perf: round 10 — auth alloc purge, parent-herd batching, query-shape pack, NC 304s

Benchmark-gated (benches/ROUND10.md; every change carries a BEFORE/AFTER
harness with equivalence/safety gates — two designs were rejected or
rewritten by their own benches before adoption):

- Auth hot path: TokenClaims/CurrentUser display fields to Arc<str>, role
  to inline SmolStr end-to-end (Bearer, cookie, Basic-auth cache) — 4→1
  allocs per authenticated request, 3→0 per warm DAV request; JWT
  Encoding/Decoding/Validation built once.
- Cold shared-album herd: leader-inline parent batching in PgAclEngine
  (+ cascade try_get_with single-flight) — 100→2 parent queries per
  100-thumb cold herd, herd wall 1.9x, sequential + warm paths unchanged,
  all ROUND8/9 safety gates plus new herd-equivalence gates.
- Query-shape pack: share download double-fetch 2→1 (2.18x), contact-group
  COUNT(*) 14.9x, save_faces UNNEST 3.9x, playlist reorder UNNEST 63.7x
  (now atomic), search files∥folders join! 1.45x, move drive-lookup join!
  2.14x, trash partial (drive_id, trashed_at) indexes, CalDAV event-gate
  narrow read, favorites/recents binary-decode port, dead count_files
  removed.
- NC surface: preview + avatar honour If-None-Match (e2e: 5 KB and 197 KB
  → 0 bytes per revalidation), avatar WebP→PNG transcode memoised,
  PROPFIND/trashbin integer+date emits on stack formatters, folder-header
  enrichment join!, chunk-PUT retry stat folded into create_new open.
- common::fmt integer rendering rewritten on the std 2-digit LUT after the
  round's own bench caught the div-loop losing to to_string (16.1 ns vs
  22.5; speeds every prior-round call site).
- Micro-pack: WebDAV scope probe borrow-only, ShareService base_url
  snapshot, cookie_secure OnceLock, Arc'd AES-GCM cipher, stack request-id,
  tantivy analyzer clone dropped.
- SPA: search stale-guard + AbortController (10→1 completed round-trips,
  stale-clobber gone), getFolder in-flight dedup, gridColumns matchMedia
  hoist (10k→0 style reads).

Backend: cargo fmt + clippy -D warnings clean, 524 tests green.
Frontend: npm run check clean, 301 vitest green.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018DdM7V7M3QPW7HEHg3gLov
This commit is contained in:
Claude
2026-07-18 20:33:50 +00:00
parent 4fe429a109
commit c51af68432
64 changed files with 3452 additions and 442 deletions
+14 -3
View File
@@ -1,6 +1,8 @@
use crate::domain::entities::user::User;
use chrono::{DateTime, Utc};
use serde::{Deserialize, Serialize};
use smol_str::SmolStr;
use std::sync::Arc;
use utoipa::ToSchema;
use uuid::Uuid;
@@ -247,12 +249,21 @@ pub struct UpgradeToInternalDto {
}
/// Authenticated current user data (for use in application services)
///
/// Built once per authenticated request in the auth middlewares.
/// `username`/`email` are `Arc<str>` (refcount-bump clones from the cached
/// `TokenClaims` / Basic-auth cache — JSON shape unchanged) and `role` is an
/// inline `SmolStr` ("admin"/"user" fit the 23-byte inline buffer, so the
/// per-request live-role render allocates nothing).
#[derive(Clone, Debug, Serialize, Deserialize, ToSchema)]
pub struct CurrentUser {
pub id: Uuid,
pub username: String,
pub email: String,
pub role: String,
#[schema(value_type = String)]
pub username: Arc<str>,
#[schema(value_type = String)]
pub email: Arc<str>,
#[schema(value_type = String)]
pub role: SmolStr,
}
// ============================================================================
+9 -2
View File
@@ -26,6 +26,13 @@ pub trait PasswordHasherPort: Send + Sync + 'static {
}
/// Claims contained in a JWT token
///
/// `username` / `email` are `Arc<str>` so the per-request `CurrentUser`
/// build clones them with a refcount bump instead of copying the strings —
/// the validation cache already hands the whole struct out behind an `Arc`,
/// but the two display fields still had to be deep-cloned out of it on
/// EVERY authenticated request (the "2 allocs/request" item deferred since
/// ROUND6).
#[derive(Debug, Clone)]
pub struct TokenClaims {
/// Subject identifier (user ID)
@@ -37,9 +44,9 @@ pub struct TokenClaims {
/// JWT unique ID
pub jti: String,
/// Username
pub username: String,
pub username: Arc<str>,
/// User email
pub email: String,
pub email: Arc<str>,
/// User role
pub role: String,
}
+4
View File
@@ -96,6 +96,10 @@ pub trait CalendarStoragePort: Send + Sync + 'static {
) -> Result<CalendarEventDto, DomainError>;
async fn delete_event(&self, event_id: &str) -> Result<(), DomainError>;
async fn get_event(&self, event_id: &str) -> Result<CalendarEventDto, DomainError>;
/// Narrow projection for authz gates: the owning calendar of an event
/// without hydrating the full event row (notably `ical_data`, the raw
/// iCalendar body, which can run to tens of KB on recurring events).
async fn calendar_id_for_event(&self, event_id: &str) -> Result<String, DomainError>;
/// Indexed single-row lookup by iCalendar UID — the CalDAV
/// object-resource paths must use this instead of listing the whole
/// calendar (every row + its `ical_data`) and filtering client-side.
+3
View File
@@ -106,6 +106,9 @@ pub trait ContactStoragePort: Send + Sync + 'static {
contact_id: &Uuid,
) -> Result<(), DomainError>;
async fn get_contacts_in_group(&self, group_id: &Uuid) -> Result<Vec<Contact>, DomainError>;
/// Membership count without hydrating the contacts (vCard TEXT +
/// 3 JSONB parses per row) — for group summary DTOs.
async fn count_contacts_in_group(&self, group_id: &Uuid) -> Result<i64, DomainError>;
async fn get_groups_for_contact(
&self,
contact_id: &Uuid,
-11
View File
@@ -189,17 +189,6 @@ pub trait FileReadPort: Send + Sync + 'static {
.await
}
/// Count files matching the search criteria (without loading them).
///
/// Used for pagination metadata without fetching the actual files.
/// Same drive-membership scoping as `search_files_paginated`.
async fn count_files(
&self,
folder_id: Option<&str>,
criteria: &SearchCriteriaDto,
caller_id: Uuid,
) -> Result<usize, DomainError>;
/// Return up to `limit` files whose name contains `query` (case-insensitive).
///
/// Results are ordered by relevance (exact > starts-with > contains) so the
@@ -15,6 +15,7 @@ use crate::infrastructure::services::password_hasher::Argon2PasswordHasher;
use chrono::{Duration, Utc};
use moka::future::Cache;
use rand_core::RngCore;
use smol_str::SmolStr;
use std::sync::Arc;
use std::time::Duration as StdDuration;
use uuid::Uuid;
@@ -56,12 +57,17 @@ const BASIC_AUTH_CACHE_TTL_SECS: u64 = 300;
const BASIC_AUTH_CACHE_MAX_ENTRIES: u64 = 10_000;
/// Cached identity returned after a successful Basic Auth verification.
///
/// `Arc<str>` / inline `SmolStr` fields: moka's `get` clones the value, so
/// with owned `String`s every warm Basic-auth request (all DAV traffic)
/// paid 3 string copies just to read the cached identity. Now a hit is
/// refcount bumps + a 24-byte memcpy.
#[derive(Clone)]
struct CachedBasicAuthResult {
user_id: Uuid,
username: String,
email: String,
role: String,
username: Arc<str>,
email: Arc<str>,
role: SmolStr,
}
pub struct AppPasswordService {
@@ -299,7 +305,7 @@ impl AppPasswordService {
&self,
username: &str,
password: &str,
) -> Result<(Uuid, String, String, String), DomainError> {
) -> Result<(Uuid, Arc<str>, Arc<str>, SmolStr), DomainError> {
// ── 1. Compute cache key = blake3("username:password") ────────
let cache_key: [u8; 32] =
blake3::hash(format!("{}:{}", username, password).as_bytes()).into();
@@ -400,9 +406,9 @@ impl AppPasswordService {
// stores this value under the blake3 key on return.
return Ok(CachedBasicAuthResult {
user_id: user.id(),
username: user.username().unwrap_or("").to_string(),
email: user.email().to_string(),
role: user.role().to_string(),
username: Arc::from(user.username().unwrap_or("")),
email: Arc::from(user.email()),
role: SmolStr::new_static(user.role().as_str()),
});
}
}
@@ -1102,9 +1102,9 @@ impl AuthApplicationService {
Ok(crate::application::dtos::user_dto::CurrentUser {
id: user.id(),
username: user.username().unwrap_or("").to_string(),
email: user.email().to_string(),
role: user.role().to_string(),
username: std::sync::Arc::from(user.username().unwrap_or("")),
email: std::sync::Arc::from(user.email()),
role: smol_str::SmolStr::new_static(user.role().as_str()),
})
}
+12 -4
View File
@@ -253,15 +253,23 @@ impl CalendarUseCase for CalendarService {
update: UpdateEventDto,
user_id: Uuid,
) -> Result<CalendarEventDto, DomainError> {
let event = self.calendar_storage.get_event(event_id).await?;
self.require_calendar_perm(&event.calendar_id, user_id, Permission::Update)
// Only the owning calendar id is needed for the gate — skip the
// full event hydration (`ical_data` can run to tens of KB).
let calendar_id = self
.calendar_storage
.calendar_id_for_event(event_id)
.await?;
self.require_calendar_perm(&calendar_id, user_id, Permission::Update)
.await?;
self.calendar_storage.update_event(event_id, update).await
}
async fn delete_event(&self, event_id: &str, user_id: Uuid) -> Result<(), DomainError> {
let event = self.calendar_storage.get_event(event_id).await?;
self.require_calendar_perm(&event.calendar_id, user_id, Permission::Delete)
let calendar_id = self
.calendar_storage
.calendar_id_for_event(event_id)
.await?;
self.require_calendar_perm(&calendar_id, user_id, Permission::Delete)
.await?;
self.calendar_storage.delete_event(event_id).await
}
+4 -3
View File
@@ -1005,11 +1005,12 @@ impl ContactUseCase for ContactService {
self.require_address_book_read_or_public(group.address_book_id(), &user_id)
.await?;
// Get the number of contacts in the group
let contacts = self.contact_storage.get_contacts_in_group(&id).await?;
// Count-only read: the summary DTO never looks at the contacts, so
// don't hydrate N full rows (vCard TEXT + 3 JSONB parses each).
let members = self.contact_storage.count_contacts_in_group(&id).await?;
let mut dto = ContactGroupDto::from(group);
dto.members_count = Some(contacts.len() as i32);
dto.members_count = Some(members as i32);
Ok(dto)
}
@@ -336,18 +336,18 @@ impl FileManagementUseCase for FileManagementService {
Uuid::parse_str(file_id).map_err(|_| DomainError::not_found("File", file_id))?;
let dst_folder_uuid = Uuid::parse_str(target_folder_id)
.map_err(|_| DomainError::not_found("Folder", target_folder_id))?;
let (src_drive_id, src_policies) = drive_repo
.get_drive_id_and_policies_for_file(file_uuid)
.await
.map_err(|e| {
DomainError::internal_error("Drive", format!("source drive lookup: {e:?}"))
})?;
let dst_drive_id = drive_repo
.drive_id_for_folder(dst_folder_uuid)
.await
.map_err(|e| {
DomainError::internal_error("Drive", format!("destination drive lookup: {e:?}"))
})?;
// Independent point reads — overlapped so the pre-move drive
// resolution pays one round-trip, not two (ROUND10).
