perf: OnceLock for env var, Arc<CurrentUser> in auth, pre-compute query lowercase

- rate_limit: cache OXICLOUD_TRUST_PROXY_HEADERS in OnceLock<bool> to avoid
  syscall on every request (~500ns → ~1ns)
- auth middleware: insert Arc<CurrentUser> instead of bare CurrentUser;
  all 5 extractors now clone Arc (~1ns) instead of 4 Strings (~60-100ns)
- search_service: pre-compute query.to_lowercase() once before loops,
  eliminating N redundant heap allocations per search
This commit is contained in:
Diocrafts
2026-03-07 11:23:56 +01:00
parent e4bcab0488
commit 9f08460027
8 changed files with 796 additions and 42 deletions
+10 -4
View File
@@ -20,9 +20,13 @@ use axum::{
};
use moka::sync::Cache;
use std::net::SocketAddr;
use std::sync::Arc;
use std::sync::{Arc, OnceLock};
use std::time::Duration;
/// Cached value of `OXICLOUD_TRUST_PROXY_HEADERS` env var.
/// Read once on first access, never again — avoids a syscall per request.
static TRUST_PROXY: OnceLock<bool> = OnceLock::new();
/// A simple sliding-window counter keyed by IP address.
///
/// Each key lives for `window` seconds; every request increments the counter.
@@ -95,9 +99,11 @@ impl RateLimiter {
/// proxy in front of the app, an attacker can spoof these headers to bypass
/// rate limiting.
pub fn extract_client_ip<B>(req: &Request<B>) -> String {
let trust_proxy = std::env::var("OXICLOUD_TRUST_PROXY_HEADERS")
.map(|v| v == "true" || v == "1")
.unwrap_or(false);
let trust_proxy = *TRUST_PROXY.get_or_init(|| {
std::env::var("OXICLOUD_TRUST_PROXY_HEADERS")
.map(|v| v == "true" || v == "1")
.unwrap_or(false)
});
let headers = req.headers();