pub trait MailStore {
Show 22 methods
// Required methods
fn register_participant(
&mut self,
id: ParticipantId,
record: ParticipantRecord,
) -> Result<(), StoreError>;
fn deregister_participant(
&mut self,
id: &ParticipantId,
) -> Result<(), StoreError>;
fn set_participant_secret_digest(
&mut self,
id: &ParticipantId,
digest: SecretDigest,
) -> Result<(), StoreError>;
fn set_listener_url(
&mut self,
id: &ParticipantId,
url: Option<String>,
) -> Result<(), StoreError>;
fn get_participant(
&self,
id: &ParticipantId,
) -> Result<Option<ParticipantRecord>, StoreError>;
fn find_participant_by_digest(
&self,
digest: &SecretDigest,
) -> Result<Option<(ParticipantId, ParticipantRecord)>, StoreError>;
fn create_room(
&mut self,
id: RoomId,
created_at_unix_ms: u64,
) -> Result<(), StoreError>;
fn add_room_member(
&mut self,
room: &RoomId,
participant: ParticipantId,
) -> Result<(), StoreError>;
fn remove_room_member(
&mut self,
room: &RoomId,
participant: &ParticipantId,
) -> Result<(), StoreError>;
fn get_room(&self, id: &RoomId) -> Result<Option<RoomRecord>, StoreError>;
fn insert_message(
&mut self,
message: Message,
idempotency: Option<(Address, String)>,
) -> Result<InsertMessageOutcome, StoreError>;
fn get_message(&self, id: &MessageId) -> Result<Option<Message>, StoreError>;
fn messages_to_since(
&self,
to: &Address,
since_unix_ms: u64,
) -> Result<Vec<Message>, StoreError>;
fn room_messages_since(
&self,
room: &RoomId,
since_unix_ms: u64,
) -> Result<Vec<Message>, StoreError>;
fn rooms_containing(
&self,
participant: &ParticipantId,
) -> Result<Vec<RoomId>, StoreError>;
fn record_ack(&mut self, ack: Ack) -> Result<Ack, StoreError>;
fn get_ack(
&self,
message_id: &MessageId,
reader: &Address,
) -> Result<Option<Ack>, StoreError>;
fn list_participants(&self) -> Result<Vec<ParticipantSummary>, StoreError>;
fn list_rooms(&self) -> Result<Vec<RoomSummary>, StoreError>;
fn get_session(
&self,
session: &SessionId,
) -> Result<Option<SessionRecord>, StoreError>;
fn upsert_session(
&mut self,
session: SessionId,
record: SessionRecord,
) -> Result<(), StoreError>;
fn sessions_of(
&self,
account: &ParticipantId,
) -> Result<Vec<(SessionId, SessionRecord)>, StoreError>;
}Expand description
The mailbox’s persistence boundary. One mutating method per engine-level mutation (see the module doc comment on why); reads are split finely enough that each maps onto a single indexed SQL query rather than a linear scan.
Required Methods§
Sourcefn register_participant(
&mut self,
id: ParticipantId,
record: ParticipantRecord,
) -> Result<(), StoreError>
fn register_participant( &mut self, id: ParticipantId, record: ParticipantRecord, ) -> Result<(), StoreError>
Registers a new participant. The caller (the engine) has already confirmed no participant is registered under this id.
Sourcefn deregister_participant(
&mut self,
id: &ParticipantId,
) -> Result<(), StoreError>
fn deregister_participant( &mut self, id: &ParticipantId, ) -> Result<(), StoreError>
Removes a participant’s registration entirely, including its place in the secret-digest index. Room memberships naming this id are left as-is: the id can never authenticate again without a fresh registration, so a stale membership entry is inert, not a leak.
Sourcefn set_participant_secret_digest(
&mut self,
id: &ParticipantId,
digest: SecretDigest,
) -> Result<(), StoreError>
fn set_participant_secret_digest( &mut self, id: &ParticipantId, digest: SecretDigest, ) -> Result<(), StoreError>
Replaces a participant’s stored secret digest – the shared
mechanism behind both revoking and rotating a secret (see
crate::MailboxEngine::rotate_participant_secret).
Sourcefn set_listener_url(
&mut self,
id: &ParticipantId,
url: Option<String>,
) -> Result<(), StoreError>
fn set_listener_url( &mut self, id: &ParticipantId, url: Option<String>, ) -> Result<(), StoreError>
Replaces a participant’s registered delivery-listener URL –
Some to register or replace one, None to remove it. The caller
(the engine) has already confirmed id is registered and, on
Some, already validated url’s shape.
fn get_participant( &self, id: &ParticipantId, ) -> Result<Option<ParticipantRecord>, StoreError>
Sourcefn find_participant_by_digest(
&self,
digest: &SecretDigest,
) -> Result<Option<(ParticipantId, ParticipantRecord)>, StoreError>
fn find_participant_by_digest( &self, digest: &SecretDigest, ) -> Result<Option<(ParticipantId, ParticipantRecord)>, StoreError>
Looks a participant up by the exact digest of a presented secret.
See crate::MailboxEngine::authenticate for why this is an index
lookup, not a scan.
Sourcefn create_room(
&mut self,
id: RoomId,
created_at_unix_ms: u64,
) -> Result<(), StoreError>
fn create_room( &mut self, id: RoomId, created_at_unix_ms: u64, ) -> Result<(), StoreError>
Creates a room with no members. The caller has already confirmed no room is registered under this id.