let (src_res, dst_res) = tokio::join!(
drive_repo.get_drive_id_and_policies_for_file(file_uuid),
drive_repo.drive_id_for_folder(dst_folder_uuid),
);
let (src_drive_id, src_policies) = src_res.map_err(|e| {
DomainError::internal_error("Drive", format!("source drive lookup: {e:?}"))
})?;
let dst_drive_id = dst_res.map_err(|e| {
DomainError::internal_error("Drive", format!("destination drive lookup: {e:?}"))
})?;
if src_drive_id != dst_drive_id {
src_policies.refuse_cross_drive_move(
crate::domain::entities::drive::CrossDriveMoveGateContext {
+13 -12
View File
@@ -665,18 +665,19 @@ impl FolderUseCase for FolderService {
Uuid::parse_str(id).map_err(|_| DomainError::not_found("Folder", id))?;
let dst_folder_uuid = Uuid::parse_str(parent_id)
.map_err(|_| DomainError::not_found("Folder", parent_id.as_str()))?;
let (src_drive_id, src_policies) = drive_repo
.get_drive_id_and_policies_for_folder(src_folder_uuid)
.await
.map_err(|e| {
DomainError::internal_error("Drive", format!("source drive lookup: {e:?}"))
})?;
let dst_drive_id = drive_repo
.drive_id_for_folder(dst_folder_uuid)
.await
.map_err(|e| {
DomainError::internal_error("Drive", format!("destination drive lookup: {e:?}"))
})?;
// Independent point reads — overlapped so the pre-move drive
// resolution pays one round-trip, not two (ROUND10, same shape
// as `move_file_with_perms`).
let (src_res, dst_res) = tokio::join!(
drive_repo.get_drive_id_and_policies_for_folder(src_folder_uuid),
drive_repo.drive_id_for_folder(dst_folder_uuid),
);
let (src_drive_id, src_policies) = src_res.map_err(|e| {
DomainError::internal_error("Drive", format!("source drive lookup: {e:?}"))
})?;
let dst_drive_id = dst_res.map_err(|e| {
DomainError::internal_error("Drive", format!("destination drive lookup: {e:?}"))
})?;
if src_drive_id != dst_drive_id {
src_policies.refuse_cross_drive_move(
crate::domain::entities::drive::CrossDriveMoveGateContext {
+36 -32
View File
@@ -620,18 +620,30 @@ impl SearchUseCase for SearchService {
// Pre-compute once — avoids N heap allocations inside enrich_file/enrich_folder.
let query_lower = query.to_lowercase();
// Content-index candidates (first page only). Feature-off or an
// index failure yields an empty set — the search stays name-only.
let content_hits = self.lookup_content_hits(&criteria, user_id).await;
// For non-recursive searches, use efficient database-level pagination
// This avoids loading all files into memory
if !criteria.recursive {
// Use database-level pagination
let (files, total_file_count) = self
.file_repository
.search_files_paginated(criteria.folder_id.as_deref(), &criteria, user_id)
.await?;
// The content-index lookup (drive resolve + Tantivy +
// ReBAC batch), the file page and the folder query are
// mutually independent — overlap them so the search pays
// ~max() instead of the serial sum (`suggest_with_perms`
// already used this shape; ROUND10 brought it here).
let (content_hits, files_page, folders_res) = tokio::join!(
self.lookup_content_hits(&criteria, user_id),
self.file_repository.search_files_paginated(
criteria.folder_id.as_deref(),
&criteria,
user_id,
),
self.folder_repository.search_folders(
criteria.folder_id.as_deref(),
criteria.name_contains.as_deref(),
user_id,
false,
),
);
let (files, total_file_count) = files_page?;
let folders = folders_res?;
// Convert to DTOs and enrich with metadata — one fused
// pass, no intermediate Vec<FileDto> materialization.
@@ -640,17 +652,6 @@ impl SearchUseCase for SearchService {
.map(|f| Self::enrich_file(FileDto::from(f), &query_lower))
.collect();
// Get folders for this folder (non-recursive, filtered in SQL)
let folders = self
.folder_repository
.search_folders(
criteria.folder_id.as_deref(),
criteria.name_contains.as_deref(),
user_id,
false,
)
.await?;
// For folders, apply sorting and pagination in memory (usually fewer folders)
let mut enriched_folders: Vec<SearchFolderResultDto> = folders
.into_iter()
@@ -717,22 +718,25 @@ impl SearchUseCase for SearchService {
// ── Recursive search via ltree (single SQL query per entity type) ──
// Uses PostgreSQL ltree GiST index to find all files and folders
// in the subtree in O(1) queries, replacing the O(N) spawn-per-folder
// approach that could saturate the connection pool.
let (found_files, total_file_count) = self
.file_repository
.search_files_in_subtree(criteria.folder_id.as_deref(), &criteria, user_id)
.await?;
// Get folders (SQL-filtered, user-scoped, recursive when applicable)
let found_folders: Vec<Folder> = self
.folder_repository
.search_folders(
// approach that could saturate the connection pool. The content
// lookup, subtree file query and folder query overlap (`join!`),
// same as the non-recursive branch.
let (content_hits, files_page, folders_res) = tokio::join!(
self.lookup_content_hits(&criteria, user_id),
self.file_repository.search_files_in_subtree(
criteria.folder_id.as_deref(),
&criteria,
user_id,
),
self.folder_repository.search_folders(
criteria.folder_id.as_deref(),
criteria.name_contains.as_deref(),
user_id,
true,
)
.await?;
),
);
let (found_files, total_file_count) = files_page?;
let found_folders: Vec<Folder> = folders_res?;
// ── Convert to DTOs and enrich with server-computed metadata ──
// Fused single pass: no intermediate DTO Vec materialization.
+24 -24
View File
@@ -79,6 +79,11 @@ const MAX_CONCURRENT_HASHES: usize = 2;
pub struct ShareService {
config: Arc<AppConfig>,
/// `AppConfig::base_url()` snapshot, taken once at construction —
/// the method re-reads `OXICLOUD_BASE_URL` from the environment (a
/// global env-lock + String build) and was being called per DTO row
/// in the share listings. Process-invariant, so snapshot it.
base_url: String,
share_repository: Arc<SharePgRepository>,
file_repository: Arc<FileBlobReadRepository>,
folder_repository: Arc<FolderDbRepository>,
@@ -107,6 +112,7 @@ impl ShareService {
authorization: Arc<PgAclEngine>,
) -> Self {
Self {
base_url: config.base_url(),
config,
share_repository,
file_repository,
@@ -204,7 +210,7 @@ impl ShareService {
));
}
Ok(ShareDto::from_entity(&share, &self.config.base_url()))
Ok(ShareDto::from_entity(&share, &self.base_url))
}
pub fn issue_unlock_jwt(&self, share_token: &str) -> Result<String, DomainError> {
@@ -338,7 +344,7 @@ impl ShareUseCase for ShareService {
// Return DTO with the requested expires_at (grant subquery on the share
// row would return NULL at this point since INSERT ran before the grant).
let mut response = ShareDto::from_entity(&saved_share, &self.config.base_url());
let mut response = ShareDto::from_entity(&saved_share, &self.base_url);
response.expires_at = dto.expires_at;
Ok(response)
}
@@ -354,7 +360,7 @@ impl ShareUseCase for ShareService {
}
// Convert the entity to DTO for the response
Ok(ShareDto::from_entity(&share, &self.config.base_url()))
Ok(ShareDto::from_entity(&share, &self.base_url))
}
async fn get_shared_link_by_token(&self, token: &str) -> Result<ShareDto, DomainError> {
@@ -380,7 +386,7 @@ impl ShareUseCase for ShareService {
// Convert the entities to DTOs for the response
let share_dtos = active_shares
.iter()
.map(|s| ShareDto::from_entity(s, &self.config.base_url()))
.map(|s| ShareDto::from_entity(s, &self.base_url))
.collect();
Ok(share_dtos)
@@ -427,7 +433,7 @@ impl ShareUseCase for ShareService {
// Use the requested expires_at for the response (subquery in update_share
// runs before set_expiry_for_subject committed, so entity may lag).
let mut response = ShareDto::from_entity(&updated_share, &self.config.base_url());
let mut response = ShareDto::from_entity(&updated_share, &self.base_url);
if dto.expires_at.is_some() {
response.expires_at = dto.expires_at;
}
@@ -462,7 +468,7 @@ impl ShareUseCase for ShareService {
// Convert the entities to DTOs
let share_dtos: Vec<ShareDto> = shares
.iter()
.map(|s| ShareDto::from_entity(s, &self.config.base_url()))
.map(|s| ShareDto::from_entity(s, &self.base_url))
.collect();
// Create the paginated result
@@ -506,7 +512,7 @@ impl ShareUseCase for ShareService {
}
// Password verified (or not required) — return full share metadata
Ok(ShareDto::from_entity(&share, &self.config.base_url()))
Ok(ShareDto::from_entity(&share, &self.base_url))
}
async fn register_shared_link_access(&self, token: &str) -> Result<(), DomainError> {
@@ -540,7 +546,9 @@ mod tests {
/// Test-only service that mirrors `ShareService` logic but accepts generic repos.
struct ShareServiceForTest<SR, FR, FoR, PH> {
#[allow(dead_code)]
config: Arc<AppConfig>,
base_url: String,
share_repository: Arc<SR>,
file_repository: Arc<FR>,
folder_repository: Arc<FoR>,
@@ -563,6 +571,7 @@ mod tests {
password_hasher: Arc<PH>,
) -> Self {
Self {
base_url: config.base_url(),
config,
share_repository,
file_repository,
@@ -641,7 +650,7 @@ mod tests {
.save_share(&share)
.await
.map_err(|e| ShareServiceError::Repository(e.to_string()))?;
Ok(ShareDto::from_entity(&saved_share, &self.config.base_url()))
Ok(ShareDto::from_entity(&saved_share, &self.base_url))
}
async fn get_shared_link(
@@ -659,7 +668,7 @@ mod tests {
if share.is_expired() {
return Err(ShareServiceError::Expired.into());
}
Ok(ShareDto::from_entity(&share, &self.config.base_url()))
Ok(ShareDto::from_entity(&share, &self.base_url))
}
async fn get_shared_link_by_token(&self, token: &str) -> Result<ShareDto, DomainError> {
@@ -673,7 +682,7 @@ mod tests {
if share.is_expired() {
return Err(ShareServiceError::Expired.into());
}
Ok(ShareDto::from_entity(&share, &self.config.base_url()))
Ok(ShareDto::from_entity(&share, &self.base_url))
}
async fn get_shared_links_for_item(
@@ -690,7 +699,7 @@ mod tests {
Ok(shares
.into_iter()
.filter(|s| !s.is_expired())
.map(|s| ShareDto::from_entity(&s, &self.config.base_url()))
.map(|s| ShareDto::from_entity(&s, &self.base_url))
.collect())
}
@@ -720,7 +729,7 @@ mod tests {
.update_share(&share)
.await
.map_err(|e| ShareServiceError::Repository(e.to_string()))?;
Ok(ShareDto::from_entity(&updated, &self.config.base_url()))
Ok(ShareDto::from_entity(&updated, &self.base_url))
}
async fn delete_shared_link(
@@ -749,7 +758,7 @@ mod tests {
.map_err(|e| ShareServiceError::Repository(e.to_string()))?;
let dtos = shares
.iter()
.map(|s| ShareDto::from_entity(s, &self.config.base_url()))
.map(|s| ShareDto::from_entity(s, &self.base_url))
.collect();
Ok(PaginatedResponseDto::new(dtos, page, per_page, total))
}
@@ -779,9 +788,9 @@ mod tests {
"Invalid share password",
));
}
Ok(ShareDto::from_entity(&share, &self.config.base_url()))
Ok(ShareDto::from_entity(&share, &self.base_url))
}
None => Ok(ShareDto::from_entity(&share, &self.config.base_url())),
None => Ok(ShareDto::from_entity(&share, &self.base_url)),
}
}
@@ -915,15 +924,6 @@ mod tests {
Ok((Vec::new(), 0))
}
async fn count_files(
&self,
_folder_id: Option<&str>,
_criteria: &crate::application::dtos::search_dto::SearchCriteriaDto,
_user_id: Uuid,
) -> Result<usize, DomainError> {
Ok(0)
}
async fn stream_files_in_subtree(
&self,
_folder_id: &str,
@@ -536,15 +536,6 @@ impl FileReadPort for MockFileRepository {
Ok((Vec::new(), 0))
}
async fn count_files(
&self,
_folder_id: Option<&str>,
_criteria: &crate::application::dtos::search_dto::SearchCriteriaDto,
_user_id: Uuid,
) -> std::result::Result<usize, DomainError> {
Ok(0)
}
async fn stream_files_in_subtree(
&self,
_folder_id: &str,
+45 -20
View File
@@ -37,10 +37,21 @@ fn civil_from_days(z: i64) -> (i64, u32, u32) {
(if m <= 2 { y + 1 } else { y }, m, d)
}
/// Two-digit decimal pairs `"00" … "99"` — the same table-driven rendering
/// `core::fmt` uses for integer `Display`. One lookup replaces a div+mod
/// pair per two digits; ROUND10 adopted it after the naive div-by-10 loop
/// benchmarked SLOWER than `u64::to_string()` (std already uses this LUT).
