Skip to main content

apiplant_db/
seed.rs

1//! Seed data: an app's `seed/` directory, loaded into the database.
2//!
3//! A seed directory holds one file per resource, named after it —
4//! `seed/organization.toml`, `seed/user.toml`, `seed/product.csv` — whose rows
5//! become that resource's rows. It is the fixture an app starts life with: an
6//! administrator who can sign in, the organisation they administer, and enough
7//! underneath for the dashboard to have something to show.
8//!
9//! TOML is the primary format, because it is the format the app is already
10//! written in — a seed file looks like the model beside it:
11//!
12//! ```toml
13//! [[row]]
14//! id = "acme"
15//! name = "Acme, Inc."
16//! slug = "acme"
17//! ```
18//!
19//! CSV is accepted for the same job at a hundred rows, where a header line and
20//! a column per field says it better than a hundred `[[row]]` headers — and
21//! because it is what a spreadsheet or a `COPY … TO` exports.
22//!
23//! Three things make either enough, without a migration format or a script per
24//! app:
25//!
26//! * **Aliases instead of UUIDs.** Anywhere an id is expected — the `id`
27//!   column, or any `reference` field — a value that is not a UUID is taken as
28//!   a name and hashed into one ([`uuid_for`]). `acme` means the same row in
29//!   every file, so `seed/membership.toml` can say `organization_id = "acme"`
30//!   without anyone minting a UUID by hand.
31//! * **Idempotence.** Because those ids are derived rather than random,
32//!   inserting is `ON CONFLICT DO NOTHING`: seeding twice inserts once, and a
33//!   seed file that grew a row since the last run adds only that row. Rows
34//!   already present are never overwritten — someone who edited the fixture in
35//!   the dashboard keeps their edit.
36//! * **Passwords.** A `password` column on a resource that declares one
37//!   ([`AuthSpec`](apiplant_core::schema::AuthSpec)) is hashed into the
38//!   password field, so the seeded administrator can actually sign in and the
39//!   file stays readable.
40//!
41//! Seeding runs in dependency order, so a file may reference rows from a file
42//! it is listed before.
43
44use apiplant_core::schema::FieldType;
45use apiplant_core::{App, Resource};
46use sea_orm::sea_query::Value as SqlValue;
47use sea_orm::{ConnectionTrait, DatabaseBackend, Statement};
48use serde_json::Value as Json;
49use std::path::{Path, PathBuf};
50use uuid::Uuid;
51
52use crate::ident::quote_ident;
53use crate::{value, Error};
54
55/// What one seed file did.
56#[derive(Debug, Clone)]
57pub struct FileReport {
58    pub resource: String,
59    /// Rows the database did not already have.
60    pub inserted: u64,
61    /// Rows whose id was already there, and were therefore left alone.
62    pub skipped: u64,
63}
64
65/// What a whole `seed/` directory did.
66#[derive(Debug, Clone, Default)]
67pub struct Report {
68    pub files: Vec<FileReport>,
69}
70
71impl Report {
72    pub fn inserted(&self) -> u64 {
73        self.files.iter().map(|f| f.inserted).sum()
74    }
75
76    pub fn skipped(&self) -> u64 {
77        self.files.iter().map(|f| f.skipped).sum()
78    }
79
80    /// True when there was no `seed/` directory, or nothing in it.
81    pub fn is_empty(&self) -> bool {
82        self.files.is_empty()
83    }
84}
85
86/// Load `<app>/seed/` into the database.
87///
88/// A missing directory is not an error — most apps have no fixture — but a file
89/// naming a resource the app does not define is, because a typo that silently
90/// seeds nothing is the whole failure mode this is meant to avoid.
91pub async fn seed(conn: &impl ConnectionTrait, app: &App) -> Result<Report, Error> {
92    seed_dir(conn, app, &app.root.join("seed")).await
93}
94
95/// Load a specific directory of seed files, for an app whose fixtures live
96/// somewhere other than `seed/`.
