Files
ResolveSpec/pkg/security/stampede_test.go
T
warkanum 3e327d0c78 fix(db): reduce per-request connection bursts and add dbtrace
* Throttle async session-activity writes to once per token per minute
* Add singleflight to session lookups, keystore validation and
  column/row security loads to stop cold-cache stampedes
* Preload security rules in BeforeHandle (restheadspec, resolvespec) so
  they no longer need a second connection while the read tx is open
* Add pkg/dbtrace: opt-in per-request DB call counting and pool logging
  (db_trace.* config, RESOLVESPEC_DB_TRACE_* env), wired into testserver
* Add tests for load dedup, activity throttle and dbtrace
2026-09-30 21:44:28 +02:00

41 lines
1.0 KiB
Go

package security
import (
"context"
"sync"
"testing"
"time"
)
func TestConcurrentColdLoadsShareOneProviderCall(t *testing.T) {
p := &slowProvider{delay: 100 * time.Millisecond}
sl, _ := NewSecurityList(p)
var wg sync.WaitGroup
for i := 0; i < 10; i++ {
wg.Add(2)
go func() { defer wg.Done(); _ = sl.LoadColumnSecurity(context.Background(), 1, "s", "t", false) }()
go func() { defer wg.Done(); _, _ = sl.LoadRowSecurity(context.Background(), 1, "s", "t", false) }()
}
wg.Wait()
if got := p.calls.Load(); got != 2 {
t.Fatalf("provider calls = %d, want 2 (one column, one row)", got)
}
}
func TestActivityThrottle(t *testing.T) {
var th activityThrottle
now := time.Now()
if !th.allow("a", now) {
t.Fatal("first call must be allowed")
}
if th.allow("a", now.Add(sessionActivityInterval/2)) {
t.Fatal("call inside interval must be skipped")
}
if !th.allow("b", now) {
t.Fatal("other token must be allowed")
}
if !th.allow("a", now.Add(sessionActivityInterval)) {
t.Fatal("call after interval must be allowed")
}
}