const DEC_LUT: &[u8; 200] = b"0001020304050607080910111213141516171819\
2021222324252627282930313233343536373839\
4041424344454647484950515253545556575859\
6061626364656667686970717273747576777879\
8081828384858687888990919293949596979899";
#[inline]
fn push2(out: &mut [u8], pos: usize, v: u32) {
out[pos] = b'0' + (v / 10) as u8;
out[pos + 1] = b'0' + (v % 10) as u8;
let d = (v as usize) * 2;
out[pos] = DEC_LUT[d];
out[pos + 1] = DEC_LUT[d + 1];
}
#[inline]
@@ -142,32 +153,46 @@ pub fn rfc2822_utc(buf: &mut [u8; 31], secs: i64) -> Option<&str> {
Some(std::str::from_utf8(&buf[..p]).expect("ascii"))
}
/// Backward two-digit-chunk render of `v` into the tail of `buf`;
/// returns the first populated index. Shared core of
/// [`u64_str`] / [`i64_str`].
#[inline]
fn digits_to_tail(buf: &mut [u8], mut v: u64) -> usize {
let mut pos = buf.len();
while v >= 100 {
let d = ((v % 100) as usize) * 2;
v /= 100;
pos -= 2;
buf[pos] = DEC_LUT[d];
buf[pos + 1] = DEC_LUT[d + 1];
}
if v >= 10 {
let d = (v as usize) * 2;
pos -= 2;
buf[pos] = DEC_LUT[d];
buf[pos + 1] = DEC_LUT[d + 1];
} else {
pos -= 1;
buf[pos] = b'0' + v as u8;
}
pos
}
/// `u64::to_string()` without the heap `String`: renders into `buf`,
/// returns the populated tail slice.
pub fn u64_str(buf: &mut [u8; 20], mut v: u64) -> &str {
let mut pos = buf.len();
loop {
pos -= 1;
buf[pos] = b'0' + (v % 10) as u8;
v /= 10;
if v == 0 {
break;
}
}
pub fn u64_str(buf: &mut [u8; 20], v: u64) -> &str {
let pos = digits_to_tail(buf, v);
std::str::from_utf8(&buf[pos..]).expect("ascii")
}
/// `i64::to_string()` without the heap `String` (quota bytes are `i64`).
pub fn i64_str(buf: &mut [u8; 21], v: i64) -> &str {
let mut u = [0u8; 20];
let digits = u64_str(&mut u, v.unsigned_abs());
let neg = v < 0;
let start = 21 - digits.len() - usize::from(neg);
if neg {
buf[start] = b'-';
let mut pos = digits_to_tail(buf, v.unsigned_abs());
if v < 0 {
pos -= 1;
buf[pos] = b'-';
}
buf[start + usize::from(neg)..].copy_from_slice(digits.as_bytes());
std::str::from_utf8(&buf[start..]).expect("ascii")
std::str::from_utf8(&buf[pos..]).expect("ascii")
}
/// Lower-case hex of `bytes` into one preallocated `String`.
-9
View File
@@ -130,15 +130,6 @@ impl FileReadPort for StubFileReadPort {
Ok((Vec::new(), 0))
}
async fn count_files(
&self,
_folder_id: Option<&str>,
_criteria: &SearchCriteriaDto,
_user_id: Uuid,
) -> Result<usize, DomainError> {
Ok(0)
}
async fn stream_files_in_subtree(
&self,
_folder_id: &str,
+12 -4
View File
@@ -11,12 +11,20 @@ pub enum UserRole {
User,
}
impl UserRole {
/// Canonical wire/DB spelling — the single source the `Display` impl
/// and every hot-path role render go through (no format machinery).
pub fn as_str(self) -> &'static str {
match self {
UserRole::Admin => "admin",
UserRole::User => "user",
}
}
}
impl std::fmt::Display for UserRole {
fn fmt(&self, f: &mut std::fmt::Formatter) -> std::fmt::Result {
match self {
UserRole::Admin => write!(f, "admin"),
UserRole::User => write!(f, "user"),
}
f.write_str(self.as_str())
}
}
@@ -25,6 +25,11 @@ pub trait CalendarEventRepository: Send + Sync + 'static {
/// Finds a calendar event by its ID
async fn find_event_by_id(&self, id: &Uuid) -> CalendarEventRepositoryResult<CalendarEvent>;
/// Narrow projection of `find_event_by_id` for authorization gates:
/// just the owning `calendar_id`, without dragging the full row —
/// notably `ical_data`, the raw iCalendar body — off the wire.
async fn find_calendar_id_by_event_id(&self, id: &Uuid) -> CalendarEventRepositoryResult<Uuid>;
/// Cursor stream over every event of `calendar_id` in bundle order:
/// rows sorted by `(first occurrence per UID, uid, master-first,
/// start_time)` so a recurring master + its exception overrides
@@ -76,6 +76,10 @@ pub trait ContactGroupRepository: Send + Sync + 'static {
) -> ContactRepositoryResult<()>;
async fn get_contacts_in_group(&self, group_id: &Uuid)
-> ContactRepositoryResult<Vec<Contact>>;
/// Membership count only — for group summaries that don't need the
/// contacts hydrated (each row carries the full vCard TEXT plus three
/// JSONB arrays; counting must not pay for any of that).
async fn count_contacts_in_group(&self, group_id: &Uuid) -> ContactRepositoryResult<i64>;
async fn get_groups_for_contact(
&self,
contact_id: &Uuid,
@@ -391,6 +391,18 @@ impl CalendarStoragePort for CalendarStorageAdapter {
Ok(CalendarEventDto::from(event))
}
async fn calendar_id_for_event(&self, event_id: &str) -> Result<String, DomainError> {
let uuid = Uuid::parse_str(event_id).map_err(|_| {
DomainError::new(ErrorKind::InvalidInput, "Event", "Invalid event ID format")
})?;
let calendar_id = self
.event_repository
.find_calendar_id_by_event_id(&uuid)
.await?;
Ok(calendar_id.to_string())
}
async fn find_event_by_ical_uid(
&self,
calendar_id: &str,
@@ -230,6 +230,12 @@ impl ContactStoragePort for ContactStorageAdapter {
.await
}
async fn count_contacts_in_group(&self, group_id: &Uuid) -> Result<i64, DomainError> {
self.contact_group_repository
.count_contacts_in_group(group_id)
.await
}
async fn get_groups_for_contact(
&self,
contact_id: &Uuid,
@@ -213,6 +213,17 @@ impl CalendarEventRepository for CalendarEventPgRepository {
Ok(events)
}
async fn find_calendar_id_by_event_id(&self, id: &Uuid) -> CalendarEventRepositoryResult<Uuid> {
sqlx::query_scalar("SELECT calendar_id FROM caldav.calendar_events WHERE id = $1")
.bind(id)
.fetch_optional(&*self.pool)
.await
.map_err(|e| {
DomainError::database_error(format!("Failed to get event calendar id: {}", e))
})?
.ok_or_else(|| DomainError::not_found("Calendar Event", id.to_string()))
}
async fn find_event_by_id(&self, id: &Uuid) -> CalendarEventRepositoryResult<CalendarEvent> {
let row = sqlx::query(
r#"
@@ -177,6 +177,20 @@ impl ContactGroupRepository for ContactGroupPgRepository {
Ok(())
}
async fn count_contacts_in_group(&self, group_id: &Uuid) -> ContactRepositoryResult<i64> {
sqlx::query_scalar("SELECT COUNT(*) FROM carddav.group_memberships WHERE group_id = $1")
.bind(group_id)
.fetch_one(self.pool.as_ref())
.await
.map_err(|e| {
DomainError::new(
ErrorKind::InternalError,
"ContactGroup",
format!("Failed to count contacts in group: {}", e),
)
})
}
async fn get_contacts_in_group(
&self,
group_id: &Uuid,
@@ -115,29 +115,70 @@ impl FaceRepository for FacePgRepository {
if faces.is_empty() {
return Ok(());
}
let mut tx = self.pool.begin().await.map_err(|e| db_err("begin", e))?;
// One multi-row INSERT over parallel UNNEST arrays instead of one
// round-trip per face — a group photo yields many faces per indexed
// image. The `bbox` float4[] can't ride an array-of-arrays through
// unnest (PG flattens), so its 4 components travel as 4 parallel
// arrays and are reassembled server-side. A single statement is
// atomic on its own; the per-row transaction wrapper is gone.
let n = faces.len();
let mut ids = Vec::with_capacity(n);
let mut file_ids = Vec::with_capacity(n);
let mut user_ids = Vec::with_capacity(n);
let mut person_ids: Vec<Option<Uuid>> = Vec::with_capacity(n);
let (mut bx, mut by, mut bw, mut bh) = (
Vec::with_capacity(n),
Vec::with_capacity(n),
Vec::with_capacity(n),
Vec::with_capacity(n),
);
let mut det_scores = Vec::with_capacity(n);
let mut qualities: Vec<Option<f32>> = Vec::with_capacity(n);
let mut embeddings = Vec::with_capacity(n);
let mut blob_hashes: Vec<Option<&str>> = Vec::with_capacity(n);
for f in faces {
sqlx::query(
r#"
INSERT INTO faces.faces
(id, file_id, user_id, person_id, bbox, det_score, quality, embedding, blob_hash)
VALUES ($1, $2, $3, $4, $5, $6, $7, $8, $9)
"#,
)
.bind(f.id)
.bind(f.file_id)
.bind(f.user_id)
.bind(f.person_id)
.bind(f.bbox.to_array())
.bind(f.det_score)
.bind(f.quality)
.bind(embedding_to_bytes(&f.embedding))
.bind(f.blob_hash.as_deref())
.execute(&mut *tx)
.await
.map_err(|e| db_err("save_faces", e))?;
ids.push(f.id);
file_ids.push(f.file_id);
user_ids.push(f.user_id);
person_ids.push(f.person_id);
bx.push(f.bbox.x);
by.push(f.bbox.y);
bw.push(f.bbox.w);
bh.push(f.bbox.h);
det_scores.push(f.det_score);
qualities.push(f.quality);
embeddings.push(embedding_to_bytes(&f.embedding));
blob_hashes.push(f.blob_hash.as_deref());
}
tx.commit().await.map_err(|e| db_err("commit", e))?;
sqlx::query(
r#"
INSERT INTO faces.faces
(id, file_id, user_id, person_id, bbox, det_score, quality, embedding, blob_hash)
SELECT t.id, t.file_id, t.user_id, t.person_id,
ARRAY[t.bx, t.by, t.bw, t.bh]::real[],
t.det_score, t.quality, t.embedding, t.blob_hash
FROM unnest($1::uuid[], $2::uuid[], $3::uuid[], $4::uuid[],
$5::real[], $6::real[], $7::real[], $8::real[],
$9::real[], $10::real[], $11::bytea[], $12::text[])
AS t(id, file_id, user_id, person_id,
bx, by, bw, bh, det_score, quality, embedding, blob_hash)
"#,
)
.bind(&ids)
.bind(&file_ids)
.bind(&user_ids)
.bind(&person_ids)
.bind(&bx)
.bind(&by)
.bind(&bw)
.bind(&bh)
.bind(&det_scores)
.bind(&qualities)
.bind(&embeddings)
.bind(&blob_hashes)
.execute(self.pool.as_ref())
.await
.map_err(|e| db_err("save_faces", e))?;
Ok(())
}
@@ -24,18 +24,21 @@ impl FavoritesPgRepository {
impl FavoritesRepositoryPort for FavoritesPgRepository {
async fn get_favorites(&self, user_id: Uuid) -> Result<Vec<FavoriteItemDto>> {
// `id`/`user_id`/`parent_id` decode as binary UUIDs (16 B on the wire,
// no server-side `::TEXT` cast) and render app-side — the ROUND6 §10
// pattern the two legacy listing methods here never picked up.
