js";
|
||||||
|
import { insertReturning } from "./returning.js";
|
||||||
|
|
||||||
export type SshCredentialUsageRecord = typeof sshCredentialUsage.$inferSelect;
|
export type SshCredentialUsageRecord = typeof sshCredentialUsage.$inferSelect;
|
||||||
|
|
||||||
@@ -22,38 +24,37 @@ export class SshCredentialUsageRepository {
|
|||||||
hostId: number,
|
hostId: number,
|
||||||
userId: string,
|
userId: string,
|
||||||
): Promise<SshCredentialUsageRecord> {
|
): Promise<SshCredentialUsageRecord> {
|
||||||
const [created] = await this.context.drizzle
|
const [created] = await insertReturning(this.context, sshCredentialUsage, {
|
||||||
.insert(sshCredentialUsage)
|
credentialId,
|
||||||
.values({ credentialId, hostId, userId })
|
hostId,
|
||||||
.returning();
|
userId,
|
||||||
|
});
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return created;
|
return created;
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteByUserId(userId: string): Promise<number> {
|
async deleteByUserId(userId: string): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(sshCredentialUsage)
|
.delete(sshCredentialUsage)
|
||||||
.where(eq(sshCredentialUsage.userId, userId))
|
.where(eq(sshCredentialUsage.userId, userId));
|
||||||
.returning({ id: sshCredentialUsage.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteByHostId(hostId: number): Promise<number> {
|
async deleteByHostId(hostId: number): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(sshCredentialUsage)
|
.delete(sshCredentialUsage)
|
||||||
.where(eq(sshCredentialUsage.hostId, hostId))
|
.where(eq(sshCredentialUsage.hostId, hostId));
|
||||||
.returning({ id: sshCredentialUsage.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteByHostIds(hostIds: number[]): Promise<number> {
|
async deleteByHostIds(hostIds: number[]): Promise<number> {
|
||||||
@@ -61,16 +62,15 @@ export class SshCredentialUsageRepository {
|
|||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(sshCredentialUsage)
|
.delete(sshCredentialUsage)
|
||||||
.where(inArray(sshCredentialUsage.hostId, hostIds))
|
.where(inArray(sshCredentialUsage.hostId, hostIds));
|
||||||
.returning({ id: sshCredentialUsage.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
private async afterWrite(): Promise<void> {
|
private async afterWrite(): Promise<void> {
|
||||||
|
|||||||
@@ -1,6 +1,8 @@
|
|||||||
import { asc, eq } from "drizzle-orm";
|
import { asc, eq } from "drizzle-orm";
|
||||||
import { ssoProviders, users } from "../db/schema.js";
|
import { ssoProviders, users } from "../db/schema.js";
|
||||||
import type { DatabaseContext } from "./database-context.js";
|
import type { DatabaseContext } from "./database-context.js";
|
||||||
|
import { rowsAffected } from "./mutation-result.js";
|
||||||
|
import { insertReturning, updateReturning } from "./returning.js";
|
||||||
|
|
||||||
export type SsoProviderRecord = typeof ssoProviders.$inferSelect;
|
export type SsoProviderRecord = typeof ssoProviders.$inferSelect;
|
||||||
export type NewSsoProviderRecord = typeof ssoProviders.$inferInsert;
|
export type NewSsoProviderRecord = typeof ssoProviders.$inferInsert;
|
||||||
@@ -76,10 +78,7 @@ export class SsoProviderRepository {
|
|||||||
}
|
}
|
||||||
|
|
||||||
async create(provider: NewSsoProviderRecord): Promise<SsoProviderRecord> {
|
async create(provider: NewSsoProviderRecord): Promise<SsoProviderRecord> {
|
||||||
const rows = await this.context.drizzle
|
const rows = await insertReturning(this.context, ssoProviders, provider);
|
||||||
.insert(ssoProviders)
|
|
||||||
.values(provider)
|
|
||||||
.returning();
|
|
||||||
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return rows[0];
|
return rows[0];
|
||||||
@@ -89,27 +88,27 @@ export class SsoProviderRepository {
|
|||||||
id: number,
|
id: number,
|
||||||
update: SsoProviderUpdate,
|
update: SsoProviderUpdate,
|
||||||
): Promise<SsoProviderRecord | null> {
|
): Promise<SsoProviderRecord | null> {
|
||||||
const rows = await this.context.drizzle
|
const rows = await updateReturning(
|
||||||
.update(ssoProviders)
|
this.context,
|
||||||
.set(update)
|
ssoProviders,
|
||||||
.where(eq(ssoProviders.id, id))
|
update,
|
||||||
.returning();
|
eq(ssoProviders.id, id),
|
||||||
|
);
|
||||||
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return rows[0] ?? null;
|
return rows[0] ?? null;
|
||||||
}
|
}
|
||||||
|
|
||||||
async delete(id: number): Promise<boolean> {
|
async delete(id: number): Promise<boolean> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(ssoProviders)
|
.delete(ssoProviders)
|
||||||
.where(eq(ssoProviders.id, id))
|
.where(eq(ssoProviders.id, id));
|
||||||
.returning({ id: ssoProviders.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length > 0;
|
return rowsAffected(result) > 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
async countUsersByProviderId(providerId: number): Promise<number> {
|
async countUsersByProviderId(providerId: number): Promise<number> {
|
||||||
|
|||||||
@@ -1,5 +1,6 @@
|
|||||||
import { and, eq, gt } from "drizzle-orm";
|
import { and, eq } from "drizzle-orm";
|
||||||
import { syncTombstones } from "../db/schema.js";
|
import { syncTombstones } from "../db/schema.js";
|
||||||
|
import { timestampAtOrAfter } from "../sync-timestamp.js";
|
||||||
import type { DatabaseContext } from "./database-context.js";
|
import type { DatabaseContext } from "./database-context.js";
|
||||||
|
|
||||||
export type SyncTombstoneRecord = typeof syncTombstones.$inferSelect;
|