97pub async fn seed_dir(conn: &impl ConnectionTrait, app: &App, dir: &Path) -> Result<Report, Error> {
98    if !dir.is_dir() {
99        return Ok(Report::default());
100    }
101
102    // Collect `<resource>.{toml,csv}`, and refuse the ones that name nothing.
103    let mut files: Vec<(String, PathBuf)> = Vec::new();
104    let entries = std::fs::read_dir(dir)
105        .map_err(|e| Error::Schema(format!("cannot read {}: {e}", dir.display())))?;
106    for entry in entries {
107        let path = entry
108            .map_err(|e| Error::Schema(format!("cannot read {}: {e}", dir.display())))?
109            .path();
110        match path.extension().and_then(|e| e.to_str()) {
111            Some("toml") | Some("csv") => {}
112            _ => continue,
113        }
114        let name = path
115            .file_stem()
116            .and_then(|s| s.to_str())
117            .unwrap_or_default()
118            .to_string();
119        if !app.resources.contains_key(&name) {
120            return Err(Error::Schema(format!(
121                "{}: no resource named `{name}` — a seed file is named after the \
122                 resource it fills",
123                path.display()
124            )));
125        }
126        if let Some((_, other)) = files.iter().find(|(existing, _)| existing == &name) {
127            return Err(Error::Schema(format!(
128                "{name} is seeded twice, by {} and {} — one file per resource",
129                other.display(),
130                path.display()
131            )));
132        }
133        files.push((name, path));
134    }
135
136    // Parents before children, so a reference always finds its row.
137    let mut report = Report::default();
138    for resource in app.resources_in_dependency_order() {
139        let Some((_, path)) = files.iter().find(|(name, _)| name == &resource.meta.name) else {
140            continue;
141        };
142        let file = seed_file(conn, resource, path).await?;
143        tracing::info!(
144            resource = %file.resource,
145            inserted = file.inserted,
146            skipped = file.skipped,
147            "seeded"
148        );
149        report.files.push(file);
150    }
151    Ok(report)
152}
153
154/// One row on its way into the database: columns in file order, each value
155/// still in the shape its format produced.
156type Row = Vec<(String, Raw)>;
157
158/// A value as it was written, before it knows what column it is for.
159#[derive(Debug, Clone)]
160enum Raw {
161    /// From CSV: a string that the column's type will parse.
162    Text(String),
163    /// From TOML: already typed.
164    Typed(Json),
165}
166
167/// Seed one resource from its file.
168async fn seed_file(
169    conn: &impl ConnectionTrait,
170    r: &Resource,
171    path: &Path,
172) -> Result<FileReport, Error> {
173    let origin = path.display().to_string();
174    let text = std::fs::read_to_string(path)
175        .map_err(|e| Error::Schema(format!("cannot read {origin}: {e}")))?;
176    let rows = if path.extension().and_then(|e| e.to_str()) == Some("csv") {
177        csv_rows(&text)
178    } else {
179        toml_rows(&text)
180    }
181    .map_err(|e| Error::Schema(format!("{origin}: {e}")))?;
182
183    let password_field = r.auth.as_ref().map(|a| a.password_field.clone());
184    let table = quote_ident(&r.table_name())?;
185    let mut inserted = 0u64;
186    let mut skipped = 0u64;
187
188    for (index, row) in rows.into_iter().enumerate() {
189        let position = index + 1;
190        let mut columns: Vec<String> = Vec::new();
191        let mut params: Vec<SqlValue> = Vec::new();
192        let mut id = None;
193
194        for (column, raw) in row {
195            let known = column == "id"
196                || r.fields.contains_key(&column)
197                || (column == "password" && password_field.is_some());
198            if !known {
199                return Err(Error::Schema(format!(
200                    "{origin}: row {position}: `{column}` is not a field of `{}`",
201                    r.meta.name
202                )));
203            }
204            if column == "id" {
205                id = Some(uuid_for(&as_key(&raw).map_err(|e| {