let rows = sqlx::query(
r#"
SELECT
uf.id::TEXT AS "id",
uf.user_id::TEXT AS "user_id",
uf.id AS "id",
uf.user_id AS "user_id",
uf.item_id AS "item_id",
uf.item_type AS "item_type",
uf.created_at AS "created_at",
COALESCE(f.name, fld.name) AS "item_name",
f.size AS "item_size",
f.mime_type AS "item_mime_type",
COALESCE(f.folder_id::TEXT, fld.parent_id::TEXT) AS "parent_id",
COALESCE(f.folder_id, fld.parent_id) AS "parent_id",
COALESCE(f.updated_at, fld.updated_at) AS "modified_at",
CASE
WHEN uf.item_type = 'folder' THEN fld.path
@@ -70,15 +73,19 @@ impl FavoritesRepositoryPort for FavoritesPgRepository {
.iter()
.map(|row| {
FavoriteItemDto {
id: row.get("id"),
user_id: row.get("user_id"),
id: row.get::<i32, _>("id").to_string(),
user_id: row.get::<Uuid, _>("user_id").to_string(),
item_id: row.get("item_id"),
item_type: row.get("item_type"),
created_at: row.get("created_at"),
item_name: row.try_get("item_name").ok(),
item_size: row.try_get("item_size").ok(),
item_mime_type: row.try_get("item_mime_type").ok(),
parent_id: row.try_get("parent_id").ok(),
parent_id: row
.try_get::<Option<Uuid>, _>("parent_id")
.ok()
.flatten()
.map(|u| u.to_string()),
modified_at: row.try_get("modified_at").ok(),
item_path: row.try_get("item_path").ok(),
// Temporary defaults; with_display_fields() computes the real values
@@ -1394,19 +1394,6 @@ impl FileReadPort for FileBlobReadRepository {
Ok((files, total_count))
}
/// Count files matching the search criteria (without loading them).
async fn count_files(
&self,
folder_id: Option<&str>,
criteria: &SearchCriteriaDto,
caller_id: Uuid,
) -> Result<usize, DomainError> {
let (_, count) = self
.search_files_paginated(folder_id, criteria, caller_id)
.await?;
Ok(count)
}
#[allow(clippy::type_complexity)]
async fn suggest_files_by_name(
&self,
@@ -544,17 +544,27 @@ impl PlaylistItemRepository for PlaylistItemPgRepository {
playlist_id: &Uuid,
item_ids: &[Uuid],
) -> PlaylistItemRepositoryResult<()> {
for (index, item_id) in item_ids.iter().enumerate() {
sqlx::query(
"UPDATE audio.playlist_items SET position = $2 WHERE id = $1 AND playlist_id = $3",
)
.bind(item_id)
.bind(index as i32)
.bind(playlist_id)
.execute(&*self.pool)
.await
.map_err(|e| DomainError::database_error(format!("Failed to reorder: {}", e)))?;
if item_ids.is_empty() {
return Ok(());
}
// One UNNEST-driven UPDATE instead of one autocommit round-trip per
// track — a full drag-reorder of an N-track playlist was N statements
// (and non-atomic: a mid-loop failure left a half-applied order).
// `WITH ORDINALITY` numbers the ids in array order, 1-based, so
// `ord - 1` reproduces the historical 0-based positions.
sqlx::query(
r#"
UPDATE audio.playlist_items AS pi
SET position = (t.ord - 1)::int
FROM unnest($1::uuid[]) WITH ORDINALITY AS t(id, ord)
WHERE pi.id = t.id AND pi.playlist_id = $2
"#,
)
.bind(item_ids)
.bind(playlist_id)
.execute(&*self.pool)
.await
.map_err(|e| DomainError::database_error(format!("Failed to reorder: {}", e)))?;
Ok(())
}
@@ -21,18 +21,20 @@ impl RecentItemsPgRepository {
impl RecentItemsRepositoryPort for RecentItemsPgRepository {
async fn get_recent_items(&self, user_id: Uuid, limit: i32) -> Result<Vec<RecentItemDto>> {
// Binary UUID decode + app-side render (ROUND6 §10 pattern) — no
// server-side `::TEXT` casts, 16 B per id on the wire instead of 36.
let rows = sqlx::query(
r#"
SELECT
ur.id::TEXT AS "id",
ur.user_id::TEXT AS "user_id",
ur.id AS "id",
ur.user_id AS "user_id",
ur.item_id AS "item_id",
ur.item_type AS "item_type",
ur.accessed_at AS "accessed_at",
COALESCE(f.name, fld.name) AS "item_name",
f.size AS "item_size",
f.mime_type AS "item_mime_type",
COALESCE(f.folder_id::TEXT, fld.parent_id::TEXT) AS "parent_id",
COALESCE(f.folder_id, fld.parent_id) AS "parent_id",
CASE
WHEN ur.item_type = 'folder' THEN fld.path
WHEN ur.item_type = 'file' THEN COALESCE(pfld.path || '/' || f.name, f.name)
@@ -67,15 +69,19 @@ impl RecentItemsRepositoryPort for RecentItemsPgRepository {
.iter()
.map(|row| {
RecentItemDto {
id: row.get("id"),
user_id: row.get("user_id"),
id: row.get::<i32, _>("id").to_string(),
user_id: row.get::<Uuid, _>("user_id").to_string(),
item_id: row.get("item_id"),
item_type: row.get("item_type"),
accessed_at: row.get("accessed_at"),
item_name: row.try_get("item_name").ok(),
item_size: row.try_get("item_size").ok(),
item_mime_type: row.try_get("item_mime_type").ok(),
parent_id: row.try_get("parent_id").ok(),
parent_id: row
.try_get::<Option<Uuid>, _>("parent_id")
.ok()
.flatten()
.map(|u| u.to_string()),
item_path: row.try_get("item_path").ok(),
// Temporary defaults; with_display_fields() computes the real values
icon_class: String::new(),
@@ -56,7 +56,10 @@ const PLAINTEXT_EMIT_SIZE: usize = 64 * 1024;
/// `BlobStorageBackend` decorator that encrypts blobs at rest.
pub struct EncryptedBlobBackend {
inner: Arc<dyn BlobStorageBackend>,
cipher: Aes256Gcm,
/// `Arc` so the per-op `clone()` handed to `offload_crypto` closures is
/// an atomic bump instead of copying the ~240-byte expanded AES-256
/// round-key schedule on every chunk read/write.
cipher: Arc<Aes256Gcm>,
}
impl EncryptedBlobBackend {
@@ -64,7 +67,8 @@ impl EncryptedBlobBackend {
///
/// `key` must be exactly 32 bytes (AES-256).
pub fn new(inner: Arc<dyn BlobStorageBackend>, key: &[u8; 32]) -> Self {
let cipher = Aes256Gcm::new_from_slice(key).expect("AES-256 key must be 32 bytes");
let cipher =
Arc::new(Aes256Gcm::new_from_slice(key).expect("AES-256 key must be 32 bytes"));
Self { inner, cipher }
}
+38 -33
View File
@@ -24,6 +24,11 @@ use crate::domain::entities::user::User;
/// Internal JWT claims structure for serialization.
/// This is the actual JWT payload structure used by jsonwebtoken crate.
///
/// `username` / `email` deserialize straight into `Arc<str>` (serde `rc`,
/// one allocation — same count as `String`) so the `TokenClaims` conversion
/// below is a plain move and the port-level claims can hand refcount bumps
/// to every consumer.
#[derive(Debug, Serialize, Deserialize)]
struct JwtClaims {
/// Subject identifier - contains the user ID
@@ -35,9 +40,9 @@ struct JwtClaims {
/// JWT unique ID for token tracking and revocation
pub jti: String,
/// Username for display and identification purposes
pub username: String,
pub username: Arc<str>,
/// User email for communication and identification
pub email: String,
pub email: Arc<str>,
/// User role for authorization checks
pub role: String,
}
@@ -80,8 +85,16 @@ impl From<JwtClaims> for TokenClaims {
/// unique-token flooding.
/// - Expired tokens are never cached (decode itself rejects them first).
pub struct JwtTokenService {
/// Secret key used for signing JWT tokens
jwt_secret: String,
/// Pre-built signing key — `EncodingKey::from_secret` copies the secret
/// into a fresh buffer, so building it per `generate_access_token` call
/// paid an allocation per login/refresh for a process-invariant value.
encoding_key: EncodingKey,
/// Pre-built verification key (same rationale, on the validation-cache
/// miss path — every new token and every token once per TTL window).
decoding_key: DecodingKey,
/// Pre-built HS256 validation config — `Validation::new` allocates a
/// `HashSet{"exp"}` + algorithm `Vec` on every call otherwise.
validation: Validation,
/// Expiration time for access tokens in seconds
access_token_expiry: i64,
/// Expiration time for refresh tokens in seconds
@@ -125,7 +138,9 @@ impl JwtTokenService {
);
Self {
jwt_secret,
encoding_key: EncodingKey::from_secret(jwt_secret.as_bytes()),
decoding_key: DecodingKey::from_secret(jwt_secret.as_bytes()),
validation: Validation::new(Algorithm::HS256),
access_token_expiry: access_token_expiry_secs,
refresh_token_expiry: refresh_token_expiry_secs,
validation_cache,
@@ -169,9 +184,9 @@ impl TokenServicePort for JwtTokenService {
exp: now + self.access_token_expiry,
iat: now,
jti: Uuid::new_v4().to_string(),
username: user.username().unwrap_or("").to_string(),
email: user.email().to_string(),
role: format!("{}", user.role()),
username: Arc::from(user.username().unwrap_or("")),
email: Arc::from(user.email()),
role: user.role().as_str().to_string(),
};
// Log JWT claims for debugging
@@ -182,12 +197,7 @@ impl TokenServicePort for JwtTokenService {
claims.iat
);
encode(
&Header::default(),
&claims,
&EncodingKey::from_secret(self.jwt_secret.as_bytes()),
)
.map_err(|e| {
encode(&Header::default(), &claims, &self.encoding_key).map_err(|e| {
tracing::error!("Error generating token: {}", e);
DomainError::new(
ErrorKind::InternalError,
@@ -217,23 +227,18 @@ impl TokenServicePort for JwtTokenService {
// ── 2. Slow-path: full HMAC-SHA256 verification ─────────
self.cache_misses.fetch_add(1, Ordering::Relaxed);
let validation = Validation::new(Algorithm::HS256);
let token_data = decode::<JwtClaims>(
token,
&DecodingKey::from_secret(self.jwt_secret.as_bytes()),
&validation,
)
.map_err(|e| match e.kind() {
jsonwebtoken::errors::ErrorKind::ExpiredSignature => {
DomainError::new(ErrorKind::AccessDenied, "TokenService", "Token expired")
}
_ => DomainError::new(
ErrorKind::AccessDenied,
"TokenService",
format!("Invalid token: {}", e),
),
})?;
let token_data = decode::<JwtClaims>(token, &self.decoding_key, &self.validation).map_err(
|e| match e.kind() {
jsonwebtoken::errors::ErrorKind::ExpiredSignature => {
DomainError::new(ErrorKind::AccessDenied, "TokenService", "Token expired")
}
_ => DomainError::new(
ErrorKind::AccessDenied,
"TokenService",
format!("Invalid token: {}", e),
),
},
)?;
let claims = Arc::new(TokenClaims::from(token_data.claims));
@@ -301,8 +306,8 @@ mod tests {
.validate_token(&token)
.expect("Should validate token");
assert_eq!(claims.sub, user.id().to_string());
assert_eq!(Some(claims.username.as_str()), user.username());
assert_eq!(claims.email, user.email());
assert_eq!(Some(&*claims.username), user.username());
assert_eq!(&*claims.email, user.email());
}
#[test]
+341 -55
View File
@@ -31,12 +31,13 @@
use std::collections::HashSet;
use std::sync::Arc;
use std::sync::atomic::{AtomicU32, Ordering};
use std::sync::atomic::{AtomicU32, AtomicU64, Ordering};
use std::time::Duration;
use uuid::Uuid;
use moka::future::Cache;
use sqlx::PgPool;
use tokio::sync::oneshot;
use crate::application::ports::authorization_ports::AuthorizationEngine;
use crate::common::errors::DomainError;
@@ -218,6 +219,61 @@ pub struct PgAclEngine {
/// Grant writes don't affect parentage — only the TTL applies (moves are
/// an indirect path, same self-heal contract as `cascade_grant_cache`).