export type SyncTombstoneRecord = typeof syncTombstones.$inferSelect;
|
||||||
@@ -12,7 +13,8 @@ export type SyncEntityType =
|
|||||||
| "snippetFolders"
|
| "snippetFolders"
|
||||||
| "vaultProfiles"
|
| "vaultProfiles"
|
||||||
| "dashboardServiceLinks"
|
| "dashboardServiceLinks"
|
||||||
| "homepageItems";
|
| "homepageItems"
|
||||||
|
| "userPreferences";
|
||||||
|
|
||||||
export class SyncTombstoneRepository {
|
export class SyncTombstoneRepository {
|
||||||
constructor(
|
constructor(
|
||||||
@@ -56,7 +58,8 @@ export class SyncTombstoneRepository {
|
|||||||
eq(syncTombstones.userId, userId),
|
eq(syncTombstones.userId, userId),
|
||||||
eq(syncTombstones.entityType, entityType),
|
eq(syncTombstones.entityType, entityType),
|
||||||
];
|
];
|
||||||
if (since) conditions.push(gt(syncTombstones.deletedAt, since));
|
if (since)
|
||||||
|
conditions.push(timestampAtOrAfter(syncTombstones.deletedAt, since));
|
||||||
|
|
||||||
return this.context.drizzle
|
return this.context.drizzle
|
||||||
.select()
|
.select()
|
||||||
|
|||||||
@@ -2,6 +2,12 @@ import { eq } from "drizzle-orm";
|
|||||||
import { termixIdentityCa } from "../db/schema.js";
|
import { termixIdentityCa } from "../db/schema.js";
|
||||||
import type { DatabaseContext } from "./database-context.js";
|
import type { DatabaseContext } from "./database-context.js";
|
||||||
import { DataCrypto } from "../../utils/data-crypto.js";
|
import { DataCrypto } from "../../utils/data-crypto.js";
|
||||||
|
import {
|
||||||
|
insertedId,
|
||||||
|
rowsAffected,
|
||||||
|
supportsReturning,
|
||||||
|
} from "./mutation-result.js";
|
||||||
|
import { updateReturning } from "./returning.js";
|
||||||
|
|
||||||
export type TermixIdentityCaRecord = typeof termixIdentityCa.$inferSelect;
|
export type TermixIdentityCaRecord = typeof termixIdentityCa.$inferSelect;
|
||||||
export type NewTermixIdentityCaRecord = typeof termixIdentityCa.$inferInsert;
|
export type NewTermixIdentityCaRecord = typeof termixIdentityCa.$inferInsert;
|
||||||
@@ -54,27 +60,7 @@ export class TermixIdentityCaRepository {
|
|||||||
ca: NewTermixIdentityCaRecord,
|
ca: NewTermixIdentityCaRecord,
|
||||||
): Promise<TermixIdentityCaRecord> {
|
): Promise<TermixIdentityCaRecord> {
|
||||||
const userDataKey = DataCrypto.validateUserAccess(userId);
|
const userDataKey = DataCrypto.validateUserAccess(userId);
|
||||||
const result = this.context.drizzle.transaction((tx) => {
|
const result = await this.insertThenEncrypt(userId, ca, userDataKey);
|
||||||
const inserted = tx
|
|
||||||
.insert(termixIdentityCa)
|
|
||||||
.values({ ...ca, privateKey: "" })
|
|
||||||
.returning()
|
|
||||||
.all();
|
|
||||||
const row = inserted[0];
|
|
||||||
const encrypted = DataCrypto.encryptRecord(
|
|
||||||
"termix_identity_ca",
|
|
||||||
{ id: row.id, privateKey: ca.privateKey },
|
|
||||||
userId,
|
|
||||||
userDataKey,
|
|
||||||
);
|
|
||||||
|
|
||||||
return tx
|
|
||||||
.update(termixIdentityCa)
|
|
||||||
.set({ privateKey: encrypted.privateKey })
|
|
||||||
.where(eq(termixIdentityCa.id, row.id))
|
|
||||||
.returning()
|
|
||||||
.all()[0];
|
|
||||||
});
|
|
||||||
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return DataCrypto.decryptRecord(
|
return DataCrypto.decryptRecord(
|
||||||
@@ -85,6 +71,81 @@ export class TermixIdentityCaRepository {
|
|||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Writes a CA in two steps, because the ciphertext depends on the id.
|
||||||
|
*
|
||||||
|
* The private key is encrypted with the row's own id as context, which does
|
||||||
|
* not exist until the row does. So: insert with an empty key, encrypt, update.
|
||||||
|
* The empty key must never be observable, hence the transaction.
|
||||||
|
*
|
||||||
|
* Two branches because better-sqlite3 rejects an async transaction callback —
|
||||||
|
* see the same note in UserRepository.
|
||||||
|
*/
|
||||||
|
private async insertThenEncrypt(
|
||||||
|
userId: string,
|
||||||
|
ca: NewTermixIdentityCaRecord,
|
||||||
|
userDataKey: Buffer,
|
||||||
|
): Promise<TermixIdentityCaRecord> {
|
||||||
|
const draft = { ...ca, privateKey: "" };
|
||||||
|
|
||||||
|
const seal = (id: number) =>
|
||||||
|
DataCrypto.encryptRecord(
|
||||||
|
"termix_identity_ca",
|
||||||
|
{ id, privateKey: ca.privateKey },
|
||||||
|
userId,
|
||||||
|
userDataKey,
|
||||||
|
).privateKey;
|
||||||
|
|
||||||
|
if (this.context.dialect === "sqlite") {
|
||||||
|
/* eslint-disable no-restricted-syntax -- sqlite-only branch: the dialect
|
||||||
|
is checked directly above, and better-sqlite3 needs the synchronous
|
||||||
|
.all() form, which has no async equivalent. */
|
||||||
|
return this.context.drizzle.transaction((tx) => {
|
||||||
|
const row = tx
|
||||||
|
.insert(termixIdentityCa)
|
||||||
|
.values(draft)
|
||||||
|
.returning()
|
||||||
|
.all()[0];
|
||||||
|
return tx
|
||||||
|
.update(termixIdentityCa)
|
||||||
|
.set({ privateKey: seal(row.id) })
|
||||||
|
.where(eq(termixIdentityCa.id, row.id))
|
||||||
|
.returning()
|
||||||
|
.all()[0];
|
||||||
|
});
|
||||||
|
/* eslint-enable no-restricted-syntax */
|
||||||
|
}
|
||||||
|
|
||||||
|
return this.context.drizzle.transaction(async (tx) => {
|
||||||
|
let id: number | null;
|
||||||
|
if (supportsReturning(this.context.dialect)) {
|
||||||
|
// eslint-disable-next-line no-restricted-syntax -- guarded by the check above
|
||||||
|
const rows = await tx
|
||||||
|
.insert(termixIdentityCa)
|
||||||
|
.values(draft)
|
||||||
|
.returning();
|
||||||
|
id = rows[0]?.id ?? null;
|
||||||
