Skip to main content

MailStore

Trait MailStore 

Source
pub trait MailStore {
Show 22 methods // Required methods fn register_participant( &mut self, id: ParticipantId, record: ParticipantRecord, ) -> Result<(), StoreError>; fn deregister_participant( &mut self, id: &ParticipantId, ) -> Result<(), StoreError>; fn set_participant_secret_digest( &mut self, id: &ParticipantId, digest: SecretDigest, ) -> Result<(), StoreError>; fn set_listener_url( &mut self, id: &ParticipantId, url: Option<String>, ) -> Result<(), StoreError>; fn get_participant( &self, id: &ParticipantId, ) -> Result<Option<ParticipantRecord>, StoreError>; fn find_participant_by_digest( &self, digest: &SecretDigest, ) -> Result<Option<(ParticipantId, ParticipantRecord)>, StoreError>; fn create_room( &mut self, id: RoomId, created_at_unix_ms: u64, ) -> Result<(), StoreError>; fn add_room_member( &mut self, room: &RoomId, participant: ParticipantId, ) -> Result<(), StoreError>; fn remove_room_member( &mut self, room: &RoomId, participant: &ParticipantId, ) -> Result<(), StoreError>; fn get_room(&self, id: &RoomId) -> Result<Option<RoomRecord>, StoreError>; fn insert_message( &mut self, message: Message, idempotency: Option<(Address, String)>, ) -> Result<InsertMessageOutcome, StoreError>; fn get_message(&self, id: &MessageId) -> Result<Option<Message>, StoreError>; fn messages_to_since( &self, to: &Address, since_unix_ms: u64, ) -> Result<Vec<Message>, StoreError>; fn room_messages_since( &self, room: &RoomId, since_unix_ms: u64, ) -> Result<Vec<Message>, StoreError>; fn rooms_containing( &self, participant: &ParticipantId, ) -> Result<Vec<RoomId>, StoreError>; fn record_ack(&mut self, ack: Ack) -> Result<Ack, StoreError>; fn get_ack( &self, message_id: &MessageId, reader: &Address, ) -> Result<Option<Ack>, StoreError>; fn list_participants(&self) -> Result<Vec<ParticipantSummary>, StoreError>; fn list_rooms(&self) -> Result<Vec<RoomSummary>, StoreError>; fn get_session( &self, session: &SessionId, ) -> Result<Option<SessionRecord>, StoreError>; fn upsert_session( &mut self, session: SessionId, record: SessionRecord, ) -> Result<(), StoreError>; fn sessions_of( &self, account: &ParticipantId, ) -> Result<Vec<(SessionId, SessionRecord)>, StoreError>;
}
Expand description

The mailbox’s persistence boundary. One mutating method per engine-level mutation (see the module doc comment on why); reads are split finely enough that each maps onto a single indexed SQL query rather than a linear scan.

Required Methods§

Source

fn register_participant( &mut self, id: ParticipantId, record: ParticipantRecord, ) -> Result<(), StoreError>

Registers a new participant. The caller (the engine) has already confirmed no participant is registered under this id.

Source

fn deregister_participant( &mut self, id: &ParticipantId, ) -> Result<(), StoreError>

Removes a participant’s registration entirely, including its place in the secret-digest index. Room memberships naming this id are left as-is: the id can never authenticate again without a fresh registration, so a stale membership entry is inert, not a leak.

Source

fn set_participant_secret_digest( &mut self, id: &ParticipantId, digest: SecretDigest, ) -> Result<(), StoreError>

Replaces a participant’s stored secret digest – the shared mechanism behind both revoking and rotating a secret (see crate::MailboxEngine::rotate_participant_secret).

Source

fn set_listener_url( &mut self, id: &ParticipantId, url: Option<String>, ) -> Result<(), StoreError>

Replaces a participant’s registered delivery-listener URL – Some to register or replace one, None to remove it. The caller (the engine) has already confirmed id is registered and, on Some, already validated url’s shape.

Source

fn get_participant( &self, id: &ParticipantId, ) -> Result<Option<ParticipantRecord>, StoreError>

Source

fn find_participant_by_digest( &self, digest: &SecretDigest, ) -> Result<Option<(ParticipantId, ParticipantRecord)>, StoreError>

Looks a participant up by the exact digest of a presented secret. See crate::MailboxEngine::authenticate for why this is an index lookup, not a scan.