file_parent_cache: Cache<Uuid, Option<Uuid>>,
/// Natural-batching collector for cold `file_parent_cache` misses — the
/// ROUND9 §10 deferred item. A shared N-photo album's cold first view
/// arrives as N near-simultaneous thumbnail requests, each missing the
/// parent memo and each paying a point `SELECT folder_id`.
///
/// Leader-runs-inline shape: an idle miss marks itself leader (one
/// mutex op) and runs its point query exactly as before — the
/// SEQUENTIAL path gains no hop, no task, no extra latency (a
/// channel-task variant benchmarked at ~66 µs/miss of pure overhead and
/// was rejected). Misses arriving while a leader is in flight park a
/// oneshot in this queue; the leader drains them into ONE `= ANY($1)`
/// batch after its own query, so a K-wide herd collapses to ~2 queries.
/// If a leader future is dropped mid-flight, its guard wakes every
/// parked waiter to retry (and re-elect); waiters that exhaust retries
/// fall back to the inline point query — strictly additive.
parent_batch: Arc<std::sync::Mutex<Option<Vec<ParentWaiter>>>>,
/// Total parent-resolution queries actually issued (point + batches) —
/// exposed via [`Self::parent_query_count`] for benches/operators.
parent_queries: Arc<AtomicU64>,
}
/// One parked parent-resolution request: file id + reply slot. A dropped
/// sender (leader cancelled) is the retry signal. Errors are shared behind
/// `Arc` because `DomainError` carries a non-clonable source chain (same
/// convention as the Basic-auth single-flight).
type ParentWaiter = (
Uuid,
oneshot::Sender<Result<Option<Uuid>, Arc<DomainError>>>,
);
/// Upper bound on ids drained into one `= ANY` parent batch. A browser herd
/// is O(100); this only guards pathological queue growth.
const PARENT_BATCH_MAX: usize = 256;
/// How many times a parked waiter re-runs the elect-or-park protocol after
/// a leader vanished before giving up and querying inline itself.
const PARENT_WAIT_RETRIES: usize = 3;
/// RAII release of parent-resolution leadership. If the leader future is
/// dropped at an await point (client disconnect cancels the request), this
/// clears the in-flight marker and drops every parked waiter's sender —
/// their `oneshot` recv errors and they re-run the election, so a vanished
/// leader can never strand the queue.
struct ParentLeaderGuard<'a> {
engine: &'a PgAclEngine,
}
impl Drop for ParentLeaderGuard<'_> {
fn drop(&mut self) {
let mut slot = match self.engine.parent_batch.lock() {
Ok(s) => s,
Err(poisoned) => poisoned.into_inner(),
};
*slot = None;
}
}
impl PgAclEngine {
@@ -263,6 +319,8 @@ impl PgAclEngine {
.max_capacity(FILE_PARENT_CACHE_CAPACITY)
.time_to_live(FILE_PARENT_CACHE_TTL)
.build(),
parent_batch: Arc::new(std::sync::Mutex::new(None)),
parent_queries: Arc::new(AtomicU64::new(0)),
}
}
@@ -341,6 +399,8 @@ impl PgAclEngine {
.max_capacity(1)
.time_to_live(Duration::from_secs(1))
.build(),
parent_batch: Arc::new(std::sync::Mutex::new(None)),
parent_queries: Arc::new(AtomicU64::new(0)),
}
}
@@ -779,11 +839,16 @@ impl PgAclEngine {
Ok(exists.is_some())
}
/// Memoised `file_id → Option<parent folder_id>` point read backing the
/// Memoised `file_id → Option<parent folder_id>` read backing the
/// file-cascade decomposition. `None` covers both a missing row and a
/// NULL `folder_id` — in either case only the direct-file-grant branch
/// can match (mirroring the historical UNION's `folder_id IS NOT NULL`
/// guard).
///
/// Cold misses run the leader-inline batching protocol (see
/// `parent_batch`): an idle miss queries inline exactly as before;
/// misses concurrent with an in-flight leader park and are answered by
/// the leader's single `= ANY` charity batch.
async fn file_parent_folder_cached(
&self,
file_id: Uuid,
@@ -793,15 +858,221 @@ impl PgAclEngine {
return Ok(parent);
}
counters.sql_queries.fetch_add(1, Ordering::Relaxed);
enum Elect {
Lead,
Park(oneshot::Receiver<Result<Option<Uuid>, Arc<DomainError>>>),
Overflow,
}
for _ in 0..=PARENT_WAIT_RETRIES {
// Elect-or-park. The guard lives only inside this block — the
// decision is acted on AFTER it drops, so no lock is ever held
// across an await (and the handler futures stay `Send`).
let outcome = {
let mut slot = self.parent_batch.lock().expect("parent_batch poisoned");
match slot.as_mut() {
// A leader is in flight — park a oneshot in its queue.
Some(queue) if queue.len() < PARENT_BATCH_MAX => {
let (tx, rx) = oneshot::channel();
queue.push((file_id, tx));
Elect::Park(rx)
}
// Queue full — behave as if idle contention: inline below.
Some(_) => Elect::Overflow,
// Idle — become the leader.
None => {
*slot = Some(Vec::new());
Elect::Lead
}
}
};
match outcome {
Elect::Lead => return self.parent_leader_resolve(file_id).await,
Elect::Park(rx) => match rx.await {
Ok(Ok(parent)) => return Ok(parent),
Ok(Err(shared)) => {
return Err(DomainError::new(
shared.kind,
shared.entity_type,
shared.message.clone(),
));
}
// Leader vanished (cancelled mid-flight) — retry the
// election; a fresh leader (possibly us) takes over.
Err(_) => continue,
},
// Queue overflow: don't wait — resolve inline.
Elect::Overflow => break,
}
}
// Retries exhausted or queue overflow: the historical inline read.
self.parent_queries.fetch_add(1, Ordering::Relaxed);
let parent = Self::query_parent_point(&self.pool, file_id).await?;
self.file_parent_cache.insert(file_id, parent).await;
Ok(parent)
}
/// Leader half of the parent-resolution protocol: run own point query
/// inline (the exact pre-round-10 cost), then serve everything that
/// parked during it with ONE `= ANY` batch. A second wave arriving
/// during the charity batch is handed to a detached drainer task so the
/// leader's own response is never delayed by more than one batch.
///
/// Cancellation-safe: `ParentLeaderGuard` releases leadership on drop
/// and wakes parked waiters (their `oneshot` senders drop → they retry
/// and re-elect).
async fn parent_leader_resolve(&self, file_id: Uuid) -> Result<Option<Uuid>, DomainError> {
let guard = ParentLeaderGuard { engine: self };
self.parent_queries.fetch_add(1, Ordering::Relaxed);
let own = Self::query_parent_point(&self.pool, file_id).await;
if let Ok(parent) = &own {
self.file_parent_cache.insert(file_id, *parent).await;
}
// Take the first charity wave (leave `Some(vec![])` so later
// arrivals keep parking while the batch runs).
let wave = {
let mut slot = self.parent_batch.lock().expect("parent_batch poisoned");
match slot.as_mut() {
Some(queue) if !queue.is_empty() => std::mem::take(queue),
_ => Vec::new(),
}
};
if !wave.is_empty() {
self.parent_queries.fetch_add(1, Ordering::Relaxed);
Self::serve_parent_wave(&self.pool, &self.file_parent_cache, wave).await;
}
// Release leadership — or, if a second wave parked during the
// charity batch, hand leadership to a detached drainer so the
// leader's own response isn't delayed further. The drainer loops:
// it keeps the slot marked in-flight (newer misses keep parking)
// and only clears it when the queue drains empty.
let second_wave = {
let mut slot = self.parent_batch.lock().expect("parent_batch poisoned");
match slot.as_mut() {
Some(queue) if !queue.is_empty() => Some(std::mem::take(queue)),
_ => {
*slot = None; // idle again
None
}
}
};
std::mem::forget(guard); // leadership released or handed to the drainer
if let Some(first) = second_wave {
let engine = self.clone_batch_handles();
tokio::spawn(async move {
let mut wave = first;
loop {
engine.2.fetch_add(1, Ordering::Relaxed);
Self::serve_parent_wave(&engine.0, &engine.1, wave).await;
let mut slot = match engine.3.lock() {
Ok(s) => s,
Err(p) => p.into_inner(),
};
match slot.as_mut() {
Some(queue) if !queue.is_empty() => {
wave = std::mem::take(queue);
}
_ => {
*slot = None;
break;
}
}
}
});
}
own
}
/// The `Arc`'d handles the detached drainer needs (pool, memo cache,
/// query counter, queue slot). Cloned individually because the drainer
/// outlives this call and the engine isn't guaranteed to sit behind an
/// `Arc` here.