Sourcefn add_room_member(
&mut self,
room: &RoomId,
participant: ParticipantId,
) -> Result<(), StoreError>
fn add_room_member( &mut self, room: &RoomId, participant: ParticipantId, ) -> Result<(), StoreError>
Idempotent: adding an existing member is a no-op.
Sourcefn remove_room_member(
&mut self,
room: &RoomId,
participant: &ParticipantId,
) -> Result<(), StoreError>
fn remove_room_member( &mut self, room: &RoomId, participant: &ParticipantId, ) -> Result<(), StoreError>
Idempotent: removing a non-member is a no-op.
fn get_room(&self, id: &RoomId) -> Result<Option<RoomRecord>, StoreError>
Sourcefn insert_message(
&mut self,
message: Message,
idempotency: Option<(Address, String)>,
) -> Result<InsertMessageOutcome, StoreError>
fn insert_message( &mut self, message: Message, idempotency: Option<(Address, String)>, ) -> Result<InsertMessageOutcome, StoreError>
Stores message unless idempotency names a (sender address, key)
pair already recorded against an earlier message, in which case
nothing is created and that earlier message’s id is returned. One
call, one transaction: a SQLite implementation satisfies this with
an insert under a UNIQUE (sender, key) constraint (or an
equivalent check-and-insert within one transaction), never a
separate read-then-write pair that could race under concurrent
callers. The sender is an Address rather than a
ParticipantId so that a retry from one specific session is
deduplicated against that session, not against every session of its
account.
fn get_message(&self, id: &MessageId) -> Result<Option<Message>, StoreError>
Sourcefn messages_to_since(
&self,
to: &Address,
since_unix_ms: u64,
) -> Result<Vec<Message>, StoreError>
fn messages_to_since( &self, to: &Address, since_unix_ms: u64, ) -> Result<Vec<Message>, StoreError>
Messages addressed to exactly to (a Address::Direct account
address or a Address::Session one), no older than
since_unix_ms. Never Address::Room – room mail is
Self::room_messages_since, keyed by RoomId rather than by a
full address, since it is never gated on the reader’s own identity
the way this method’s result is.
Sourcefn room_messages_since(
&self,
room: &RoomId,
since_unix_ms: u64,
) -> Result<Vec<Message>, StoreError>
fn room_messages_since( &self, room: &RoomId, since_unix_ms: u64, ) -> Result<Vec<Message>, StoreError>
Messages addressed to room, no older than since_unix_ms. Not
gated on membership – the caller (the engine) decides who may see
the result.
Sourcefn rooms_containing(
&self,
participant: &ParticipantId,
) -> Result<Vec<RoomId>, StoreError>
fn rooms_containing( &self, participant: &ParticipantId, ) -> Result<Vec<RoomId>, StoreError>
Every room participant currently belongs to. Membership stays on
the account: a session looks its account’s rooms up through this
same method, it does not have a membership set of its own (see
SessionRecord).
Sourcefn record_ack(&mut self, ack: Ack) -> Result<Ack, StoreError>
fn record_ack(&mut self, ack: Ack) -> Result<Ack, StoreError>
Records an acknowledgement, or returns the one already on file for
this (message_id, reader) pair unchanged. One call, one
transaction, so two concurrent acks of the same message by the same
reader cannot both “win” with different timestamps. reader is an
Address so a session’s ack is tracked separately from its
account’s and from its sibling sessions’, the way Matrix scopes a
read marker to a (user_id, device_id) pair.
fn get_ack( &self, message_id: &MessageId, reader: &Address, ) -> Result<Option<Ack>, StoreError>
Sourcefn list_participants(&self) -> Result<Vec<ParticipantSummary>, StoreError>
fn list_participants(&self) -> Result<Vec<ParticipantSummary>, StoreError>
Every registered participant, for the mailbox’s own directory
(crate::MailboxEngine::directory). Returns the full set, always
– this mailbox is a small, local directory, not a paginated
social graph. Never returns a secret digest or a permission
bit: see ParticipantSummary’s own doc comment for why the
return type itself rules that out.
Sourcefn list_rooms(&self) -> Result<Vec<RoomSummary>, StoreError>
fn list_rooms(&self) -> Result<Vec<RoomSummary>, StoreError>
Every room the mailbox tracks, with its current membership, for the same directory. Also the full set, always, for the same reason.
Sourcefn get_session(
&self,
session: &SessionId,
) -> Result<Option<SessionRecord>, StoreError>
fn get_session( &self, session: &SessionId, ) -> Result<Option<SessionRecord>, StoreError>
Looks a session up by its id. None until
crate::MailboxEngine::ensure_session has registered it at least
once.
Sourcefn upsert_session(
&mut self,
session: SessionId,
record: SessionRecord,
) -> Result<(), StoreError>
fn upsert_session( &mut self, session: SessionId, record: SessionRecord, ) -> Result<(), StoreError>
Inserts or wholesale-replaces the record for session. The engine,
not this trait, is responsible for merging a fresh reading into an
existing record before calling this – see
crate::MailboxEngine::ensure_session and ::set_declared, the
only two callers, and the only two ways a SessionRecord ever
changes.
Sourcefn sessions_of(
&self,
account: &ParticipantId,
) -> Result<Vec<(SessionId, SessionRecord)>, StoreError>
fn sessions_of( &self, account: &ParticipantId, ) -> Result<Vec<(SessionId, SessionRecord)>, StoreError>
Every session currently registered under account, for the
mailbox’s own directory (crate::MailboxEngine::directory), which
nests them under their account the way Matrix nests devices under a
user_id.
Dyn Compatibility§
This trait is dyn compatible.
In older versions of Rust, dyn compatibility was called "object safety".