fix(db): reduce per-request connection bursts and add dbtrace

* Throttle async session-activity writes to once per token per minute
* Add singleflight to session lookups, keystore validation and
  column/row security loads to stop cold-cache stampedes
* Preload security rules in BeforeHandle (restheadspec, resolvespec) so
  they no longer need a second connection while the read tx is open
* Add pkg/dbtrace: opt-in per-request DB call counting and pool logging
  (db_trace.* config, RESOLVESPEC_DB_TRACE_* env), wired into testserver
* Add tests for load dedup, activity throttle and dbtrace
This commit is contained in:
2026-09-30 21:44:28 +02:00
parent 62cc14c02a
commit 3e327d0c78
20 changed files with 544 additions and 87 deletions
+13
View File
@@ -241,6 +241,19 @@ func LoadSecurityRules(secCtx SecurityContext, securityList *SecurityList) error
return loadSecurityRules(secCtx, securityList)
}
// PreloadSecurityRules loads column/row security rules into the SecurityList
// cache for read operations. Call it from a BeforeHandle hook, i.e. before the
// handler opens its transaction, so the provider queries do not need a second
// pooled connection while the transaction holds one. Later LoadSecurityRules
// calls in the same request are then cache hits. Non-read operations and
// models with security disabled are skipped.
func PreloadSecurityRules(secCtx SecurityContext, securityList *SecurityList, operation string) error {
if operation != "read" || IsModelSecurityDisabled(secCtx) {
return nil
}
return loadSecurityRules(secCtx, securityList)
}
// ApplyRowSecurity is a public wrapper for applyRowSecurity that accepts a SecurityContext
// This allows other packages to apply row-level security using the generic interface
func ApplyRowSecurity(secCtx SecurityContext, securityList *SecurityList) error {