|
} else {
|
||||||
|
id = insertedId(await tx.insert(termixIdentityCa).values(draft));
|
||||||
|
}
|
||||||
|
|
||||||
|
if (id === null) {
|
||||||
|
throw new Error("Insert into termix_identity_ca returned no id.");
|
||||||
|
}
|
||||||
|
|
||||||
|
await tx
|
||||||
|
.update(termixIdentityCa)
|
||||||
|
.set({ privateKey: seal(id) })
|
||||||
|
.where(eq(termixIdentityCa.id, id));
|
||||||
|
|
||||||
|
const [row] = await tx
|
||||||
|
.select()
|
||||||
|
.from(termixIdentityCa)
|
||||||
|
.where(eq(termixIdentityCa.id, id));
|
||||||
|
return row;
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
async updateEncryptedForIdentity(
|
async updateEncryptedForIdentity(
|
||||||
userId: string,
|
userId: string,
|
||||||
identityId: number,
|
identityId: number,
|
||||||
@@ -103,43 +164,42 @@ export class TermixIdentityCaRepository {
|
|||||||
).privateKey
|
).privateKey
|
||||||
: undefined;
|
: undefined;
|
||||||
|
|
||||||
const rows = await this.context.drizzle
|
const rows = await updateReturning(
|
||||||
.update(termixIdentityCa)
|
this.context,
|
||||||
.set({
|
termixIdentityCa,
|
||||||
|
{
|
||||||
...update,
|
...update,
|
||||||
...(encryptedPrivateKey ? { privateKey: encryptedPrivateKey } : {}),
|
...(encryptedPrivateKey ? { privateKey: encryptedPrivateKey } : {}),
|
||||||
})
|
},
|
||||||
.where(eq(termixIdentityCa.identityId, identityId))
|
eq(termixIdentityCa.identityId, identityId),
|
||||||
.returning();
|
);
|
||||||
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return this.decryptOne(rows[0] ?? null, userId);
|
return this.decryptOne(rows[0] ?? null, userId);
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteByIdentityId(identityId: number): Promise<boolean> {
|
async deleteByIdentityId(identityId: number): Promise<boolean> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(termixIdentityCa)
|
.delete(termixIdentityCa)
|
||||||
.where(eq(termixIdentityCa.identityId, identityId))
|
.where(eq(termixIdentityCa.identityId, identityId));
|
||||||
.returning({ id: termixIdentityCa.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length > 0;
|
return rowsAffected(result) > 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteByUserId(userId: string): Promise<number> {
|
async deleteByUserId(userId: string): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(termixIdentityCa)
|
.delete(termixIdentityCa)
|
||||||
.where(eq(termixIdentityCa.userId, userId))
|
.where(eq(termixIdentityCa.userId, userId));
|
||||||
.returning({ id: termixIdentityCa.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
private decryptOne<T extends Record<string, unknown>>(
|
private decryptOne<T extends Record<string, unknown>>(
|
||||||
|
|||||||
@@ -1,6 +1,8 @@
|
|||||||
import { and, asc, eq } from "drizzle-orm";
|
import { and, asc, eq } from "drizzle-orm";
|
||||||
import { termixIdentities, termixIdentityKeys } from "../db/schema.js";
|
import { termixIdentities, termixIdentityKeys } from "../db/schema.js";
|
||||||
import type { DatabaseContext } from "./database-context.js";
|
import type { DatabaseContext } from "./database-context.js";
|
||||||
|
import { rowsAffected } from "./mutation-result.js";
|
||||||
|
import { insertReturning, updateReturning } from "./returning.js";
|
||||||
|
|
||||||
export type TermixIdentityRecord = typeof termixIdentities.$inferSelect;
|
export type TermixIdentityRecord = typeof termixIdentities.$inferSelect;
|
||||||
export type NewTermixIdentityRecord = typeof termixIdentities.$inferInsert;
|
export type NewTermixIdentityRecord = typeof termixIdentities.$inferInsert;
|
||||||
@@ -57,10 +59,11 @@ export class TermixIdentityRepository {
|
|||||||
async createIdentity(
|
async createIdentity(
|
||||||
identity: NewTermixIdentityRecord,
|
identity: NewTermixIdentityRecord,
|
||||||
): Promise<TermixIdentityRecord> {
|
): Promise<TermixIdentityRecord> {
|
||||||
const rows = await this.context.drizzle
|
const rows = await insertReturning(
|
||||||
.insert(termixIdentities)
|
this.context,
|
||||||
.values(identity)
|
termixIdentities,
|
||||||
.returning();
|
identity,
|
||||||
|
);
|
||||||
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return rows[0];
|
return rows[0];
|
||||||
@@ -70,11 +73,12 @@ export class TermixIdentityRepository {
|
|||||||
userId: string,
|
userId: string,
|
||||||
update: TermixIdentityUpdate,
|
update: TermixIdentityUpdate,
|
||||||
): Promise<TermixIdentityRecord | null> {
|
): Promise<TermixIdentityRecord | null> {
|
||||||
const rows = await this.context.drizzle
|
const rows = await updateReturning(
|
||||||
.update(termixIdentities)
|
this.context,
|
||||||
.set(update)
|
termixIdentities,
|
||||||
.where(eq(termixIdentities.userId, userId))
|
update,
|
||||||
.returning();
|
eq(termixIdentities.userId, userId),
|
||||||
|
);
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rows.length > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
@@ -84,39 +88,36 @@ export class TermixIdentityRepository {
|
|||||||
}
|
}
|
||||||
|
|
||||||
async deleteIdentityForUser(userId: string): Promise<boolean> {
|
async deleteIdentityForUser(userId: string): Promise<boolean> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(termixIdentities)
|
.delete(termixIdentities)
|
||||||
.where(eq(termixIdentities.userId, userId))
|
.where(eq(termixIdentities.userId, userId));
|
||||||
.returning({ id: termixIdentities.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length > 0;
|
return rowsAffected(result) > 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteByUserId(userId: string): Promise<{
