Skip to main content

Module sqlite

Module sqlite 

Source
Expand description

Persistence: one module per table, over sqlx and SQLite.

Queries are built with the runtime sqlx::query API rather than the compile-time macros, so DATABASE_URL is not needed to build the crate. Migrations are embedded and run at startup — see db.

Two invariants shape almost everything here:

  • A profile is a data boundary. accounts and orders carry a profile column and accounts is keyed UNIQUE(profile, pubkey), so one client key at two endpoints is two unrelated accounts. Request-path lookups always take the profile; the admin layer uses the deliberately unscoped find_any_* variants.
  • audit rows outlive their subjects. That table has no foreign keys, because a CASCADE would delete the evidence along with the account or order it describes. It is INSERT-only: there is no setter and no UPDATE against it anywhere in the crate.

Methods return Result<_, sqlx::Error> and leave the mapping to a crate::error::Problem to their caller.

Modules§

account
admin_recovery_code
admin_session
admin_user
audit
The audit_log model: append, read back, purge by age.
authz
db
eab
job
The jobs model: the durable queue behind crate::jobs.
nonce
order
status
The three ACME state machines, as types rather than strings.
upstream_order
The mapping between a local order and the order the relay signer backend opened for it at the upstream CA.