feat(harness): persist server sessions in postgres
This commit is contained in:
@@ -0,0 +1,60 @@
|
||||
CREATE SCHEMA IF NOT EXISTS thoth_sessions;
|
||||
REVOKE ALL ON SCHEMA thoth_sessions FROM PUBLIC;
|
||||
|
||||
CREATE TABLE IF NOT EXISTS thoth_sessions.principals (
|
||||
id bigserial PRIMARY KEY,
|
||||
issuer text NOT NULL,
|
||||
subject text NOT NULL,
|
||||
display_name text,
|
||||
created_at timestamptz NOT NULL DEFAULT pg_catalog.now(),
|
||||
updated_at timestamptz NOT NULL DEFAULT pg_catalog.now(),
|
||||
UNIQUE (issuer, subject)
|
||||
);
|
||||
|
||||
CREATE TABLE IF NOT EXISTS thoth_sessions.principal_preferences (
|
||||
principal_id bigint PRIMARY KEY REFERENCES thoth_sessions.principals(id) ON DELETE CASCADE,
|
||||
preferences jsonb NOT NULL DEFAULT '{}'::jsonb,
|
||||
updated_at timestamptz NOT NULL DEFAULT pg_catalog.now()
|
||||
);
|
||||
|
||||
CREATE TABLE IF NOT EXISTS thoth_sessions.sessions (
|
||||
id uuid PRIMARY KEY,
|
||||
principal_id bigint NOT NULL REFERENCES thoth_sessions.principals(id),
|
||||
manifest jsonb NOT NULL,
|
||||
created_at timestamptz NOT NULL DEFAULT pg_catalog.now(),
|
||||
updated_at timestamptz NOT NULL DEFAULT pg_catalog.now()
|
||||
);
|
||||
CREATE INDEX IF NOT EXISTS sessions_principal_id_created_at_idx
|
||||
ON thoth_sessions.sessions (principal_id, created_at DESC);
|
||||
|
||||
CREATE TABLE IF NOT EXISTS thoth_sessions.session_artifacts (
|
||||
session_id uuid NOT NULL REFERENCES thoth_sessions.sessions(id) ON DELETE CASCADE,
|
||||
artifact_key text NOT NULL,
|
||||
content text NOT NULL,
|
||||
updated_at timestamptz NOT NULL DEFAULT pg_catalog.now(),
|
||||
PRIMARY KEY (session_id, artifact_key)
|
||||
);
|
||||
|
||||
CREATE TABLE IF NOT EXISTS thoth_sessions.review_decisions (
|
||||
session_id uuid NOT NULL REFERENCES thoth_sessions.sessions(id) ON DELETE CASCADE,
|
||||
seq integer NOT NULL CHECK (seq > 0),
|
||||
ts timestamptz NOT NULL,
|
||||
phase integer,
|
||||
type text NOT NULL,
|
||||
subject text NOT NULL,
|
||||
detail text NOT NULL DEFAULT '',
|
||||
rationale text NOT NULL DEFAULT '',
|
||||
retracts integer,
|
||||
PRIMARY KEY (session_id, seq)
|
||||
);
|
||||
|
||||
CREATE TABLE IF NOT EXISTS thoth_sessions.audit_log (
|
||||
id bigserial PRIMARY KEY,
|
||||
occurred_at timestamptz NOT NULL DEFAULT pg_catalog.now(),
|
||||
action text NOT NULL,
|
||||
session_id uuid NOT NULL,
|
||||
actor_issuer text NOT NULL,
|
||||
actor_subject text NOT NULL,
|
||||
owner_issuer text NOT NULL,
|
||||
owner_subject text NOT NULL
|
||||
);
|
||||
@@ -0,0 +1,126 @@
|
||||
DO $roles$
|
||||
BEGIN
|
||||
IF NOT EXISTS (SELECT 1 FROM pg_catalog.pg_roles WHERE rolname = 'thoth_sessions_runtime') THEN
|
||||
CREATE ROLE thoth_sessions_runtime NOLOGIN NOBYPASSRLS NOSUPERUSER NOCREATEDB NOCREATEROLE NOINHERIT;
|
||||
END IF;
|
||||
IF NOT EXISTS (SELECT 1 FROM pg_catalog.pg_roles WHERE rolname = 'thoth_sessions_migrator') THEN
|
||||
CREATE ROLE thoth_sessions_migrator NOLOGIN NOBYPASSRLS NOSUPERUSER NOCREATEDB NOCREATEROLE NOINHERIT;
|
||||
END IF;
|
||||
END
|
||||
$roles$;
|
||||
|
||||
