The runtime half — suppressions now actually decline inherited templates. - Triggers (live, per-event): a correlated NOT EXISTS anti-join (TRIGGER_SUPPRESSION_ANTIJOIN) appended to all four dispatch match queries (list_matching_kv/docs/files + the pubsub fan-out). It excludes a group-owned trigger whose handler script name the firing app suppresses; `$1` is the firing app (already bound), and the `t.group_id IS NOT NULL` guard keeps an app's OWN trigger unsuppressable. - Routes (rebuild-time): compile_effective_routes takes a `suppressed_paths: &HashSet<(AppId, path)>` and drops an inherited (`depth > 0`) route at a suppressed path — the binding 404s. rebuild_route_table loads the set via a new RouteRepository::list_route_suppressions, so every existing rebuild edge (route CRUD, apply, tree mutations) already applies it. No new invalidation edges; the marker CASCADEs on app delete. Pinned by tests/template_suppression.rs (live DB): a suppressing app matches NEITHER the inherited trigger NOR route; a sibling that did not suppress still inherits both; the app's OWN trigger on the suppressed handler still fires (suppression is inheritance-only). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
130 lines
4.5 KiB
Rust
130 lines
4.5 KiB
Rust
//! `PubsubRepo` — publish-time fan-out for the v1.1.5 `pubsub::*` SDK.
|
|
//!
|
|
//! `publish_durable` writes one outbox row per matching enabled `pubsub`
|
|
//! trigger, all inside a single transaction so a partial fan-out (some
|
|
//! subscribers got rows, others didn't, then a crash) can't happen.
|
|
//! Each delivery row then retries / dead-letters independently through
|
|
//! the existing dispatcher — no pub/sub-specific dispatch branching.
|
|
//!
|
|
//! Topic pattern matching runs in Rust (`picloud_shared::topic_matches`)
|
|
//! against the small set of the app's enabled pubsub triggers, keeping
|
|
//! the SELECT trivial. v1.2 can add a topic-trie index if fan-out
|
|
//! becomes a hot path.
|
|
|
|
use async_trait::async_trait;
|
|
use picloud_shared::{topic_matches, AdminUserId, AppId, ExecutionId};
|
|
use sqlx::PgPool;
|
|
use uuid::Uuid;
|
|
|
|
use crate::config_resolver::CHAIN_LEVELS_CTE;
|
|
|
|
#[derive(Debug, thiserror::Error)]
|
|
pub enum PubsubRepoError {
|
|
#[error("database error: {0}")]
|
|
Db(#[from] sqlx::Error),
|
|
}
|
|
|
|
/// The execution-context bits a fan-out needs to stamp onto each outbox
|
|
/// row. Derived from the publishing script's `SdkCallCx`.
|
|
#[derive(Debug, Clone, Copy)]
|
|
pub struct PublishCtx {
|
|
pub app_id: AppId,
|
|
pub origin_principal: Option<AdminUserId>,
|
|
pub trigger_depth: u32,
|
|
pub root_execution_id: ExecutionId,
|
|
}
|
|
|
|
#[async_trait]
|
|
pub trait PubsubRepo: Send + Sync {
|
|
/// Fan out a publish to every matching enabled pubsub trigger in
|
|
/// `ctx.app_id`, inserting one outbox row each in a SINGLE
|
|
/// transaction. `event_payload` is the serialized
|
|
/// `TriggerEvent::Pubsub`. Returns the number of delivery rows
|
|
/// written (0 when no trigger matched — the publish still succeeds).
|
|
async fn fan_out_publish(
|
|
&self,
|
|
ctx: PublishCtx,
|
|
topic: &str,
|
|
event_payload: serde_json::Value,
|
|
) -> Result<u32, PubsubRepoError>;
|
|
}
|
|
|
|
pub struct PostgresPubsubRepo {
|
|
pool: PgPool,
|
|
}
|
|
|
|
impl PostgresPubsubRepo {
|
|
#[must_use]
|
|
pub fn new(pool: PgPool) -> Self {
|
|
Self { pool }
|
|
}
|
|
}
|
|
|
|
#[derive(sqlx::FromRow)]
|
|
struct PubsubTriggerRow {
|
|
id: Uuid,
|
|
script_id: Uuid,
|
|
topic_pattern: String,
|
|
}
|
|
|
|
#[async_trait]
|
|
impl PubsubRepo for PostgresPubsubRepo {
|
|
async fn fan_out_publish(
|
|
&self,
|
|
ctx: PublishCtx,
|
|
topic: &str,
|
|
event_payload: serde_json::Value,
|
|
) -> Result<u32, PubsubRepoError> {
|
|
let mut tx = self.pool.begin().await?;
|
|
|
|
// Load all enabled pubsub triggers for the app; filter by topic
|
|
// pattern in Rust (keeps the query simple, honours the
|
|
// empty/`*`/prefix semantics without teaching SQL about globs).
|
|
// §11 tail: the chain union picks up the app's own pubsub triggers AND
|
|
// ancestor-group pubsub TEMPLATES (live, no materialization). The outbox
|
|
// row below stamps the firing `ctx.app_id`, so a template runs under the
|
|
// publishing app — the inheriting-app boundary. The suppression
|
|
// anti-join drops an inherited template whose handler the app opts out
|
|
// of (`$1` = ctx.app_id).
|
|
let rows: Vec<PubsubTriggerRow> = sqlx::query_as(&format!(
|
|
"{CHAIN_LEVELS_CTE} \
|
|
SELECT t.id, t.script_id, d.topic_pattern \
|
|
FROM triggers t \
|
|
JOIN pubsub_trigger_details d ON d.trigger_id = t.id \
|
|
JOIN chain c ON (t.app_id = c.app_owner OR t.group_id = c.group_owner) \
|
|
WHERE t.kind = 'pubsub' AND t.enabled = TRUE{ANTIJOIN}",
|
|
ANTIJOIN = crate::trigger_repo::TRIGGER_SUPPRESSION_ANTIJOIN,
|
|
))
|
|
.bind(ctx.app_id.into_inner())
|
|
.fetch_all(&mut *tx)
|
|
.await?;
|
|
|
|
let mut written: u32 = 0;
|
|
for r in rows {
|
|
if !topic_matches(&r.topic_pattern, topic) {
|
|
continue;
|
|
}
|
|
sqlx::query(
|
|
"INSERT INTO outbox ( \
|
|
app_id, source_kind, trigger_id, script_id, reply_to, \
|
|
payload, origin_principal, trigger_depth, root_execution_id \
|
|
) VALUES ($1, 'pubsub', $2, $3, NULL, $4, $5, $6, $7)",
|
|
)
|
|
.bind(ctx.app_id.into_inner())
|
|
.bind(r.id)
|
|
.bind(r.script_id)
|
|
.bind(&event_payload)
|
|
.bind(ctx.origin_principal.map(AdminUserId::into_inner))
|
|
.bind(i32::try_from(ctx.trigger_depth.saturating_add(1)).unwrap_or(1))
|
|
.bind(ctx.root_execution_id.into_inner())
|
|
.execute(&mut *tx)
|
|
.await?;
|
|
written += 1;
|
|
}
|
|
|
|
// Commit once — all rows or none.
|
|
tx.commit().await?;
|
|
Ok(written)
|
|
}
|
|
}
|