|
async deleteByUserId(userId: string): Promise<{
|
||||||
identitiesDeleted: number;
|
identitiesDeleted: number;
|
||||||
keysDeleted: number;
|
keysDeleted: number;
|
||||||
}> {
|
}> {
|
||||||
const keyRows = await this.context.drizzle
|
const keyResult = await this.context.drizzle
|
||||||
.delete(termixIdentityKeys)
|
.delete(termixIdentityKeys)
|
||||||
.where(eq(termixIdentityKeys.userId, userId))
|
.where(eq(termixIdentityKeys.userId, userId));
|
||||||
.returning({ id: termixIdentityKeys.id });
|
|
||||||
|
|
||||||
const identityRows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(termixIdentities)
|
.delete(termixIdentities)
|
||||||
.where(eq(termixIdentities.userId, userId))
|
.where(eq(termixIdentities.userId, userId));
|
||||||
.returning({ id: termixIdentities.id });
|
|
||||||
|
|
||||||
if (keyRows.length > 0 || identityRows.length > 0) {
|
if (rowsAffected(keyResult) > 0 || rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return {
|
return {
|
||||||
identitiesDeleted: identityRows.length,
|
identitiesDeleted: rowsAffected(result),
|
||||||
keysDeleted: keyRows.length,
|
keysDeleted: rowsAffected(keyResult),
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -170,10 +171,7 @@ export class TermixIdentityRepository {
|
|||||||
async createKey(
|
async createKey(
|
||||||
key: NewTermixIdentityKeyRecord,
|
key: NewTermixIdentityKeyRecord,
|
||||||
): Promise<TermixIdentityKeyRecord> {
|
): Promise<TermixIdentityKeyRecord> {
|
||||||
const rows = await this.context.drizzle
|
const rows = await insertReturning(this.context, termixIdentityKeys, key);
|
||||||
.insert(termixIdentityKeys)
|
|
||||||
.values(key)
|
|
||||||
.returning();
|
|
||||||
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return rows[0];
|
return rows[0];
|
||||||
@@ -184,16 +182,12 @@ export class TermixIdentityRepository {
|
|||||||
id: number,
|
id: number,
|
||||||
update: TermixIdentityKeyUpdate,
|
update: TermixIdentityKeyUpdate,
|
||||||
): Promise<TermixIdentityKeyRecord | null> {
|
): Promise<TermixIdentityKeyRecord | null> {
|
||||||
const rows = await this.context.drizzle
|
const rows = await updateReturning(
|
||||||
.update(termixIdentityKeys)
|
this.context,
|
||||||
.set(update)
|
termixIdentityKeys,
|
||||||
.where(
|
update,
|
||||||
and(
|
and(eq(termixIdentityKeys.id, id), eq(termixIdentityKeys.userId, userId)),
|
||||||
eq(termixIdentityKeys.id, id),
|
);
|
||||||
eq(termixIdentityKeys.userId, userId),
|
|
||||||
),
|
|
||||||
)
|
|
||||||
.returning();
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rows.length > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
@@ -203,21 +197,20 @@ export class TermixIdentityRepository {
|
|||||||
}
|
}
|
||||||
|
|
||||||
async deleteKeyForUser(userId: string, id: number): Promise<boolean> {
|
async deleteKeyForUser(userId: string, id: number): Promise<boolean> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(termixIdentityKeys)
|
.delete(termixIdentityKeys)
|
||||||
.where(
|
.where(
|
||||||
and(
|
and(
|
||||||
eq(termixIdentityKeys.id, id),
|
eq(termixIdentityKeys.id, id),
|
||||||
eq(termixIdentityKeys.userId, userId),
|
eq(termixIdentityKeys.userId, userId),
|
||||||
),
|
),
|
||||||
)
|
);
|
||||||
.returning({ id: termixIdentityKeys.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length > 0;
|
return rowsAffected(result) > 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
async findKeyForUser(
|
async findKeyForUser(
|
||||||
|
|||||||
@@ -1,6 +1,7 @@
|
|||||||
import { and, eq } from "drizzle-orm";
|
import { and, eq } from "drizzle-orm";
|
||||||
import { tmuxSessionTags } from "../db/schema.js";
|
import { tmuxSessionTags } from "../db/schema.js";
|
||||||
import type { DatabaseContext } from "./database-context.js";
|
import type { DatabaseContext } from "./database-context.js";
|
||||||
|
import { rowsAffected } from "./mutation-result.js";
|
||||||
|
|
||||||
export type TmuxSessionTagRecord = typeof tmuxSessionTags.$inferSelect;
|
export type TmuxSessionTagRecord = typeof tmuxSessionTags.$inferSelect;
|
||||||
|
|
||||||
@@ -45,7 +46,7 @@ export class TmuxSessionTagRepository {
|
|||||||
sessionName: string,
|
sessionName: string,
|
||||||
newSessionName: string,
|
newSessionName: string,
|
||||||
): Promise<number> {
|
): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.update(tmuxSessionTags)
|
.update(tmuxSessionTags)
|
||||||
.set({ sessionName: newSessionName })
|
.set({ sessionName: newSessionName })
|
||||||
.where(
|
.where(
|
||||||
@@ -53,35 +54,33 @@ export class TmuxSessionTagRepository {
|
|||||||
eq(tmuxSessionTags.hostId, hostId),
|
eq(tmuxSessionTags.hostId, hostId),
|
||||||
eq(tmuxSessionTags.sessionName, sessionName),
|
eq(tmuxSessionTags.sessionName, sessionName),
|
||||||
),
|
),
|
||||||
)
|
);
|
||||||
.returning({ id: tmuxSessionTags.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteSessionForHost(
|
async deleteSessionForHost(
|
||||||
hostId: number,
|
hostId: number,
|
||||||
sessionName: string,
|
sessionName: string,
|
||||||
): Promise<number> {
|
): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(tmuxSessionTags)
|
.delete(tmuxSessionTags)
|
||||||
.where(
|
.where(
|
||||||
and(
|
and(
|
||||||
eq(tmuxSessionTags.hostId, hostId),
|
eq(tmuxSessionTags.hostId, hostId),
|
||||||
eq(tmuxSessionTags.sessionName, sessionName),
|
eq(tmuxSessionTags.sessionName, sessionName),
|
||||||
),
|
),
|
||||||
)
|
);
|
||||||
.returning({ id: tmuxSessionTags.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
