mirror of
https://github.com/bitechdev/ResolveSpec.git
synced 2026-10-01 12:31:59 +00:00
* Throttle async session-activity writes to once per token per minute * Add singleflight to session lookups, keystore validation and column/row security loads to stop cold-cache stampedes * Preload security rules in BeforeHandle (restheadspec, resolvespec) so they no longer need a second connection while the read tx is open * Add pkg/dbtrace: opt-in per-request DB call counting and pool logging (db_trace.* config, RESOLVESPEC_DB_TRACE_* env), wired into testserver * Add tests for load dedup, activity throttle and dbtrace
41 lines
1.0 KiB
Go
41 lines
1.0 KiB
Go
package security
|
|
|
|
import (
|
|
"context"
|
|
"sync"
|
|
"testing"
|
|
"time"
|
|
)
|
|
|
|
func TestConcurrentColdLoadsShareOneProviderCall(t *testing.T) {
|
|
p := &slowProvider{delay: 100 * time.Millisecond}
|
|
sl, _ := NewSecurityList(p)
|
|
var wg sync.WaitGroup
|
|
for i := 0; i < 10; i++ {
|
|
wg.Add(2)
|
|
go func() { defer wg.Done(); _ = sl.LoadColumnSecurity(context.Background(), 1, "s", "t", false) }()
|
|
go func() { defer wg.Done(); _, _ = sl.LoadRowSecurity(context.Background(), 1, "s", "t", false) }()
|
|
}
|
|
wg.Wait()
|
|
if got := p.calls.Load(); got != 2 {
|
|
t.Fatalf("provider calls = %d, want 2 (one column, one row)", got)
|
|
}
|
|
}
|
|
|
|
func TestActivityThrottle(t *testing.T) {
|
|
var th activityThrottle
|
|
now := time.Now()
|
|
if !th.allow("a", now) {
|
|
t.Fatal("first call must be allowed")
|
|
}
|
|
if th.allow("a", now.Add(sessionActivityInterval/2)) {
|
|
t.Fatal("call inside interval must be skipped")
|
|
}
|
|
if !th.allow("b", now) {
|
|
t.Fatal("other token must be allowed")
|
|
}
|
|
if !th.allow("a", now.Add(sessionActivityInterval)) {
|
|
t.Fatal("call after interval must be allowed")
|
|
}
|
|
}
|