206                    Error::Schema(format!("{origin}: row {position}: `id`: {e}"))
207                })?));
208                continue;
209            }
210            if Some(column.as_str()) == password_field.as_deref() {
211                return Err(Error::Schema(format!(
212                    "{origin}: row {position}: set `password` rather than `{column}` — \
213                     seeding hashes it"
214                )));
215            }
216            if column == "password" {
217                let field = password_field.as_deref().expect("checked just above");
218                let plaintext = as_key(&raw)
219                    .map_err(|e| Error::Schema(format!("{origin}: row {position}: {e}")))?;
220                let hash = apiplant_auth::Authenticator::hash_password_with_argon2(&plaintext)
221                    .map_err(|e| Error::Schema(format!("{origin}: row {position}: {e}")))?;
222                columns.push(field.to_string());
223                params.push(SqlValue::from(hash));
224                continue;
225            }
226
227            let field = &r.fields[&column];
228            let sql = to_sql(field.ty, &raw)
229                .map_err(|e| Error::Schema(format!("{origin}: row {position}: `{column}`: {e}")))?;
230            let Some(sql) = sql else { continue };
231            columns.push(column);
232            params.push(sql);
233        }
234
235        // Without an explicit id, the row is still given a derived one — from
236        // the resource and its position in the file — so that re-running the
237        // seed inserts nothing twice.
238        let id = id.unwrap_or_else(|| uuid_for(&format!("{}#{position}", r.meta.name)));
239        columns.insert(0, "id".to_string());
240        params.insert(0, SqlValue::from(id));
241
242        let quoted: Vec<String> = columns
243            .iter()
244            .map(|c| quote_ident(c))
245            .collect::<Result<_, _>>()?;
246        let placeholders: Vec<String> = (1..=quoted.len()).map(|n| format!("${n}")).collect();
247        let sql = format!(
248            "INSERT INTO {table} ({}) VALUES ({}) ON CONFLICT (\"id\") DO NOTHING",
249            quoted.join(", "),
250            placeholders.join(", ")
251        );
252        let result = conn
253            .execute(Statement::from_sql_and_values(
254                DatabaseBackend::Postgres,
255                sql,
256                params,
257            ))
258            .await?;
259        if result.rows_affected() > 0 {
260            inserted += 1;
261        } else {
262            skipped += 1;
263        }
264    }
265
266    Ok(FileReport {
267        resource: r.meta.name.clone(),
268        inserted,
269        skipped,
270    })
271}
272
273/// The string behind a value that has to be one — an id, an alias, a password.
274fn as_key(raw: &Raw) -> Result<String, String> {
275    match raw {
276        Raw::Text(s) => Ok(s.clone()),
277        Raw::Typed(Json::String(s)) => Ok(s.clone()),
278        Raw::Typed(_) => Err("expected a string".to_string()),
279    }
280}
281
282/// Convert one written value for one column, or `None` when the row leaves the
283/// column out and the database's own default should apply.
284fn to_sql(ty: FieldType, raw: &Raw) -> Result<Option<SqlValue>, String> {
285    // A reference or an id is written as the alias its target row uses, in
286    // either format.
287    if matches!(ty, FieldType::Reference | FieldType::Uuid) {
288        return Ok(Some(SqlValue::from(uuid_for(&as_key(raw)?))));
289    }
290    Ok(Some(match raw {
291        Raw::Text(s) if s.is_empty() => return Ok(None),
292        // CSV has one type; the column says what it means.
293        Raw::Text(s) if ty == FieldType::Json => {
294            SqlValue::from(serde_json::from_str::<Json>(s).map_err(|e| format!("not JSON: {e}"))?)
295        }
296        Raw::Text(s) => value::string_to_sql(ty, s)?,
297        Raw::Typed(Json::Null) => return Ok(None),
298        // TOML is typed, but a number written for a text column (a postcode, a
299        // version) is a spelling, not a mistake — so a scalar is accepted
300        // wherever a string is wanted.