#[allow(clippy::type_complexity)]
fn clone_batch_handles(
&self,
) -> (
Arc<PgPool>,
Cache<Uuid, Option<Uuid>>,
Arc<AtomicU64>,
Arc<std::sync::Mutex<Option<Vec<ParentWaiter>>>>,
) {
(
Arc::clone(&self.pool),
self.file_parent_cache.clone(),
Arc::clone(&self.parent_queries),
Arc::clone(&self.parent_batch),
)
}
/// Resolve one file's parent with the point query (shared by the
/// leader's own read and the no-batching fallback).
async fn query_parent_point(pool: &PgPool, file_id: Uuid) -> Result<Option<Uuid>, DomainError> {
let parent: Option<Option<Uuid>> =
sqlx::query_scalar("SELECT folder_id FROM storage.files WHERE id = $1")
.bind(file_id)
.fetch_optional(self.pool.as_ref())
.fetch_optional(pool)
.await
.map_err(|e| DomainError::internal_error("PgAcl", format!("file parent: {e}")))?;
let parent = parent.flatten();
self.file_parent_cache.insert(file_id, parent).await;
Ok(parent)
Ok(parent.flatten())
}
/// Serve a parked wave with one `= ANY` query: memoise every id
/// (requested-but-absent rows memoise as `None`, matching the point
/// read) and answer every oneshot. On error the shared failure is
/// fanned out instead.
async fn serve_parent_wave(
pool: &PgPool,
cache: &Cache<Uuid, Option<Uuid>>,
wave: Vec<ParentWaiter>,
) {
let mut ids: Vec<Uuid> = Vec::with_capacity(wave.len());
for (id, _) in &wave {
if !ids.contains(id) {
ids.push(*id);
}
}
let fetched: Result<Vec<(Uuid, Option<Uuid>)>, sqlx::Error> =
sqlx::query_as("SELECT id, folder_id FROM storage.files WHERE id = ANY($1)")
.bind(&ids)
.fetch_all(pool)
.await;
match fetched {
Ok(rows) => {
let mut by_id: std::collections::HashMap<Uuid, Option<Uuid>> =
rows.into_iter().collect();
for id in &ids {
by_id.entry(*id).or_insert(None);
}
for (id, parent) in &by_id {
cache.insert(*id, *parent).await;
}
for (id, reply) in wave {
let parent = by_id.get(&id).copied().unwrap_or(None);
let _ = reply.send(Ok(parent));
}
}
Err(e) => {
let shared = Arc::new(DomainError::internal_error(
"PgAcl",
format!("file parent batch: {e}"),
));
for (_, reply) in wave {
let _ = reply.send(Err(Arc::clone(&shared)));
}
}
}
}
/// Total parent-resolution queries actually issued (point + `= ANY`
/// batches). With batching, this is ≤ the number of cold misses — the
/// gap is the herd-collapse win. Exposed for benches and operators.
pub fn parent_query_count(&self) -> u64 {
self.parent_queries.load(Ordering::Relaxed)
}
/// Cache-aware wrapper over the File/Folder grant cascade. Serves the
@@ -843,56 +1114,71 @@ impl PgAclEngine {
counters.cache_hit.fetch_add(1, Ordering::Relaxed);
return Ok(allowed);
}
let allowed = match resource {
Resource::Folder(id) => {
let (subject_types, subject_ids) =
self.subject_match_set(subject, counters).await?;
self.folder_cascade_grant_exists(
&subject_types,
&subject_ids,
permission,
id,
counters,
)
.await?
}
Resource::File(id) => {
// Ancestor half first — amortized to one query per FOLDER
// via the recursive Folder arm (its own cache entry).
let folder_allowed = match self.file_parent_folder_cached(id, counters).await? {
Some(parent) => {
Box::pin(self.cascade_grant_cached(
subject,
Resource::Folder(parent),
permission,
counters,
))
.await?
}
None => false,
};
if folder_allowed {
true
} else {
let (subject_types, subject_ids) =
self.subject_match_set(subject, counters).await?;
self.file_direct_grant_exists(
&subject_types,
&subject_ids,
permission,
id,
counters,
)
.await?
}
}
// Only File/Folder reach this helper (see `check_inner`).
_ => return Ok(false),
};
// Only File/Folder reach this helper (see `check_inner`); keep the
// defensive arm OUTSIDE the loader so it stays uncached, as before.
if !matches!(resource, Resource::Folder(_) | Resource::File(_)) {
return Ok(false);
}
// `try_get_with`: a cold herd on the same key — every photo of an
// album recursing into the SAME folder decision at once — coalesces
// into ONE loader run. The old get→compute→insert let K concurrent
// misses each run the ltree query (ROUND10; the ROUND3 auth-herd
// pattern). moka never caches loader errors, preserving the
// historical error semantics.
self.cascade_grant_cache
.insert((subject, resource, permission), allowed)
.await;
Ok(allowed)
.try_get_with((subject, resource, permission), async {
match resource {
Resource::Folder(id) => {
let (subject_types, subject_ids) =
self.subject_match_set(subject, counters).await?;
self.folder_cascade_grant_exists(
&subject_types,
&subject_ids,
permission,
id,
counters,
)
.await
}
Resource::File(id) => {
// Ancestor half first — amortized to one query per
// FOLDER via the recursive Folder arm (its own cache
// entry + its own single-flight).
let folder_allowed =
match self.file_parent_folder_cached(id, counters).await? {
Some(parent) => {
Box::pin(self.cascade_grant_cached(
subject,
Resource::Folder(parent),
permission,
counters,
))
.await?
}
None => false,
};
if folder_allowed {
Ok(true)
} else {
let (subject_types, subject_ids) =
self.subject_match_set(subject, counters).await?;
self.file_direct_grant_exists(
&subject_types,
&subject_ids,
permission,
id,
counters,
)
.await
}
}
_ => unreachable!("guarded above"),
}
})
.await
.map_err(|e: Arc<DomainError>| {
DomainError::new(e.kind, e.entity_type, e.message.clone())
})
}
/// Cached resolution of `(subject, drive_id) → Option<Role>` — the
@@ -238,8 +238,10 @@ impl TantivyContentIndex {
}
/// Tokenize `raw` with the index analyzer (simple split + lowercase).
fn query_tokens(analyzer: &TextAnalyzer, raw: &str) -> Vec<String> {
let mut analyzer = analyzer.clone();
/// Takes the analyzer by value — the caller's per-search clone is the
/// only one needed; cloning the boxed tokenizer chain again here doubled
/// the per-query allocation for nothing.
fn query_tokens(mut analyzer: TextAnalyzer, raw: &str) -> Vec<String> {
let mut tokens = Vec::new();
let mut stream = analyzer.token_stream(raw);
while stream.advance() && tokens.len() < MAX_QUERY_TOKENS {
@@ -337,7 +339,7 @@ impl TantivyContentIndex {
raw_query: &str,
limit: usize,
) -> Result<Vec<ContentHitDto>, DomainError> {
let tokens = Self::query_tokens(&analyzer, raw_query);
let tokens = Self::query_tokens(analyzer, raw_query);
if tokens.is_empty() {
return Ok(Vec::new());
}
+10
View File
@@ -44,7 +44,17 @@ pub fn is_cookie_secure() -> bool {
cookie_secure()
}
/// Memoised [`resolve_cookie_secure`]. The flag is a pure function of two
/// process-invariant env vars, yet a single login used to re-resolve it
/// ~4× (two auth cookies + the CSRF cookie + the handler's own probe) —
/// each call paying the env-lock syscalls and re-emitting the same
/// "⚠️ SECURITY" log line. Resolve once, log once.
fn cookie_secure() -> bool {
static COOKIE_SECURE: std::sync::OnceLock<bool> = std::sync::OnceLock::new();
*COOKIE_SECURE.get_or_init(resolve_cookie_secure)
}
fn resolve_cookie_secure() -> bool {
if let Ok(v) = std::env::var("OXICLOUD_COOKIE_SECURE") {
let secure = v == "true" || v == "1";
if !secure {
+9 -2
View File
@@ -489,7 +489,14 @@ async fn serve_share_file(
}
}
match retrieval.get_file_optimized(file_id, false, true).await {
// The metadata was already fetched at the top of this fn — hand the DTO
// to the `_preloaded` variant (as the authenticated download path does)
// instead of letting `get_file_optimized` re-run the same metadata query.
let file_size = file_dto.size;
match retrieval
.get_file_optimized_preloaded(file_id, file_dto, false, true)
.await
{
Ok((_, content)) => match content {
OptimizedFileContent::Bytes { data, .. } => Response::builder()
.status(StatusCode::OK)
@@ -510,7 +517,7 @@ async fn serve_share_file(
.status(StatusCode::OK)
.header(header::CONTENT_TYPE, &*mime)
.header(header::CONTENT_DISPOSITION, &disposition)
.header(header::CONTENT_LENGTH, file_dto.size)
.header(header::CONTENT_LENGTH, file_size)
.header(header::ACCEPT_RANGES, "bytes")
.header(header::ETAG, &etag)
.header(
@@ -259,6 +259,13 @@ struct DriveScope {
db_path: String,
}
/// Borrow-only `s.strip_prefix(&format!("{prefix}/"))` — the prefix tests
/// below run on EVERY native WebDAV verb, so they must not allocate a
/// throwaway `{prefix}/` String per request.
fn strip_prefix_slash<'a>(s: &'a str, prefix: &str) -> Option<&'a str> {
s.strip_prefix(prefix)?.strip_prefix('/')
}
async fn resolve_webdav_scope(
state: &Arc<AppState>,
user_id: Uuid,
@@ -292,8 +299,7 @@ async fn resolve_webdav_scope(
if normalized == listing_marker {
return Ok(WebdavTarget::ListDrives);
}
let with_slash = format!("{}/", listing_marker);
if let Some(after_prefix) = normalized.strip_prefix(&with_slash) {
if let Some(after_prefix) = strip_prefix_slash(normalized, listing_marker) {
if after_prefix.is_empty() {
return Ok(WebdavTarget::ListDrives);
}
@@ -316,7 +322,7 @@ async fn resolve_webdav_scope(
let root_name = default.root_folder_name.as_str();
let db_path = if normalized.is_empty() {
root_name.to_string()
} else if normalized == root_name || normalized.starts_with(&format!("{}/", root_name)) {
} else if normalized == root_name || strip_prefix_slash(normalized, root_name).is_some() {
// Pre-refactor bookmark already carried the drive-root prefix.
normalized.to_string()
} else {
+3 -2
View File
@@ -8,6 +8,7 @@
//! for audit / ownership purposes.
use axum::http::{HeaderMap, StatusCode, header};
use smol_str::SmolStr;
use uuid::Uuid;
use crate::application::ports::auth_ports::TokenServicePort;
@@ -26,7 +27,7 @@ use crate::interfaces::middleware::user::{LiveRole, resolve_live_role};
pub async fn require_admin(
state: &AppState,
headers: &HeaderMap,
) -> Result<(Uuid, String), AppError> {
) -> Result<(Uuid, SmolStr), AppError> {
let auth = state
.auth_service
.as_ref()
@@ -85,7 +86,7 @@ pub async fn require_admin(
pub async fn require_authenticated(
state: &AppState,
headers: &HeaderMap,
) -> Result<(Uuid, String), AppError> {
) -> Result<(Uuid, SmolStr), AppError> {
let auth = state
.auth_service
.as_ref()
+8 -4
View File
@@ -204,10 +204,14 @@ pub async fn auth_middleware(
LiveRole::Active(role) => role,
LiveRole::Revoked => return Err(AuthError::AccountInactive),
};
// `username`/`email` are `Arc<str>` refcount
// bumps out of the cached claims; `role` is an
// inline SmolStr — the whole build is 1 alloc
// (the `Arc::new`) instead of 4.
let current_user = Arc::new(CurrentUser {
id: user_id,
username: claims.username.clone(),
email: claims.email.clone(),
username: Arc::clone(&claims.username),
email: Arc::clone(&claims.email),
role,
});
request.extensions_mut().insert(current_user);
@@ -319,8 +323,8 @@ pub async fn auth_middleware(
LiveRole::Active(role) => {
let current_user = Arc::new(CurrentUser {
id: user_id,
username: claims.username.clone(),
email: claims.email.clone(),
username: Arc::clone(&claims.username),
email: Arc::clone(&claims.email),
role,
});
request.extensions_mut().insert(current_user);
+5 -2
View File
@@ -69,8 +69,11 @@ pub struct UuidRequestId;
impl MakeRequestId for UuidRequestId {
fn make_request_id<B>(&mut self, _request: &axum::http::Request<B>) -> Option<RequestId> {
let id = Uuid::now_v7().to_string();
axum::http::HeaderValue::from_str(&id)
// Stack-encode the UUID: `to_string()` allocated an intermediate
// String per request just for HeaderValue to copy it again.
let mut buf = [0u8; uuid::fmt::Hyphenated::LENGTH];
let id = Uuid::now_v7();
axum::http::HeaderValue::from_str(id.hyphenated().encode_lower(&mut buf))
.ok()
.map(RequestId::new)
}
+9 -7
View File
@@ -27,6 +27,7 @@ use axum::extract::{Request, State};
use axum::http::StatusCode;
use axum::middleware::Next;
use axum::response::{IntoResponse, Response};
use smol_str::SmolStr;
use std::sync::Arc;
use uuid::Uuid;
@@ -109,8 +110,9 @@ pub async fn require_admin_user(
pub enum LiveRole {
/// The account exists and is active. Carries the caller's *current*
/// role string (`"admin"` / `"user"`), which is authoritative and
/// supersedes the — possibly stale — JWT `role` claim.