Source

fn create_room( &mut self, id: RoomId, created_at_unix_ms: u64, ) -> Result<(), StoreError>

Creates a room with no members. The caller has already confirmed no room is registered under this id.

Source

fn add_room_member( &mut self, room: &RoomId, participant: ParticipantId, ) -> Result<(), StoreError>

Idempotent: adding an existing member is a no-op.

Source

fn remove_room_member( &mut self, room: &RoomId, participant: &ParticipantId, ) -> Result<(), StoreError>

Idempotent: removing a non-member is a no-op.

Source

fn get_room(&self, id: &RoomId) -> Result<Option<RoomRecord>, StoreError>

Source

fn insert_message( &mut self, message: Message, idempotency: Option<(Address, String)>, ) -> Result<InsertMessageOutcome, StoreError>

Stores message unless idempotency names a (sender address, key) pair already recorded against an earlier message, in which case nothing is created and that earlier message’s id is returned. One call, one transaction: a SQLite implementation satisfies this with an insert under a UNIQUE (sender, key) constraint (or an equivalent check-and-insert within one transaction), never a separate read-then-write pair that could race under concurrent callers. The sender is an Address rather than a ParticipantId so that a retry from one specific session is deduplicated against that session, not against every session of its account.

Source

fn get_message(&self, id: &MessageId) -> Result<Option<Message>, StoreError>

Source

fn messages_to_since( &self, to: &Address, since_unix_ms: u64, ) -> Result<Vec<Message>, StoreError>

Messages addressed to exactly to (a Address::Direct account address or a Address::Session one), no older than since_unix_ms. Never Address::Room – room mail is Self::room_messages_since, keyed by RoomId rather than by a full address, since it is never gated on the reader’s own identity the way this method’s result is.

Source

fn room_messages_since( &self, room: &RoomId, since_unix_ms: u64, ) -> Result<Vec<Message>, StoreError>

Messages addressed to room, no older than since_unix_ms. Not gated on membership – the caller (the engine) decides who may see the result.

Source

fn rooms_containing( &self, participant: &ParticipantId, ) -> Result<Vec<RoomId>, StoreError>

Every room participant currently belongs to. Membership stays on the account: a session looks its account’s rooms up through this same method, it does not have a membership set of its own (see SessionRecord).

Source

fn record_ack(&mut self, ack: Ack) -> Result<Ack, StoreError>

Records an acknowledgement, or returns the one already on file for this (message_id, reader) pair unchanged. One call, one transaction, so two concurrent acks of the same message by the same reader cannot both “win” with different timestamps. reader is an Address so a session’s ack is tracked separately from its account’s and from its sibling sessions’, the way Matrix scopes a read marker to a (user_id, device_id) pair.

Source

fn get_ack( &self, message_id: &MessageId, reader: &Address, ) -> Result<Option<Ack>, StoreError>

Source

fn list_participants(&self) -> Result<Vec<ParticipantSummary>, StoreError>

Every registered participant, for the mailbox’s own directory (crate::MailboxEngine::directory). Returns the full set, always – this mailbox is a small, local directory, not a paginated social graph. Never returns a secret digest or a permission bit: see ParticipantSummary’s own doc comment for why the return type itself rules that out.

Source

fn list_rooms(&self) -> Result<Vec<RoomSummary>, StoreError>

Every room the mailbox tracks, with its current membership, for the same directory. Also the full set, always, for the same reason.

Source

fn get_session( &self, session: &SessionId, ) -> Result<Option<SessionRecord>, StoreError>

Looks a session up by its id. None until crate::MailboxEngine::ensure_session has registered it at least once.

Source

fn upsert_session( &mut self, session: SessionId, record: SessionRecord, ) -> Result<(), StoreError>

Inserts or wholesale-replaces the record for session. The engine, not this trait, is responsible for merging a fresh reading into an existing record before calling this – see crate::MailboxEngine::ensure_session and ::set_declared, the only two callers, and the only two ways a SessionRecord ever changes.

Source

fn sessions_of( &self, account: &ParticipantId, ) -> Result<Vec<(SessionId, SessionRecord)>, StoreError>

Every session currently registered under account, for the mailbox’s own directory (crate::MailboxEngine::directory), which nests them under their account the way Matrix nests devices under a user_id.

Dyn Compatibility§

This trait is dyn compatible.

In older versions of Rust, dyn compatibility was called "object safety".

Implementors§