async replaceForUserHostSession(
|
async replaceForUserHostSession(
|
||||||
@@ -90,7 +89,7 @@ export class TmuxSessionTagRepository {
|
|||||||
sessionName: string,
|
sessionName: string,
|
||||||
tags: string[],
|
tags: string[],
|
||||||
): Promise<number> {
|
): Promise<number> {
|
||||||
const deletedRows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(tmuxSessionTags)
|
.delete(tmuxSessionTags)
|
||||||
.where(
|
.where(
|
||||||
and(
|
and(
|
||||||
@@ -98,8 +97,7 @@ export class TmuxSessionTagRepository {
|
|||||||
eq(tmuxSessionTags.hostId, hostId),
|
eq(tmuxSessionTags.hostId, hostId),
|
||||||
eq(tmuxSessionTags.sessionName, sessionName),
|
eq(tmuxSessionTags.sessionName, sessionName),
|
||||||
),
|
),
|
||||||
)
|
);
|
||||||
.returning({ id: tmuxSessionTags.id });
|
|
||||||
|
|
||||||
if (tags.length > 0) {
|
if (tags.length > 0) {
|
||||||
await this.context.drizzle.insert(tmuxSessionTags).values(
|
await this.context.drizzle.insert(tmuxSessionTags).values(
|
||||||
@@ -112,7 +110,7 @@ export class TmuxSessionTagRepository {
|
|||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
const changedRows = deletedRows.length + tags.length;
|
const changedRows = rowsAffected(result) + tags.length;
|
||||||
if (changedRows > 0) {
|
if (changedRows > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
@@ -121,16 +119,15 @@ export class TmuxSessionTagRepository {
|
|||||||
}
|
}
|
||||||
|
|
||||||
async deleteByUserId(userId: string): Promise<number> {
|
async deleteByUserId(userId: string): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(tmuxSessionTags)
|
.delete(tmuxSessionTags)
|
||||||
.where(eq(tmuxSessionTags.userId, userId))
|
.where(eq(tmuxSessionTags.userId, userId));
|
||||||
.returning({ id: tmuxSessionTags.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
private async afterWrite(): Promise<void> {
|
private async afterWrite(): Promise<void> {
|
||||||
|
|||||||
@@ -1,6 +1,7 @@
|
|||||||
import { and, desc, eq, inArray, or } from "drizzle-orm";
|
import { and, desc, eq, inArray, or } from "drizzle-orm";
|
||||||
import { transferRecent } from "../db/schema.js";
|
import { transferRecent } from "../db/schema.js";
|
||||||
import type { DatabaseContext } from "./database-context.js";
|
import type { DatabaseContext } from "./database-context.js";
|
||||||
|
import { rowsAffected } from "./mutation-result.js";
|
||||||
|
|
||||||
export type TransferRecentRecord = typeof transferRecent.$inferSelect;
|
export type TransferRecentRecord = typeof transferRecent.$inferSelect;
|
||||||
|
|
||||||
@@ -100,47 +101,44 @@ export class TransferRecentRepository {
|
|||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
const deleted = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(transferRecent)
|
.delete(transferRecent)
|
||||||
.where(inArray(transferRecent.id, idsToDelete))
|
.where(inArray(transferRecent.id, idsToDelete));
|
||||||
.returning({ id: transferRecent.id });
|
|
||||||
|
|
||||||
if (deleted.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return deleted.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteByUserId(userId: string): Promise<number> {
|
async deleteByUserId(userId: string): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(transferRecent)
|
.delete(transferRecent)
|
||||||
.where(eq(transferRecent.userId, userId))
|
.where(eq(transferRecent.userId, userId));
|
||||||
.returning({ id: transferRecent.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteByHostId(hostId: number): Promise<number> {
|
async deleteByHostId(hostId: number): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(transferRecent)
|
.delete(transferRecent)
|
||||||
.where(
|
.where(
|
||||||
or(
|
or(
|
||||||
eq(transferRecent.sourceHostId, hostId),
|
eq(transferRecent.sourceHostId, hostId),
|
||||||
eq(transferRecent.destHostId, hostId),
|
eq(transferRecent.destHostId, hostId),
|
||||||
),
|
),
|
||||||
)
|
);
|
||||||
.returning({ id: transferRecent.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteByHostIds(hostIds: number[]): Promise<number> {
|
async deleteByHostIds(hostIds: number[]): Promise<number> {
|
||||||
@@ -148,21 +146,20 @@ export class TransferRecentRepository {
|
|||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(transferRecent)
|
.delete(transferRecent)
|
||||||
.where(
|
.where(
|
||||||
or(
|
or(
|
||||||
inArray(transferRecent.sourceHostId, hostIds),
|
inArray(transferRecent.sourceHostId, hostIds),
|
||||||
inArray(transferRecent.destHostId, hostIds),
|
inArray(transferRecent.destHostId, hostIds),
|
||||||
),
|
),
|
||||||
)
|
);
|
||||||
.returning({ id: transferRecent.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
private async afterWrite(): Promise<void> {
|
private async afterWrite(): Promise<void> {
|
||||||
|
|||||||
@@ -1,6 +1,8 @@
|
|||||||
import { eq } from "drizzle-orm";
|
import { eq } from "drizzle-orm";
|
||||||
import { userPreferences } from "../db/schema.js";
|
import { userPreferences } from "../db/schema.js";
|
||||||
import type { DatabaseContext } from "./database-context.js";
|
import type { DatabaseContext } from "./database-context.js";
|
||||||
|
import { rowsAffected } from "./mutation-result.js";
|
||||||
|
import { insertReturningWhere, updateReturning } from "./returning.js";
|
||||||
|
|
||||||
export type UserPreferenceRecord = typeof userPreferences.$inferSelect;
|
export type UserPreferenceRecord = typeof userPreferences.$inferSelect;
|
||||||
export type NewUserPreferenceRecord = typeof userPreferences.$inferInsert;