Active(String),
/// supersedes the — possibly stale — JWT `role` claim. `SmolStr` so the
/// per-request render of the (≤23-byte) role never heap-allocates.
Active(SmolStr),
/// The account is deactivated or deleted: the request must be rejected
/// even though its token is still cryptographically valid.
Revoked,
@@ -152,7 +154,7 @@ fn decide_live_role(
claim_role: &str,
) -> LiveRole {
match flags {
Ok(flags) if flags.active => LiveRole::Active(flags.role.to_string()),
Ok(flags) if flags.active => LiveRole::Active(SmolStr::new_static(flags.role.as_str())),
Ok(_) => {
audit_token_revoked(user_id, "deactivated");
LiveRole::Revoked
@@ -170,7 +172,7 @@ fn decide_live_role(
error = %e,
"live-user re-check failed transiently; allowing request on the JWT claim role (fail-open)"
);
LiveRole::Active(claim_role.to_string())
LiveRole::Active(SmolStr::new(claim_role))
}
}
}
@@ -257,14 +259,14 @@ mod tests {
let live = decide_live_role(Ok(flags(UserRole::Admin, true)), Uuid::nil(), "user");
// The live record wins over the (stale) claim — a freshly promoted
// user is admin even though their token still says "user".
assert_eq!(live, LiveRole::Active("admin".to_string()));
assert_eq!(live, LiveRole::Active(SmolStr::new_static("admin")));
}
#[test]
fn active_user_yields_current_user_role() {
// A demoted admin: token claim still "admin", live record "user".
let live = decide_live_role(Ok(flags(UserRole::User, true)), Uuid::nil(), "admin");
assert_eq!(live, LiveRole::Active("user".to_string()));
assert_eq!(live, LiveRole::Active(SmolStr::new_static("user")));
}
#[test]
@@ -285,6 +287,6 @@ mod tests {
// A DB blip must not lock everyone out: allow on the claim role.
let err = DomainError::new(ErrorKind::InternalError, "User", "connection reset");
let live = decide_live_role(Err(err), Uuid::nil(), "admin");
assert_eq!(live, LiveRole::Active("admin".to_string()));
assert_eq!(live, LiveRole::Active(SmolStr::new_static("admin")));
}
}
+79 -31
View File
@@ -1,13 +1,32 @@
use axum::{
extract::{Path, State},
http::{StatusCode, header},
http::{HeaderMap, StatusCode, header},
response::{IntoResponse, Response},
};
use base64::Engine;
use bytes::Bytes;
use std::sync::Arc;
use crate::common::di::AppState;
/// Transcoded-avatar memo: `blake3(stored data URI)` → PNG bytes.
///
/// The WebP→PNG transcode below is a full image decode + PNG encode (tens
/// of ms of CPU) that used to run on EVERY avatar request once the
/// client's 1 h cache lapsed — per client, per surface. Avatars are tiny
/// and rarely change; 32 entries bounds the memo to a few MB.
static AVATAR_PNG_CACHE: std::sync::OnceLock<moka::sync::Cache<[u8; 32], Bytes>> =
std::sync::OnceLock::new();
fn avatar_png_cache() -> &'static moka::sync::Cache<[u8; 32], Bytes> {
AVATAR_PNG_CACHE.get_or_init(|| {
moka::sync::Cache::builder()
.max_capacity(32)
.time_to_live(std::time::Duration::from_secs(24 * 3600))
.build()
})
}
/// Re-encode WebP image bytes as PNG. Returns `None` on decode/encode
/// failure (treated upstream as "fall through to SVG" — a bad stored
/// blob shouldn't break the rendering pipeline). PNG is universal:
@@ -77,10 +96,11 @@ fn parse_data_uri(uri: &str) -> Option<(String, Vec<u8>)> {
pub async fn handle_dav_avatar(
state: State<Arc<AppState>>,
Path((username, size_with_ext)): Path<(String, String)>,
headers: HeaderMap,
) -> Response {
let size_str = size_with_ext.strip_suffix(".png").unwrap_or(&size_with_ext);
let size: u32 = size_str.parse().unwrap_or(64);
handle_avatar(state, Path((username, size))).await
handle_avatar(state, Path((username, size)), headers).await
}
/// GET /index.php/avatar/{user}/{size}
@@ -98,6 +118,7 @@ pub async fn handle_dav_avatar(
pub async fn handle_avatar(
State(state): State<Arc<AppState>>,
Path((username, size)): Path<(String, u32)>,
headers: HeaderMap,
) -> Response {
let size = size.clamp(16, 1024);
@@ -113,39 +134,66 @@ pub async fn handle_avatar(
.get_user_by_username(&username)
.await
&& let Some(image_uri) = user.image.as_deref()
&& let Some((mime, bytes)) = parse_data_uri(image_uri)
{
// WebP is OxiCloud's storage format of choice (smaller files,
// better quality at a given size) but NextCloud clients have
// patchy WebP support — older Qt-based desktop builds, some
// mobile image stacks. Transcode to PNG before serving on the
// NC surface so every client renders it. PNG is bigger on the
// wire but small enough at avatar dimensions that the
// tradeoff is worth it. Decode failure falls through to SVG.
let (final_mime, final_bytes): (&str, Vec<u8>) = if mime == "image/webp" {
match webp_to_png(&bytes) {
Some(png) => ("image/png", png),
None => return svg_initials_response(&username, size),
}
} else {
// Whatever MIME we stored (`image/png`, `image/jpeg`,
// `image/gif`) is universally supported by NC clients.
// The `mime` String is moved out via `.as_str()` here, so
// bind it locally to keep the borrow alive for the response.
(mime_as_static_str(&mime), bytes)
};
return (
StatusCode::OK,
[
(header::CONTENT_TYPE, final_mime),
// Content-derived ETag over the STORED value — computable before
// any base64 decode or image work. NC desktop/mobile revalidate
// avatars every cache lapse (1 h) per surface; this endpoint used
// to re-decode (and for WebP re-transcode to PNG — a full image
// decode + encode) and re-ship the body every time (ROUND10).
let content_hash: [u8; 32] = blake3::hash(image_uri.as_bytes()).into();
let etag = format!(
"\"av-{}\"",
crate::common::fmt::hex_lower(&content_hash[..12])
);
if let Some(inm) = headers.get(header::IF_NONE_MATCH)
&& let Ok(client_etag) = inm.to_str()
&& (client_etag == etag || client_etag == "*")
{
return Response::builder()
.status(StatusCode::NOT_MODIFIED)
.header(header::CACHE_CONTROL, "public, max-age=3600")
.header(header::ETAG, etag)
.body(axum::body::Body::empty())
.unwrap();
}
if let Some((mime, bytes)) = parse_data_uri(image_uri) {
// WebP is OxiCloud's storage format of choice (smaller files,
// better quality at a given size) but NextCloud clients have
// patchy WebP support — older Qt-based desktop builds, some
// mobile image stacks. Transcode to PNG before serving on the
// NC surface so every client renders it. The transcode result
// is memoised by content hash — decode+encode ran per request
// before. Decode failure falls through to SVG.
let (final_mime, final_bytes): (&str, Bytes) = if mime == "image/webp" {
if let Some(png) = avatar_png_cache().get(&content_hash) {
("image/png", png)
} else {
match webp_to_png(&bytes) {
Some(png) => {
let png = Bytes::from(png);
avatar_png_cache().insert(content_hash, png.clone());
("image/png", png)
}
None => return svg_initials_response(&username, size),
}
}
} else {
// Whatever MIME we stored (`image/png`, `image/jpeg`,
// `image/gif`) is universally supported by NC clients.
(mime_as_static_str(&mime), Bytes::from(bytes))
};
return Response::builder()
.status(StatusCode::OK)
.header(header::CONTENT_TYPE, final_mime)
// Shorter cache than the SVG fallback because users can
// re-upload their picture at any time — the URL is the
// same so a long immutable cache would pin the old one.
(header::CACHE_CONTROL, "public, max-age=3600"),
],
final_bytes,
)
.into_response();
.header(header::CACHE_CONTROL, "public, max-age=3600")
.header(header::ETAG, etag)
.body(axum::body::Body::from(final_bytes))
.unwrap();
}
}
svg_initials_response(&username, size)
+7 -7
View File
@@ -339,9 +339,9 @@ pub async fn handle_oidc_login_completion(
let current_user = CurrentUser {
id: user_id,
username: username.to_string(),
email: user_dto.email.clone(),
role: user_dto.role.clone(),
username: std::sync::Arc::from(username),
email: std::sync::Arc::from(user_dto.email.as_str()),
role: smol_str::SmolStr::new(&user_dto.role),
};
let drives = match state
@@ -438,7 +438,7 @@ async fn complete_flow(
let login_name = match drive_id {
Some(uuid) => format!("{}~{}", user.username, uuid),
None => user.username.clone(),
None => user.username.to_string(),
};
let base_url = state.core.config.base_url();
@@ -550,9 +550,9 @@ pub async fn handle_drive_pick(
};
let user = CurrentUser {
id: user_id,
username,
email: user_dto.email.clone(),
role: user_dto.role.clone(),
username: std::sync::Arc::from(username.as_str()),
email: std::sync::Arc::from(user_dto.email.as_str()),
role: smol_str::SmolStr::new(&user_dto.role),
};
let _folder = match state
+3 -3
View File
@@ -109,11 +109,11 @@ pub async fn handle_user_info(
// than the raw UUID the wire form carries.
let id = session.raw_username.clone();
let displayname = if session.is_home() {
session.user.username.clone()
session.user.username.to_string()
} else {
match session.chroot.as_ref() {
Some(chroot) => format!("{}@{}", session.user.username, chroot.name),
None => session.user.username.clone(),
None => session.user.username.to_string(),
}
};
@@ -356,7 +356,7 @@ pub async fn handle_sharees_search(
.into_iter()
.filter_map(|u| {
let handle = u.username.clone()?;
if handle == user.username {
if handle.as_str() == &*user.username {
return None;
}
Some(json!({
+31 -13
View File
@@ -5,7 +5,7 @@
use axum::{
body::Body,
extract::{Query, State},
http::{StatusCode, header},
http::{HeaderMap, StatusCode, header},
response::{IntoResponse, Response},
};
use serde::Deserialize;
@@ -39,6 +39,7 @@ pub async fn handle_preview(
State(state): State<Arc<AppState>>,
user: AuthUser,
Query(params): Query<PreviewParams>,
headers: HeaderMap,
) -> impl IntoResponse {
// Parse the Nextcloud file ID — the NC app may append an instance suffix
// (e.g. "00000326ocnca"), so strip non-digit characters first.
