arcature 0.1.3

Arcature: an opinionated full-stack Rust web framework. One package, batteries included.
Documentation
//! MySQL 8 statement text for the API token store.
//!
//! Placeholders are `?`, bound in order of appearance. "Now" is
//! `UTC_TIMESTAMP(6)` rather than `NOW(6)`: `NOW()` follows the session time
//! zone, and `arcature_api_tokens.expires_at` is a `DATETIME(6)` holding UTC.
//! A connection that happened to be set to a different time zone would
//! otherwise move every expiry by that offset.

/// Every statement the API token store issues against MySQL.
pub(crate) mod sql {
    /// Insert a token that must not already exist.
    ///
    /// `INSERT IGNORE` reports the clash as zero rows affected rather than as
    /// an error, which is what lets `issue` retry with a fresh id instead of
    /// matching on a driver-specific constraint message.
    /// Binds: id, secret digest, tokenable id, name, abilities, expires at,
    /// created at.
    pub(crate) const INSERT_NEW: &str = r#"INSERT IGNORE INTO arcature_api_tokens
    (id, secret_digest, tokenable_id, name, abilities, expires_at, created_at)
VALUES (?, ?, ?, ?, ?, ?, ?)"#;

    /// Read one live token by its public id. The expiry is part of the
    /// predicate, not a check the caller makes afterwards, so an expired
    /// token is invisible from the instant it expires whether or not the
    /// sweep has run.
    /// Binds: id.
    pub(crate) const FIND: &str = r#"SELECT tokenable_id, name, abilities, expires_at, created_at
  FROM arcature_api_tokens
 WHERE id = ? AND expires_at > UTC_TIMESTAMP(6)"#;

    /// [`FIND`] plus the digest, for the one caller that has a secret to
    /// check against it. Kept separate so that every other read is
    /// structurally incapable of loading the digest into memory.
    /// Binds: id.
    pub(crate) const AUTHENTICATE: &str = r#"SELECT secret_digest, tokenable_id, name, abilities, expires_at, created_at
  FROM arcature_api_tokens
 WHERE id = ? AND expires_at > UTC_TIMESTAMP(6)"#;

    /// Every live token issued to one subject, newest first.
    /// Binds: tokenable id.
    pub(crate) const LIST_FOR: &str = r#"SELECT id, tokenable_id, name, abilities, expires_at, created_at
  FROM arcature_api_tokens
 WHERE tokenable_id = ? AND expires_at > UTC_TIMESTAMP(6)
 ORDER BY created_at DESC, id"#;

    /// Binds: id.
    pub(crate) const DELETE: &str = "DELETE FROM arcature_api_tokens WHERE id = ?";

    /// Binds: tokenable id.
    pub(crate) const DELETE_FOR: &str = "DELETE FROM arcature_api_tokens WHERE tokenable_id = ?";

    /// Delete every token whose expiry has passed. No binds.
    pub(crate) const DELETE_EXPIRED: &str =
        "DELETE FROM arcature_api_tokens WHERE expires_at <= UTC_TIMESTAMP(6)";

    /// The migration history table.
    pub(crate) const CREATE_HISTORY: &str = r#"CREATE TABLE IF NOT EXISTS arcature_api_tokens_schema_migrations (
    version    VARCHAR(191) NOT NULL PRIMARY KEY,
    applied_at DATETIME(6)  NOT NULL DEFAULT CURRENT_TIMESTAMP(6)
) ENGINE=InnoDB"#;

    /// Binds: version.
    pub(crate) const COUNT_APPLIED: &str =
        "SELECT COUNT(*) FROM arcature_api_tokens_schema_migrations WHERE version = ?";

    /// Binds: version. Idempotent so a racing migrator cannot fail on the
    /// primary key.
    pub(crate) const RECORD_APPLIED: &str =
        "INSERT IGNORE INTO arcature_api_tokens_schema_migrations (version) VALUES (?)";

    /// Serialise concurrent migrators. Session-scoped, so it must be
    /// released. A lock name of its own, for the same reason the PostgreSQL
    /// key is its own: the schemas are independent, and sharing a name would
    /// make an application that migrates both wait on itself.
    pub(crate) const LOCK: Option<&str> =
        Some("SELECT GET_LOCK('arcature_api_tokens_migrate', 10)");

    /// Release [`LOCK`].
    pub(crate) const UNLOCK: Option<&str> =
        Some("SELECT RELEASE_LOCK('arcature_api_tokens_migrate')");

    /// The schema, one statement per `--;;` separated chunk.
    pub(crate) const SCHEMA: &str = include_str!("../migrations/mysql/0001_api_tokens.sql");
}