301        Raw::Typed(v) if matches!(ty, FieldType::String | FieldType::Text) && !v.is_string() => {
302            match v {
303                Json::Object(_) | Json::Array(_) => return Err("expected a string".to_string()),
304                other => SqlValue::from(other.to_string()),
305            }
306        }
307        Raw::Typed(v) => value::json_to_sql(ty, v)?,
308    }))
309}
310
311/// Parse a TOML seed file: an array of `[[row]]` tables.
312///
313/// A datetime is handed on as its RFC 3339 text, which is what a `timestamp`
314/// column parses — so a seed file may write a bare TOML datetime and does not
315/// have to quote it.
316fn toml_rows(text: &str) -> Result<Vec<Row>, String> {
317    let doc: toml::Value = toml::from_str(text).map_err(|e| e.to_string())?;
318    let table = doc
319        .as_table()
320        .ok_or("expected a table of `[[row]]` entries")?;
321    for key in table.keys() {
322        if key != "row" {
323            return Err(format!(
324                "`{key}` is not `row` — a seed file is a list of `[[row]]` tables"
325            ));
326        }
327    }
328    let Some(rows) = table.get("row") else {
329        return Ok(Vec::new());
330    };
331    let rows = rows
332        .as_array()
333        .ok_or("`row` must be written as `[[row]]` tables")?;
334
335    rows.iter()
336        .enumerate()
337        .map(|(index, row)| {
338            let row = row
339                .as_table()
340                .ok_or_else(|| format!("row {} is not a table", index + 1))?;
341            Ok(row
342                .iter()
343                .map(|(k, v)| (k.clone(), Raw::Typed(toml_to_json(v))))
344                .collect())
345        })
346        .collect()
347}
348
349/// TOML's values as JSON's, which is the shape the column converters take.
350fn toml_to_json(v: &toml::Value) -> Json {
351    match v {
352        toml::Value::String(s) => Json::String(s.clone()),
353        toml::Value::Integer(i) => Json::from(*i),
354        toml::Value::Float(f) => Json::from(*f),
355        toml::Value::Boolean(b) => Json::Bool(*b),
356        // RFC 3339 text, which is what a timestamp column reads.
357        toml::Value::Datetime(d) => Json::String(d.to_string()),
358        toml::Value::Array(items) => Json::Array(items.iter().map(toml_to_json).collect()),
359        toml::Value::Table(t) => Json::Object(
360            t.iter()
361                .map(|(k, v)| (k.clone(), toml_to_json(v)))
362                .collect(),
363        ),
364    }
365}
366
367/// Parse a CSV seed file into the same rows a TOML one produces: the header
368/// names the columns, and each record pairs with it.
369fn csv_rows(text: &str) -> Result<Vec<Row>, String> {
370    let records = parse_csv(text)?;
371    let mut records = records.into_iter();
372    let Some(header) = records.next() else {
373        return Ok(Vec::new());
374    };
375    let header: Vec<String> = header
376        .into_iter()
377        .map(|c| c.text.trim().to_string())
378        .collect();
379
380    records
381        .enumerate()
382        .map(|(index, record)| {
383            if record.len() > header.len() {
384                return Err(format!(
385                    "row {}: {} values for {} columns",
386                    index + 1,
387                    record.len(),
388                    header.len()
389                ));
390            }
391            Ok(header
392                .iter()
393                .cloned()
394                .zip(record)
395                // An empty, unquoted cell is "no value" — the column is left
396                // out and the database's own default (or NULL) applies. `""`
397                // is an empty string, which is a different thing and sometimes
398                // what is wanted.
399                .filter(|(_, cell)| !cell.text.is_empty() || cell.quoted)
400                .map(|(column, cell)| (column, Raw::Text(cell.text)))
401                .collect())
402        })
403        .collect()
404}
405
406/// The id a seed file's key stands for.
407///
408/// A real UUID is itself, so a fixture may pin an id exactly. Anything else is
409/// a name — `acme`, `admin`, `widget-blue` — hashed into a UUID, the same one
410/// every time and on every machine. That determinism is what makes seeding
411/// idempotent and lets one file point at another's rows by a readable word.