|
export type NewUserPreferenceRecord = typeof userPreferences.$inferInsert;
|
||||||
@@ -31,34 +33,36 @@ export class UserPreferenceRepository {
|
|||||||
const existing = await this.findByUserId(userId);
|
const existing = await this.findByUserId(userId);
|
||||||
|
|
||||||
if (!existing) {
|
if (!existing) {
|
||||||
const rows = await this.context.drizzle
|
const rows = await insertReturningWhere(
|
||||||
.insert(userPreferences)
|
this.context,
|
||||||
.values({ userId, ...update })
|
userPreferences,
|
||||||
.returning();
|
{ userId, ...update },
|
||||||
|
eq(userPreferences.userId, userId),
|
||||||
|
);
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return rows[0];
|
return rows[0];
|
||||||
}
|
}
|
||||||
|
|
||||||
const rows = await this.context.drizzle
|
const rows = await updateReturning(
|
||||||
.update(userPreferences)
|
this.context,
|
||||||
.set(update)
|
userPreferences,
|
||||||
.where(eq(userPreferences.userId, userId))
|
update,
|
||||||
.returning();
|
eq(userPreferences.userId, userId),
|
||||||
|
);
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return rows[0];
|
return rows[0];
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteByUserId(userId: string): Promise<number> {
|
async deleteByUserId(userId: string): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(userPreferences)
|
.delete(userPreferences)
|
||||||
.where(eq(userPreferences.userId, userId))
|
.where(eq(userPreferences.userId, userId));
|
||||||
.returning({ userId: userPreferences.userId });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
private async afterWrite(): Promise<void> {
|
private async afterWrite(): Promise<void> {
|
||||||
|
|||||||
@@ -1,6 +1,8 @@
|
|||||||
import { eq, inArray } from "drizzle-orm";
|
import { eq, inArray } from "drizzle-orm";
|
||||||
import { users } from "../db/schema.js";
|
import { users } from "../db/schema.js";
|
||||||
import type { DatabaseContext } from "./database-context.js";
|
import type { DatabaseContext } from "./database-context.js";
|
||||||
|
import { rowsAffected, supportsReturning } from "./mutation-result.js";
|
||||||
|
import { insertReturning, updateReturning } from "./returning.js";
|
||||||
|
|
||||||
export type UserRecord = typeof users.$inferSelect;
|
export type UserRecord = typeof users.$inferSelect;
|
||||||
export type NewUserRecord = typeof users.$inferInsert;
|
export type NewUserRecord = typeof users.$inferInsert;
|
||||||
@@ -62,10 +64,7 @@ export class UserRepository {
|
|||||||
}
|
}
|
||||||
|
|
||||||
async create(user: NewUserRecord): Promise<UserRecord> {
|
async create(user: NewUserRecord): Promise<UserRecord> {
|
||||||
const rows = await this.context.drizzle
|
const rows = await insertReturning(this.context, users, user);
|
||||||
.insert(users)
|
|
||||||
.values(user)
|
|
||||||
.returning();
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return rows[0];
|
return rows[0];
|
||||||
}
|
}
|
||||||
@@ -73,17 +72,10 @@ export class UserRepository {
|
|||||||
async createFirstLocalUser(
|
async createFirstLocalUser(
|
||||||
user: NewFirstLocalUserRecord,
|
user: NewFirstLocalUserRecord,
|
||||||
): Promise<{ user: UserRecord; isFirstUser: boolean }> {
|
): Promise<{ user: UserRecord; isFirstUser: boolean }> {
|
||||||
const result = this.context.drizzle.transaction((tx) => {
|
const result = await this.createCheckingIfFirst((isFirstUser) => ({
|
||||||
const existingUsers = tx.select({ id: users.id }).from(users).all();
|
...user,
|
||||||
const isFirstUser = existingUsers.length === 0;
|
isAdmin: isFirstUser,
|
||||||
const rows = tx
|
}));
|
||||||
.insert(users)
|
|
||||||
.values({ ...user, isAdmin: isFirstUser })
|
|
||||||
.returning()
|
|
||||||
.all();
|
|
||||||
|
|
||||||
return { user: rows[0], isFirstUser };
|
|
||||||
});
|
|
||||||
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return result;
|
return result;
|
||||||
@@ -92,41 +84,87 @@ export class UserRepository {
|
|||||||
async createFirstSsoUser(
|
async createFirstSsoUser(
|
||||||
user: NewUserRecord,
|
user: NewUserRecord,
|
||||||
): Promise<{ user: UserRecord; isFirstUser: boolean }> {
|
): Promise<{ user: UserRecord; isFirstUser: boolean }> {
|
||||||
const result = this.context.drizzle.transaction((tx) => {
|
const result = await this.createCheckingIfFirst((isFirstUser) => ({
|
||||||
const existingUsers = tx.select({ id: users.id }).from(users).all();
|
...user,
|
||||||
const isFirstUser = existingUsers.length === 0;
|
isAdmin: isFirstUser || Boolean(user.isAdmin),
|
||||||
const rows = tx
|
}));
|
||||||
.insert(users)
|
|
||||||
.values({ ...user, isAdmin: isFirstUser || Boolean(user.isAdmin) })
|
|
||||||
.returning()
|
|
||||||
.all();
|
|
||||||
|
|
||||||
return { user: rows[0], isFirstUser };
|
|
||||||
});
|
|
||||||
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return result;
|
return result;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Creates a user, making them an admin if the table was empty.
|
||||||
|
*
|
||||||
|
* The check and the insert have to be one transaction: two people signing up
|
||||||
|
* at once would otherwise both see an empty table and both become admin.
|
||||||
|
*
|
||||||
|
* The two branches are not a style choice. better-sqlite3 is synchronous and
|
||||||
|
* rejects an async transaction callback outright — "Transaction function
|
||||||
|
* cannot return a promise" — so a single body cannot serve both. It fails
|
||||||
|
* loudly rather than silently skipping the write, which is the one mercy here.
