Files
ResolveSpec/pkg/security/lookup/ddl/ddl.go
T
Hein c9fa8c60f2 refactor(security): move all database access into pkg/security/lookup
pkg/security no longer contains SQL. Every provider calls a store interface
from lookup, implemented by a procedure backend (Postgres stored procedures,
the default there) and a direct backend (dialect-driven SQL for postgres,
sqlite, mysql and mssql with configurable table and column names).

- add sectypes, lookup, lookup/{dialect,procedure,direct,backends,ddl,conformance}
- split totp and providers sub packages out of the core package
- replace SQLNames/TableNames/QueryMode with lookup.Config (see breaking_changes.md)
- direct backend now covers column/row security and API-key login
- move txsettings SQL to lookup.ApplyTxSettings; remove password.go
- move schema scripts under lookup/, add reference DDL per dialect
- add a shared conformance suite; run it on sqlite, and on Postgres in a
  podman/docker container (RESOLVESPEC_TEST_CONTAINERS=1)
- fix procedure schema bugs found on real Postgres: duplicate p_data
  parameter, JSON null arrays, expires_at timezone casts, passkey list
  GROUP BY, missing resolvespec_passkey_login; accept zone-less timestamps
2026-10-01 13:19:44 +02:00

51 lines
1.4 KiB
Go

// Package ddl holds the reference table schemas for the lookup direct backend, one per
// dialect. They use the lookup.DefaultSchema table and column names; copy and adapt them
// when you override names through lookup.Config.Schema.
//
// The Postgres file creates tables only. The stored-procedure schema
// (lookup/database_schema.sql) is a separate script with native bytea / text[] columns and
// must not be combined with it.
package ddl
import (
"embed"
"fmt"
"strings"
)
//go:embed postgres.sql sqlite.sql mysql.sql mssql.sql
var files embed.FS
// SQL returns the schema script for a dialect name ("postgres", "sqlite", "mysql", "mssql").
func SQL(dialect string) (string, error) {
b, err := files.ReadFile(dialect + ".sql")
if err != nil {
return "", fmt.Errorf("ddl: no reference schema for dialect %q", dialect)
}
return string(b), nil
}
// Statements returns the schema as separate statements, for drivers that reject
// multi-statement execution. Comment-only lines are dropped.
func Statements(dialect string) ([]string, error) {
s, err := SQL(dialect)
if err != nil {
return nil, err
}
var out []string
var cur strings.Builder
for _, line := range strings.Split(s, "\n") {
t := strings.TrimSpace(line)
if t == "" || strings.HasPrefix(t, "--") {
continue
}
cur.WriteString(line)
cur.WriteString("\n")
if strings.HasSuffix(t, ";") {
out = append(out, strings.TrimSpace(cur.String()))
cur.Reset()
}
}
return out, nil
}