412pub fn uuid_for(key: &str) -> Uuid {
413    if let Ok(uuid) = Uuid::parse_str(key) {
414        return uuid;
415    }
416    let digest = apiplant_auth::Authenticator::hash_api_key(&format!("apiplant-seed:{key}"));
417    let mut bytes = [0u8; 16];
418    for (i, byte) in bytes.iter_mut().enumerate() {
419        // The digest is hex, so two characters per byte.
420        *byte = u8::from_str_radix(&digest[i * 2..i * 2 + 2], 16).unwrap_or(0);
421    }
422    // Version 8 (custom) with the RFC 4122 variant: honest about being derived
423    // rather than random, and still a well-formed UUID to everything that
424    // looks at one.
425    bytes[6] = (bytes[6] & 0x0f) | 0x80;
426    bytes[8] = (bytes[8] & 0x3f) | 0x80;
427    Uuid::from_bytes(bytes)
428}
429
430/// One CSV cell, and whether it arrived quoted.
431#[derive(Debug, Clone, PartialEq, Eq)]
432struct Cell {
433    text: String,
434    quoted: bool,
435}
436
437/// Parse RFC 4180 CSV: commas separate, `"` quotes, `""` is a literal quote
438/// inside a quoted field, and a quoted field may span lines.
439///
440/// Two departures, both for files people edit by hand: a line whose first
441/// character is `#` is a comment, and a blank line is nothing at all.
442fn parse_csv(text: &str) -> Result<Vec<Vec<Cell>>, String> {
443    let mut rows: Vec<Vec<Cell>> = Vec::new();
444    let mut row: Vec<Cell> = Vec::new();
445    let mut cell = String::new();
446    let mut quoted = false;
447    let mut in_quotes = false;
448    // Only meaningful at the very start of a line, which is where the comment
449    // and blank-line rules apply.
450    let mut at_line_start = true;
451    let mut chars = text.chars().peekable();
452
453    while let Some(c) = chars.next() {
454        if at_line_start {
455            if c == '#' {
456                for c in chars.by_ref() {
457                    if c == '\n' {
458                        break;
459                    }
460                }
461                continue;
462            }
463            if c == '\n' {
464                continue;
465            }
466            if c == '\r' && chars.peek() == Some(&'\n') {
467                chars.next();
468                continue;
469            }
470            at_line_start = false;
471        }
472
473        if in_quotes {
474            if c == '"' {
475                if chars.peek() == Some(&'"') {
476                    chars.next();
477                    cell.push('"');
478                } else {
479                    in_quotes = false;
480                }
481            } else {
482                cell.push(c);
483            }
484            continue;
485        }
486
487        match c {
488            '"' if cell.is_empty() => {
489                in_quotes = true;
490                quoted = true;
491            }
492            '"' => return Err("a quote may only open a field".to_string()),
493            ',' => row.push(Cell {
494                text: std::mem::take(&mut cell),
495                quoted: std::mem::take(&mut quoted),
496            }),
497            '\r' if chars.peek() == Some(&'\n') => {}
498            '\n' => {
499                row.push(Cell {
500                    text: std::mem::take(&mut cell),
501                    quoted: std::mem::take(&mut quoted),
502                });
503                rows.push(std::mem::take(&mut row));
504                at_line_start = true;
505            }
506            _ => cell.push(c),
507        }
508    }
509
510    if in_quotes {
511        return Err("a quoted field was never closed".to_string());
512    }
513    // A file not ending in a newline still ends in a row.