|
||||||
|
*/
|
||||||
|
private async createCheckingIfFirst(
|
||||||
|
build: (isFirstUser: boolean) => NewUserRecord,
|
||||||
|
): Promise<{ user: UserRecord; isFirstUser: boolean }> {
|
||||||
|
if (this.context.dialect === "sqlite") {
|
||||||
|
/* eslint-disable no-restricted-syntax -- sqlite-only branch: the dialect
|
||||||
|
is checked directly above, and better-sqlite3 rejects an async
|
||||||
|
transaction callback, so this cannot use the shared helpers. */
|
||||||
|
return this.context.drizzle.transaction((tx) => {
|
||||||
|
const isFirstUser =
|
||||||
|
tx.select({ id: users.id }).from(users).all().length === 0;
|
||||||
|
const rows = tx
|
||||||
|
.insert(users)
|
||||||
|
.values(build(isFirstUser))
|
||||||
|
.returning()
|
||||||
|
.all();
|
||||||
|
return { user: rows[0], isFirstUser };
|
||||||
|
});
|
||||||
|
/* eslint-enable no-restricted-syntax */
|
||||||
|
}
|
||||||
|
|
||||||
|
return this.context.drizzle.transaction(async (tx) => {
|
||||||
|
const existing = await tx.select({ id: users.id }).from(users);
|
||||||
|
const isFirstUser = existing.length === 0;
|
||||||
|
const values = build(isFirstUser);
|
||||||
|
|
||||||
|
if (supportsReturning(this.context.dialect)) {
|
||||||
|
// eslint-disable-next-line no-restricted-syntax -- guarded by the check on this line
|
||||||
|
const rows = await tx.insert(users).values(values).returning();
|
||||||
|
return { user: rows[0], isFirstUser };
|
||||||
|
}
|
||||||
|
|
||||||
|
// users is keyed by a text id the caller supplies, so there is something
|
||||||
|
// to read back by even without RETURNING.
|
||||||
|
await tx.insert(users).values(values);
|
||||||
|
const [user] = await tx
|
||||||
|
.select()
|
||||||
|
.from(users)
|
||||||
|
.where(eq(users.id, values.id));
|
||||||
|
return { user, isFirstUser };
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
async update(id: string, update: UserUpdate): Promise<UserRecord | null> {
|
async update(id: string, update: UserUpdate): Promise<UserRecord | null> {
|
||||||
const rows = await this.context.drizzle
|
const rows = await updateReturning(
|
||||||
.update(users)
|
this.context,
|
||||||
.set(update)
|
users,
|
||||||
.where(eq(users.id, id))
|
update,
|
||||||
.returning();
|
eq(users.id, id),
|
||||||
|
);
|
||||||
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return rows[0] ?? null;
|
return rows[0] ?? null;
|
||||||
}
|
}
|
||||||
|
|
||||||
async delete(id: string): Promise<boolean> {
|
async delete(id: string): Promise<boolean> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(users)
|
.delete(users)
|
||||||
.where(eq(users.id, id))
|
.where(eq(users.id, id));
|
||||||
.returning({ id: users.id });
|
|
||||||
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return rows.length > 0;
|
return rowsAffected(result) > 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
async countAdmins(): Promise<number> {
|
async countAdmins(): Promise<number> {
|
||||||
|
|||||||
@@ -2,6 +2,12 @@ import { desc, eq, or } from "drizzle-orm";
|
|||||||
import { randomUUID } from "crypto";
|
import { randomUUID } from "crypto";
|
||||||
import { vaultProfiles } from "../db/schema.js";
|
import { vaultProfiles } from "../db/schema.js";
|
||||||
import type { DatabaseContext } from "./database-context.js";
|
import type { DatabaseContext } from "./database-context.js";
|
||||||
|
import { rowsAffected } from "./mutation-result.js";
|
||||||
|
import {
|
||||||
|
deleteReturning,
|
||||||
|
insertReturning,
|
||||||
|
updateReturning,
|
||||||
|
} from "./returning.js";
|
||||||
|
|
||||||
export type VaultProfileRecord = typeof vaultProfiles.$inferSelect;
|
export type VaultProfileRecord = typeof vaultProfiles.$inferSelect;
|
||||||
|
|
||||||
@@ -45,26 +51,23 @@ export class VaultProfileRepository {
|
|||||||
}
|
}
|
||||||
|
|
||||||
async create(input: VaultProfileCreateInput): Promise<VaultProfileRecord> {
|
async create(input: VaultProfileCreateInput): Promise<VaultProfileRecord> {
|
||||||
const [created] = await this.context.drizzle
|
const [created] = await insertReturning(this.context, vaultProfiles, {
|
||||||
.insert(vaultProfiles)
|
syncId: randomUUID(),
|
||||||
.values({
|
userId: input.userId,
|
||||||
syncId: randomUUID(),
|
name: input.name,
|
||||||
userId: input.userId,
|
description: input.description,
|
||||||
name: input.name,
|
folder: input.folder,
|
||||||
description: input.description,
|
tags: input.tags,
|
||||||
folder: input.folder,
|
vaultAddr: input.vaultAddr,
|
||||||
tags: input.tags,
|
vaultNamespace: input.vaultNamespace,
|
||||||
vaultAddr: input.vaultAddr,
|
oidcMount: input.oidcMount,
|
||||||
vaultNamespace: input.vaultNamespace,
|
oidcRole: input.oidcRole,
|
||||||
oidcMount: input.oidcMount,
|
sshMount: input.sshMount,
|
||||||
oidcRole: input.oidcRole,
|
sshRole: input.sshRole,
|
||||||
sshMount: input.sshMount,
|
validPrincipals: input.validPrincipals,
|
||||||
sshRole: input.sshRole,
|
keyType: input.keyType,
|
||||||
validPrincipals: input.validPrincipals,
|
shared: input.shared ?? false,
|
||||||
keyType: input.keyType,
|
});
|
||||||
shared: input.shared ?? false,
|
|
||||||
})
|
|
||||||
.returning();
|
|
||||||
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return created;
|
return created;
|
||||||
@@ -84,14 +87,15 @@ export class VaultProfileRepository {
|
|||||||
id: number,
|
id: number,
|
||||||
input: VaultProfileUpdateInput,
|
input: VaultProfileUpdateInput,
|
||||||
): Promise<VaultProfileRecord | null> {
|
): Promise<VaultProfileRecord | null> {
|
||||||
const [updated] = await this.context.drizzle
|
const [updated] = await updateReturning(
|
||||||
.update(vaultProfiles)
|
this.context,
|
||||||
.set({
|
vaultProfiles,
|
||||||
|
{
|
||||||
...input,
|
...input,
|
||||||
updatedAt: input.updatedAt ?? new Date().toISOString(),
|