@@ -135,6 +136,27 @@ pub async fn handle_preview(
}
};
// Conditional revalidation — the ETag is derived from (object id, size)
// only, so it is computable right here, BEFORE the blob-hash query and
// the thumbnail cache/disk read. NC clients revalidate gallery previews
// constantly; the REST thumbnail endpoint has honoured `If-None-Match`
// since PHOTOS-ETAG — this endpoint set an immutable ETag but never
// compared it, so every revalidation re-ran the whole pipeline and
// re-shipped the body (ROUND10). Authz already passed above; a 304
// must never skip the Read check.
let etag = format!("\"thumb-{}-{:?}\"", object_id, thumb_size);
if let Some(inm) = headers.get(header::IF_NONE_MATCH)
&& let Ok(client_etag) = inm.to_str()
&& (client_etag == etag || client_etag == "*")
{
return Response::builder()
.status(StatusCode::NOT_MODIFIED)
.header(header::CACHE_CONTROL, "public, max-age=31536000, immutable")
.header(header::ETAG, etag)
.body(Body::empty())
.unwrap();
}
// Check if file is an image
if !state
.core
@@ -175,7 +197,6 @@ pub async fn handle_preview(
)
.await
{
let etag = format!("\"thumb-{}-{:?}\"", object_id, thumb_size);
return Response::builder()
.status(StatusCode::OK)
.header(header::CONTENT_TYPE, "image/jpeg")
@@ -201,17 +222,14 @@ pub async fn handle_preview(
)
.await
{
Ok(data) => {
let etag = format!("\"thumb-{}-{:?}\"", object_id, thumb_size);
Response::builder()
.status(StatusCode::OK)
.header(header::CONTENT_TYPE, "image/jpeg")
.header(header::CONTENT_LENGTH, data.len())
.header(header::CACHE_CONTROL, "public, max-age=31536000, immutable")
.header(header::ETAG, etag)
.body(Body::from(data))
.unwrap()
}
Ok(data) => Response::builder()
.status(StatusCode::OK)
.header(header::CONTENT_TYPE, "image/jpeg")
.header(header::CONTENT_LENGTH, data.len())
.header(header::CACHE_CONTROL, "public, max-age=31536000, immutable")
.header(header::ETAG, etag)
.body(Body::from(data))
.unwrap(),
Err(err) => {
tracing::error!("Thumbnail generation failed for {}: {}", object_id, err);
Response::builder()
+16 -11
View File
@@ -16,7 +16,7 @@ use crate::common::di::AppState;
use crate::interfaces::errors::AppError;
use crate::interfaces::nextcloud::webdav_handler::{
batch_resolve_ids, extract_nc_subpath_from_dest, format_oc_id, nc_id_of, nc_to_internal_path,
write_text_element,
write_date_element, write_etag_element, write_text_element,
};
const HEADER_DAV: HeaderName = HeaderName::from_static("dav");
@@ -445,11 +445,12 @@ fn write_trash_item_response<W: std::io::Write>(
// d:displayname
write_text_element(xml, "d:displayname", &item.name)?;
// d:getlastmodified
write_text_element(xml, "d:getlastmodified", &item.trashed_at.to_rfc2822())?;
// d:getlastmodified — stack-rendered (common::fmt), chrono fallback for
// out-of-range timestamps; byte-identical to the old `to_rfc2822()`.
write_date_element(xml, "d:getlastmodified", item.trashed_at.timestamp(), true)?;
// d:getetag
write_text_element(xml, "d:getetag", &format!("\"{}\"", item.original_id))?;
// d:getetag — exact-size quoted alloc instead of the format! interpreter.
write_etag_element(xml, "d:getetag", &item.original_id)?;
// d:resourcetype
if item.item_type == "folder" {
@@ -478,7 +479,8 @@ fn write_trash_item_response<W: std::io::Write>(
// oc:fileid and oc:id — resolved up front in a batch query.
let file_id = nc_id_of(id_map, &item.original_id);
if let Some(id) = file_id {
write_text_element(xml, "oc:fileid", &id.to_string())?;
let mut ibuf = [0u8; 21];
write_text_element(xml, "oc:fileid", crate::common::fmt::i64_str(&mut ibuf, id))?;
let oc_id = format_oc_id(id, file_id_svc);
write_text_element(xml, "oc:id", &oc_id)?;
}
@@ -491,11 +493,14 @@ fn write_trash_item_response<W: std::io::Write>(
write_text_element(xml, "nc:trashbin-original-location", original_location)?;
// nc:trashbin-deletion-time
write_text_element(
xml,
"nc:trashbin-deletion-time",
&item.trashed_at.timestamp().to_string(),
)?;
{
let mut ibuf = [0u8; 21];
write_text_element(
xml,
"nc:trashbin-deletion-time",
crate::common::fmt::i64_str(&mut ibuf, item.trashed_at.timestamp()),
)?;
}
// oc:permissions — empty in trash
write_text_element(xml, "oc:permissions", "")?;
+5 -4
View File
@@ -325,15 +325,16 @@ async fn handle_put_chunk(
.map_err(|e| AppError::bad_request(format!("Invalid chunk path: {}", e)))?;
let max_chunk = state.core.config.storage.chunk_max_bytes;
// A re-PUT of an existing chunk (client retry) makes the running
// session counter stale — drop it so the next gate rebuilds from disk.
let overwrite = tokio::fs::metadata(&chunk_path).await.is_ok();
// No client-side integrity contract on the NC chunked surface — the
// NC desktop client validates the assembled-file ETag against the
// server-side `oc:checksums` after MOVE. So we skip per-chunk
// hashing here (peak heap stays at ~one HTTP frame).
//
// Retry detection (a re-PUT makes the running session counter stale)
// rides on the open itself now — `created_fresh` from the `create_new`
// probe replaces the extra per-chunk `stat` this path used to issue.
let streamed = stream_body_to_path(req.into_body(), &chunk_path, max_chunk, None).await?;
if overwrite {
if !streamed.created_fresh {
nc.chunked_uploads
.forget_session_bytes(&user.username, upload_id);
} else {
+48 -18
View File
@@ -1510,16 +1510,24 @@ fn build_nc_streaming_propfind(
// ── <d:multistatus> + the folder's own entry ─────────────────
// Collection hrefs MUST end in `/` (RFC 4918 §5.2 + strict
// NC-client enforcement — see `nc_collection_href`).
let folder_favs = if let Some(fav) = fav_svc {
fav.batch_check_favorites(user_id, &[(folder.id.as_str(), "folder")])
.await
.unwrap_or_default()
} else {
HashSet::new()
};
let (_, folder_id_map) =
batch_resolve_ids(file_id_svc, &[], &[folder.id.as_str()]).await;
let folder_dead = folder_dead_props(&state.webdav_dead_props, &folder).await;
// Same three independent reads as the per-page child triple below,
// and on the critical path of EVERY folder PROPFIND's first byte —
// overlapped with `join!` (ROUND10; the header trio was left serial
// when ROUND9 converted the page loops).
let folder_id_arr = [folder.id.as_str()];
let (folder_favs, (_, folder_id_map), folder_dead) = tokio::join!(
async {
if let Some(fav) = fav_svc {
fav.batch_check_favorites(user_id, &[(folder.id.as_str(), "folder")])
.await
.unwrap_or_default()
} else {
HashSet::new()
}
},
batch_resolve_ids(file_id_svc, &[], &folder_id_arr),
folder_dead_props(&state.webdav_dead_props, &folder),
);
let mut buf = Vec::with_capacity(4096);
{
@@ -1756,7 +1764,8 @@ pub fn write_folder_response<W: std::io::Write>(
// Nextcloud/ownCloud properties
if let Some(id) = file_id {
write_text_element(xml, "oc:fileid", &id.to_string())?;
let mut buf = [0u8; 21];
write_text_element(xml, "oc:fileid", crate::common::fmt::i64_str(&mut buf, id))?;
}
if let Some(oid) = oc_id {
write_text_element(xml, "oc:id", oid)?;
@@ -1770,9 +1779,18 @@ pub fn write_folder_response<W: std::io::Write>(
// surface's `write_folder_standard_props` (see
// `AppState::resolve_webdav_quota`).
if let Some((used, available)) = quota {
write_text_element(xml, "d:quota-used-bytes", &used.to_string())?;
let mut buf = [0u8; 21];
write_text_element(
xml,
"d:quota-used-bytes",
crate::common::fmt::i64_str(&mut buf, used),
)?;
if let Some(avail) = available {
write_text_element(xml, "d:quota-available-bytes", &avail.to_string())?;
write_text_element(
xml,
"d:quota-available-bytes",
crate::common::fmt::i64_str(&mut buf, avail),
)?;
}
}
write_text_element(xml, "oc:owner-id", owner)?;
@@ -1858,7 +1876,8 @@ pub fn write_file_response<W: std::io::Write>(
// Nextcloud/ownCloud properties
if let Some(id) = file_id {
write_text_element(xml, "oc:fileid", &id.to_string())?;
let mut buf = [0u8; 21];
write_text_element(xml, "oc:fileid", crate::common::fmt::i64_str(&mut buf, id))?;
}
if let Some(oid) = oc_id {
write_text_element(xml, "oc:id", oid)?;
@@ -1900,8 +1919,19 @@ pub fn write_file_response<W: std::io::Write>(
write_text_element(xml, "nc:is-encrypted", "0")?;
write_text_element(xml, "nc:mount-type", "")?;
write_text_element(xml, "nc:creation_time", &file.created_at.to_string())?;
write_text_element(xml, "nc:upload_time", &file.modified_at.to_string())?;
{
let mut buf = [0u8; 20];
write_text_element(
xml,
"nc:creation_time",
crate::common::fmt::u64_str(&mut buf, file.created_at),
)?;
write_text_element(
xml,
"nc:upload_time",
crate::common::fmt::u64_str(&mut buf, file.modified_at),
)?;
}
xml.write_event(Event::End(BytesEnd::new("d:prop")))
.xml_err()?;
@@ -1921,7 +1951,7 @@ pub fn write_file_response<W: std::io::Write>(
/// (`common::fmt`) — the old per-row `to_rfc2822()` / `to_rfc3339()`
/// ran chrono's format interpreter and allocated a String each.
/// Out-of-range timestamps keep the chrono path, byte-identical.
fn write_date_element<W: std::io::Write>(
pub fn write_date_element<W: std::io::Write>(
xml: &mut Writer<W>,
tag: &str,
secs: i64,
@@ -1946,7 +1976,7 @@ fn write_date_element<W: std::io::Write>(
/// `d:getetag` with the HTTP quoting — one exactly-sized allocation
/// instead of `format!`'s grow-from-empty.
fn write_etag_element<W: std::io::Write>(
pub fn write_etag_element<W: std::io::Write>(
xml: &mut Writer<W>,
tag: &str,
etag: &str,
+30 -2
View File
@@ -291,6 +291,10 @@ pub fn stream_from_files(
pub struct StreamedToPath {
/// Total bytes written.
pub bytes_written: u64,
/// `true` when the destination did not exist before this call — the
/// open itself detects it (`create_new` + AlreadyExists fallback), so
/// retry-detection callers don't need a separate `stat` per chunk.
pub created_fresh: bool,
/// Lowercase hex digest, populated only when `checksum_alg=Some(_)`
/// was passed. The algorithm is identified by [`StreamedToPath::alg`].
pub checksum_hex: Option<String>,
@@ -329,9 +333,32 @@ pub async fn stream_body_to_path(
// per frame (benches/UPLOAD-SPOOL.md). Same capacity as the dedup
// handler's spool loop. On the error paths below the partial file is
// removed, so silently dropping unflushed buffer contents is fine.
let file = tokio::fs::File::create(path)
//
// `create_new` first: the common fresh-chunk case stays one open AND
// doubles as the retry probe (AlreadyExists → truncate-open), so callers
// that need overwrite detection no longer pay a separate stat per chunk.
let (file, created_fresh) = match tokio::fs::OpenOptions::new()
.write(true)
.create_new(true)
.open(path)
.await
.map_err(|e| AppError::internal_error(format!("Failed to open chunk file: {e}")))?;
{
Ok(f) => (f, true),
Err(e) if e.kind() == std::io::ErrorKind::AlreadyExists => {
let f = tokio::fs::OpenOptions::new()
.write(true)
.truncate(true)
.open(path)
.await
.map_err(|e| AppError::internal_error(format!("Failed to open chunk file: {e}")))?;
(f, false)
}
Err(e) => {
return Err(AppError::internal_error(format!(
"Failed to open chunk file: {e}"
)));
}
};
let mut file = tokio::io::BufWriter::with_capacity(512 * 1024, file);
let mut total_bytes: usize = 0;
@@ -377,6 +404,7 @@ pub async fn stream_body_to_path(
Ok(StreamedToPath {
bytes_written: total_bytes as u64,
created_fresh,
checksum_hex: hasher.map(IncrementalHasher::finalize_hex),
alg: checksum_alg,
})