514    if !cell.is_empty() || quoted || !row.is_empty() {
515        row.push(Cell { text: cell, quoted });
516        rows.push(row);
517    }
518    Ok(rows)
519}
520
521#[cfg(test)]
522mod tests {
523    use super::*;
524
525    fn cells(row: &[Cell]) -> Vec<&str> {
526        row.iter().map(|c| c.text.as_str()).collect()
527    }
528
529    fn column<'a>(row: &'a Row, name: &str) -> &'a Raw {
530        &row.iter().find(|(c, _)| c == name).expect("column").1
531    }
532
533    #[test]
534    fn parses_quotes_commas_and_newlines() {
535        let rows = parse_csv("a,b\n1,\"two, and\"\n\"line\nbreak\",\"say \"\"hi\"\"\"\n").unwrap();
536        assert_eq!(cells(&rows[0]), ["a", "b"]);
537        assert_eq!(cells(&rows[1]), ["1", "two, and"]);
538        assert_eq!(cells(&rows[2]), ["line\nbreak", "say \"hi\""]);
539    }
540
541    #[test]
542    fn comments_and_blank_lines_are_skipped() {
543        let rows = parse_csv("# a note\nname\n\nacme\n").unwrap();
544        assert_eq!(rows.len(), 2);
545        assert_eq!(cells(&rows[1]), ["acme"]);
546    }
547
548    #[test]
549    fn an_empty_csv_cell_is_left_out_but_an_empty_string_is_not() {
550        let rows = csv_rows("a,b\n,\"\"\n").unwrap();
551        assert!(rows[0].iter().all(|(c, _)| c != "a"));
552        assert!(matches!(column(&rows[0], "b"), Raw::Text(s) if s.is_empty()));
553    }
554
555    #[test]
556    fn a_final_row_without_a_newline_still_counts() {
557        assert_eq!(parse_csv("a\n1").unwrap().len(), 2);
558    }
559
560    #[test]
561    fn an_unterminated_quote_is_an_error() {
562        assert!(parse_csv("a\n\"oops\n").is_err());
563    }
564
565    #[test]
566    fn toml_rows_are_read_in_order_with_their_types() {
567        let rows = toml_rows(
568            r#"
569            [[row]]
570            id = "acme"
571            name = "Acme, Inc."
572            seats = 12
573            active = true
574
575            [[row]]
576            id = "globex"
577            name = "Globex"
578            "#,
579        )
580        .unwrap();
581        assert_eq!(rows.len(), 2);
582        assert!(matches!(
583            column(&rows[0], "seats"),
584            Raw::Typed(Json::Number(_))
585        ));
586        assert!(matches!(
587            column(&rows[0], "active"),
588            Raw::Typed(Json::Bool(true))
589        ));
590        assert!(matches!(column(&rows[1], "id"), Raw::Typed(Json::String(s)) if s == "globex"));
591    }
592
593    #[test]
594    fn a_toml_file_that_is_not_rows_says_so() {
595        let err = toml_rows("[[organization]]\nname = \"Acme\"\n").unwrap_err();
596        assert!(err.contains("`[[row]]`"), "{err}");
597    }
598
599    #[test]
600    fn a_toml_datetime_becomes_a_timestamp() {
601        let rows = toml_rows("[[row]]\nat = 2024-01-31T09:00:00Z\n").unwrap();
602        let sql = to_sql(FieldType::Timestamp, column(&rows[0], "at")).unwrap();
603        assert!(sql.is_some());
604    }
605
606    #[test]
607    fn a_number_is_accepted_where_a_string_column_wants_one() {
608        let rows = toml_rows("[[row]]\npostcode = 90210\n").unwrap();
609        let sql = to_sql(FieldType::String, column(&rows[0], "postcode")).unwrap();
610        assert_eq!(sql, Some(SqlValue::from("90210".to_string())));
611    }
612
613    #[test]
614    fn aliases_are_stable_and_uuids_pass_through() {
615        assert_eq!(uuid_for("acme"), uuid_for("acme"));
616        assert_ne!(uuid_for("acme"), uuid_for("globex"));
617        let explicit = "0f1e2d3c-4b5a-6978-8796-a5b4c3d2e1f0";
618        assert_eq!(uuid_for(explicit).to_string(), explicit);
619        // Well-formed: version 8, RFC 4122 variant.
620        let derived = uuid_for("acme");
621        assert_eq!(derived.get_version_num(), 8);
622        assert_eq!(derived.as_bytes()[8] & 0xc0, 0x80);
623    }
624}