Repository navigation
Conversation
…dd error handling for shard-backed buckets in the use case. Update HTTP gateway to support bucket deletion endpoint. Enhance tests for bucket deletion scenarios.
…ted repository interface. Simplify bucket entry removal logic in the use case and enhance test stubs for better clarity and maintainability.
| const [user, bucket, sample] = await Promise.all([ | ||
| this.usersRepository.findByUuid(userUuid), | ||
| this.bucketsRepository.findOne({ id: bucketId }), | ||
| this.bucketEntriesRepository.findOne({ bucket: bucketId }), | ||
| ]); |
There was a problem hiding this comment.
How are you going to make sure the bucket is the mail one? is there any way you can guarantee that only mail buckets are removed?
There was a problem hiding this comment.
that's one of my worries, currently there is a guard that checks for one bucket entry and then checks if it has shards associated. since mail generates none it assumes it is a mail bucket but it is a bit of a fragile check
…cking shard-backed and metadata-only entries. Update repository interface and adjust bucket entry deletion logic in the use case to include bucket name validation. Improve HTTP gateway controller to require bucket name on deletion requests. Update tests to cover new functionality and edge cases.
…summarizing bucket entries and deleting metadata-only entries. Update the repository interface accordingly. Enhance bucket entry use case to utilize new summary method and improve logging during bucket deletion. Update tests to reflect changes in repository methods and ensure proper functionality.
|
Why do you need this @jzunigax2 ? Please provide a proper description |
…yBucket in MongoDBBucketEntriesRepository. Update repository interface and adjust BucketEntriesUsecase to utilize the new method. Modify tests to reflect these changes and ensure proper functionality.
|
@jzunigax2 Can you add some small comment in the controller so it's cleaner that the EP only deletes entries created from the gateway? Just so we can remember this later, it's clear if you read the PR but this repo is somehow hard to navigate through so when it gets merged you'll need to dive into the funcions to be able to know what's happening |
What
Adds
DELETE /v2/gateway/users/:uuid/buckets/:id?name=<bucket-name>. removes a bucket, its entries, and credits the released bytes back to the user'stotalUsedSpaceBytesin one call. ReturnsUserSpaceSnapshot(200).Refuses (409) any bucket holding shard-backed entries.
nameWhy
mail-server is building the purge of suspended mail accounts: a downgraded plan suspends the account today, and 30 days later it has to be destroyed for real —the Stalwart principal, the local tables, and the Bridge storage behind it. Mail
already promises the user a
deletionAtdate it can't yet act on.Each mail address owns one Bridge bucket, and Bridge is the only place that can release its entries and the quota they hold. There was no gateway route to do that, so the purge had nothing to call —
BridgeClient.deleteMailBucket()on themail side was a placeholder pointing at a path Bridge never served. This is the Bridge half of that task; the mail-server client is now moved onto the real route.
The wholesale delete is safe because gateway-minted entries (
createEntry) are metadata only: a bucket, a size, a version — nothing downstream. Real uploads always setframe(v1) orindex+hmac(v2). That is the discriminator usedthroughout, and dropping a shard-backed entry wholesale would strand its shards, mirrors and farmer bytes with nothing left pointing at them — hence the 409.
How
Order of operations:
namedoesn't match.hasShardBackedEntriesByBucket:countDocumentswithlimit: 1, O(1) refusal before any scan.summarizeByBucket: one aggregate returningshardBackedCountandmetadataOnlyBytes; refuses again if the count is non-zero.deleteMetadataOnlyByBucket: the delete filter itself excludes shard-backed entries, so a mixed bucket cannot strand anything even if every check above were wrong.$incontotalUsedSpaceBytes, only when bytes > 0.hasEntriesByBucket: anything left means something was shard-backed: 409, and the bucket document is kept.