Public Access
Add data model, DbContext and initial migration (M1)
Schema for identity, vaults, grants, hosts and the sync change log, verified against a real PostgreSQL 18 container rather than an in-memory provider: partial unique indexes, CHECK constraints, citext and identity-always columns are all provider behaviour that an in-memory fake would not exercise. Invariants pushed into the database, so they hold even when application code has a bug: - ck_host_relay_target is a security boundary, not tidiness. A host may carry a plaintext hostname and port ONLY when relay is deliberately enabled. Both directions are tested; the important one is that relay-disabled hosts cannot carry an address, since otherwise a bug would silently give the server infrastructure visibility it was never granted. - ck_vault_owner: exactly one of owner_user_id or team_id, or permission resolution would have no defined answer. - ck_vault_key_grant_recipient: member grants name a user; recovery and escrow grants are wrapped to a key and must not. - ck_user_key_wrap_kdf: a password-derived wrap without its parameters is permanently unopenable, so a partial write is rejected outright. Present from the first migration on purpose: - GrantKind (Member/Recovery/Escrow). Recovery cannot be bolted on later — every vault created before it existed would be unrecoverable by design. - team and team_membership, though team features are M3. Adding them later would mean introducing a foreign key on a live vault table. - Host.ContentKeyId, reserved for per-item content keys wrapped to individual users. - user_key as its own table, so key rotation does not require altering the user row. Two things verified rather than assumed: - Npgsql's UseXminAsConcurrencyToken helper no longer exists in EF 10, so xmin is mapped directly in XminConcurrency. The generated migration *looks* like it creates an xmin column; it does not. Confirmed by inspecting pg_attribute (attnum -2, a system column) and by grepping the emitted DDL. A test pins both, because had it created a real column PostgreSQL would have rejected the name. - EF Core is now pinned centrally. The Npgsql provider asks for 10.0.4 while EntityFrameworkCore.Design pulls 10.0.10, and because Design is PrivateAssets=all that higher version does not flow to referencing projects — producing a CS1705 in any test project referencing Infrastructure. Also commits artifacts/schema/v0.1.sql, the idempotent script, as the baseline for future upgrade tests. Verified: 0 warnings, 122 tests pass (27 new against Postgres), format clean.
This commit is contained in:
@@ -0,0 +1,75 @@
|
||||
using DodoSSH.Domain;
|
||||
using Microsoft.EntityFrameworkCore;
|
||||
|
||||
namespace DodoSSH.Infrastructure;
|
||||
|
||||
/// <summary>
|
||||
/// The application database context.
|
||||
/// </summary>
|
||||
/// <remarks>
|
||||
/// <para>
|
||||
/// Everything lives in the <c>dodo</c> schema with snake_case names. Timestamps are
|
||||
/// <c>timestamptz</c> and always UTC, so there is no tzdata dependency and no conflict with
|
||||
/// <c>InvariantGlobalization</c>.
|
||||
/// </para>
|
||||
/// <para>
|
||||
/// Two concurrency mechanisms coexist deliberately. <c>Version</c> on item rows is the
|
||||
/// client-visible, monotonic value used for <c>expectedVersion</c> conflict detection.
|
||||
/// <c>xmin</c> is the server-side optimistic guard and is never exposed, because it is not stable
|
||||
/// across <c>VACUUM FREEZE</c> and must never become a client cursor.
|
||||
/// </para>
|
||||
/// </remarks>
|
||||
public class DodoDbContext(DbContextOptions<DodoDbContext> options) : DbContext(options)
|
||||
{
|
||||
/// <summary>The database schema every table lives in.</summary>
|
||||
public const string SchemaName = "dodo";
|
||||
|
||||
/// <summary>User accounts.</summary>
|
||||
public DbSet<UserAccount> Users => Set<UserAccount>();
|
||||
|
||||
/// <summary>Identity key generations.</summary>
|
||||
public DbSet<UserKey> UserKeys => Set<UserKey>();
|
||||
|
||||
/// <summary>Wraps of users' secret bundles.</summary>
|
||||
public DbSet<UserKeyWrap> UserKeyWraps => Set<UserKeyWrap>();
|
||||
|
||||
/// <summary>Enrolled devices.</summary>
|
||||
public DbSet<Device> Devices => Set<Device>();
|
||||
|
||||
/// <summary>The append-only key transparency log.</summary>
|
||||
public DbSet<KeyLogEntry> KeyLog => Set<KeyLogEntry>();
|
||||
|
||||
/// <summary>Teams.</summary>
|
||||
public DbSet<Team> Teams => Set<Team>();
|
||||
|
||||
/// <summary>Team memberships.</summary>
|
||||
public DbSet<TeamMembership> TeamMemberships => Set<TeamMembership>();
|
||||
|
||||
/// <summary>Vaults.</summary>
|
||||
public DbSet<Vault> Vaults => Set<Vault>();
|
||||
|
||||
/// <summary>Wrapped vault keys.</summary>
|
||||
public DbSet<VaultKeyGrant> VaultKeyGrants => Set<VaultKeyGrant>();
|
||||
|
||||
/// <summary>SSH hosts.</summary>
|
||||
public DbSet<Host> Hosts => Set<Host>();
|
||||
|
||||
/// <summary>The per-vault change log that delta sync reads.</summary>
|
||||
public DbSet<SyncChange> SyncChanges => Set<SyncChange>();
|
||||
|
||||
/// <summary>Applied-operation receipts, for exactly-once retries.</summary>
|
||||
public DbSet<SyncOperationReceipt> SyncOperationReceipts => Set<SyncOperationReceipt>();
|
||||
|
||||
/// <inheritdoc />
|
||||
protected override void OnModelCreating(ModelBuilder modelBuilder)
|
||||
{
|
||||
ArgumentNullException.ThrowIfNull(modelBuilder);
|
||||
|
||||
modelBuilder.HasDefaultSchema(SchemaName);
|
||||
modelBuilder.HasPostgresExtension("citext");
|
||||
|
||||
modelBuilder.ApplyConfigurationsFromAssembly(typeof(DodoDbContext).Assembly);
|
||||
|
||||
base.OnModelCreating(modelBuilder);
|
||||
}
|
||||
}
|
||||
Reference in New Issue
Block a user