updatedAt: input.updatedAt ?? new Date().toISOString(),
|
||||||
})
|
},
|
||||||
.where(eq(vaultProfiles.id, id))
|
eq(vaultProfiles.id, id),
|
||||||
.returning();
|
);
|
||||||
|
|
||||||
if (updated) {
|
if (updated) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
@@ -101,27 +105,27 @@ export class VaultProfileRepository {
|
|||||||
}
|
}
|
||||||
|
|
||||||
async deleteById(id: number): Promise<{ syncId: string | null } | null> {
|
async deleteById(id: number): Promise<{ syncId: string | null } | null> {
|
||||||
const rows = await this.context.drizzle
|
const rows = await deleteReturning(
|
||||||
.delete(vaultProfiles)
|
this.context,
|
||||||
.where(eq(vaultProfiles.id, id))
|
vaultProfiles,
|
||||||
.returning({ syncId: vaultProfiles.syncId });
|
eq(vaultProfiles.id, id),
|
||||||
|
);
|
||||||
|
|
||||||
if (rows.length === 0) return null;
|
if (rows.length === 0) return null;
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
return rows[0];
|
return { syncId: rows[0].syncId };
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteByUserId(userId: string): Promise<number> {
|
async deleteByUserId(userId: string): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(vaultProfiles)
|
.delete(vaultProfiles)
|
||||||
.where(eq(vaultProfiles.userId, userId))
|
.where(eq(vaultProfiles.userId, userId));
|
||||||
.returning({ id: vaultProfiles.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
private async afterWrite(): Promise<void> {
|
private async afterWrite(): Promise<void> {
|
||||||
|
|||||||
@@ -1,6 +1,8 @@
|
|||||||
import { and, eq } from "drizzle-orm";
|
import { and, eq } from "drizzle-orm";
|
||||||
import { vaultTokens } from "../db/schema.js";
|
import { vaultTokens } from "../db/schema.js";
|
||||||
import type { DatabaseContext } from "./database-context.js";
|
import type { DatabaseContext } from "./database-context.js";
|
||||||
|
import { rowsAffected } from "./mutation-result.js";
|
||||||
|
import { upsert } from "./returning.js";
|
||||||
|
|
||||||
export type VaultTokenRecord = typeof vaultTokens.$inferSelect;
|
export type VaultTokenRecord = typeof vaultTokens.$inferSelect;
|
||||||
|
|
||||||
@@ -22,16 +24,17 @@ export class VaultTokenRepository {
|
|||||||
async upsert(input: VaultTokenUpsertInput): Promise<void> {
|
async upsert(input: VaultTokenUpsertInput): Promise<void> {
|
||||||
const createdAt = input.createdAt ?? new Date().toISOString();
|
const createdAt = input.createdAt ?? new Date().toISOString();
|
||||||
|
|
||||||
await this.context.drizzle
|
await upsert(
|
||||||
.insert(vaultTokens)
|
this.context,
|
||||||
.values({
|
vaultTokens,
|
||||||
|
{
|
||||||
userId: input.userId,
|
userId: input.userId,
|
||||||
profileId: input.profileId,
|
profileId: input.profileId,
|
||||||
sshCert: input.sshCert,
|
sshCert: input.sshCert,
|
||||||
privateKey: input.privateKey,
|
privateKey: input.privateKey,
|
||||||
expiresAt: input.expiresAt,
|
expiresAt: input.expiresAt,
|
||||||
})
|
},
|
||||||
.onConflictDoUpdate({
|
{
|
||||||
target: [vaultTokens.userId, vaultTokens.profileId],
|
target: [vaultTokens.userId, vaultTokens.profileId],
|
||||||
set: {
|
set: {
|
||||||
sshCert: input.sshCert,
|
sshCert: input.sshCert,
|
||||||
@@ -39,7 +42,8 @@ export class VaultTokenRepository {
|
|||||||
expiresAt: input.expiresAt,
|
expiresAt: input.expiresAt,
|
||||||
createdAt,
|
createdAt,
|
||||||
},
|
},
|
||||||
});
|
},
|
||||||
|
);
|
||||||
|
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
@@ -67,7 +71,7 @@ export class VaultTokenRepository {
|
|||||||
profileId: number,
|
profileId: number,
|
||||||
lastUsed = new Date().toISOString(),
|
lastUsed = new Date().toISOString(),
|
||||||
): Promise<boolean> {
|
): Promise<boolean> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.update(vaultTokens)
|
.update(vaultTokens)
|
||||||
.set({ lastUsed })
|
.set({ lastUsed })
|
||||||
.where(
|
.where(
|
||||||
@@ -75,48 +79,45 @@ export class VaultTokenRepository {
|
|||||||
eq(vaultTokens.userId, userId),
|
eq(vaultTokens.userId, userId),
|
||||||
eq(vaultTokens.profileId, profileId),
|
eq(vaultTokens.profileId, profileId),
|
||||||
),
|
),
|
||||||
)
|
);
|
||||||
.returning({ id: vaultTokens.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length > 0;
|
return rowsAffected(result) > 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteByUserAndProfile(
|
async deleteByUserAndProfile(
|
||||||
userId: string,
|
userId: string,
|
||||||
profileId: number,
|
profileId: number,
|
||||||
): Promise<boolean> {
|
): Promise<boolean> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(vaultTokens)
|
.delete(vaultTokens)
|
||||||
.where(
|
.where(
|
||||||
and(
|
and(
|
||||||
eq(vaultTokens.userId, userId),
|
eq(vaultTokens.userId, userId),
|
||||||
eq(vaultTokens.profileId, profileId),
|
eq(vaultTokens.profileId, profileId),
|
||||||
),
|
),
|
||||||
)
|
);
|
||||||
.returning({ id: vaultTokens.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length > 0;
|
return rowsAffected(result) > 0;
|
||||||
}
|
}
|
||||||
|
|
||||||
async deleteByUserId(userId: string): Promise<number> {
|
async deleteByUserId(userId: string): Promise<number> {
|
||||||
const rows = await this.context.drizzle
|
const result = await this.context.drizzle
|
||||||
.delete(vaultTokens)
|
.delete(vaultTokens)
|
||||||
.where(eq(vaultTokens.userId, userId))
|
.where(eq(vaultTokens.userId, userId));
|
||||||
.returning({ id: vaultTokens.id });
|
|
||||||
|
|
||||||
if (rows.length > 0) {
|
if (rowsAffected(result) > 0) {
|
||||||
await this.afterWrite();
|
await this.afterWrite();
|
||||||
}
|
}
|
||||||
|
|
||||||
return rows.length;
|
return rowsAffected(result);
|
||||||
}
|
}
|
||||||
|
|
||||||
private async afterWrite(): Promise<void> {
|
private async afterWrite(): Promise<void> {
|
||||||
|
|||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user