1a7e130f9f
- Drop the FIFO from oauthStates: consumed states left entries behind, so an unrate-limited start/cancel cycle grew the slice without bound. Evict by oldest expiry instead — the map alone now bounds memory. - CreateSession runs INSERT + expiry sweep in one transaction. - slices.Contains replaces a hand-rolled contains; APIBase typo fixed. - Stale comments and test paths updated; login hover uses --ember-ink.
12 lines
528 B
SQL
12 lines
528 B
SQL
-- One row per browser session. The id is an opaque random value the cookie
|
|
-- carries verbatim; a request is authenticated by looking the row up, and
|
|
-- deleting the row is how a session is revoked. Expired rows are removed
|
|
-- lazily on lookup and swept by the next login, so nothing runs a background
|
|
-- cleanup.
|
|
CREATE TABLE sessions (
|
|
id text PRIMARY KEY,
|
|
reader_id bigint NOT NULL REFERENCES readers (id) ON DELETE CASCADE,
|
|
created_at timestamptz NOT NULL DEFAULT now(),
|
|
expires_at timestamptz NOT NULL
|
|
);
|