ALTER ROLE thoth_sessions_runtime NOLOGIN NOBYPASSRLS NOSUPERUSER NOCREATEDB NOCREATEROLE NOINHERIT;
|
||||
ALTER ROLE thoth_sessions_migrator NOLOGIN NOBYPASSRLS NOSUPERUSER NOCREATEDB NOCREATEROLE NOINHERIT;
|
||||
|
||||
REVOKE ALL ON SCHEMA thoth_sessions FROM PUBLIC;
|
||||
REVOKE ALL ON ALL TABLES IN SCHEMA thoth_sessions FROM PUBLIC;
|
||||
REVOKE ALL ON ALL SEQUENCES IN SCHEMA thoth_sessions FROM PUBLIC;
|
||||
REVOKE ALL ON SCHEMA thoth_sessions FROM thoth_sessions_runtime, thoth_sessions_migrator;
|
||||
REVOKE ALL ON ALL TABLES IN SCHEMA thoth_sessions FROM thoth_sessions_runtime, thoth_sessions_migrator;
|
||||
REVOKE ALL ON ALL SEQUENCES IN SCHEMA thoth_sessions FROM thoth_sessions_runtime, thoth_sessions_migrator;
|
||||
|
||||
GRANT USAGE ON SCHEMA thoth_sessions TO thoth_sessions_runtime;
|
||||
GRANT SELECT, INSERT, UPDATE ON thoth_sessions.principals TO thoth_sessions_runtime;
|
||||
GRANT SELECT, INSERT, UPDATE ON thoth_sessions.principal_preferences TO thoth_sessions_runtime;
|
||||
GRANT SELECT, INSERT, UPDATE, DELETE ON thoth_sessions.sessions TO thoth_sessions_runtime;
|
||||
GRANT SELECT, INSERT, UPDATE ON thoth_sessions.session_artifacts TO thoth_sessions_runtime;
|
||||
GRANT SELECT, INSERT ON thoth_sessions.review_decisions TO thoth_sessions_runtime;
|
||||
GRANT SELECT, INSERT ON thoth_sessions.audit_log TO thoth_sessions_runtime;
|
||||
GRANT USAGE, SELECT ON ALL SEQUENCES IN SCHEMA thoth_sessions TO thoth_sessions_runtime;
|
||||
|
||||
ALTER TABLE thoth_sessions.principals ENABLE ROW LEVEL SECURITY;
|
||||
ALTER TABLE thoth_sessions.principals FORCE ROW LEVEL SECURITY;
|
||||
ALTER TABLE thoth_sessions.principal_preferences ENABLE ROW LEVEL SECURITY;
|
||||
ALTER TABLE thoth_sessions.principal_preferences FORCE ROW LEVEL SECURITY;
|
||||
ALTER TABLE thoth_sessions.sessions ENABLE ROW LEVEL SECURITY;
|
||||
ALTER TABLE thoth_sessions.sessions FORCE ROW LEVEL SECURITY;
|
||||
ALTER TABLE thoth_sessions.session_artifacts ENABLE ROW LEVEL SECURITY;
|
||||
ALTER TABLE thoth_sessions.session_artifacts FORCE ROW LEVEL SECURITY;
|
||||
ALTER TABLE thoth_sessions.review_decisions ENABLE ROW LEVEL SECURITY;
|
||||
ALTER TABLE thoth_sessions.review_decisions FORCE ROW LEVEL SECURITY;
|
||||
ALTER TABLE thoth_sessions.audit_log ENABLE ROW LEVEL SECURITY;
|
||||
ALTER TABLE thoth_sessions.audit_log FORCE ROW LEVEL SECURITY;
|
||||
|
||||
CREATE POLICY principals_owner_or_admin ON thoth_sessions.principals
|
||||
FOR ALL
|
||||
USING (
|
||||
pg_catalog.current_setting('thoth_sessions.is_admin', true) = 'true'
|
||||
OR (issuer = pg_catalog.current_setting('thoth_sessions.actor_issuer', true)
|
||||
AND subject = pg_catalog.current_setting('thoth_sessions.actor_subject', true))
|
||||
)
|
||||
WITH CHECK (
|
||||
pg_catalog.current_setting('thoth_sessions.is_admin', true) = 'true'
|
||||
OR (issuer = pg_catalog.current_setting('thoth_sessions.actor_issuer', true)
|
||||
AND subject = pg_catalog.current_setting('thoth_sessions.actor_subject', true))
|
||||
);
|
||||
|
||||
CREATE POLICY preferences_owner_or_admin ON thoth_sessions.principal_preferences
|
||||
FOR ALL
|
||||
USING (
|
||||
EXISTS (
|
||||
SELECT 1 FROM thoth_sessions.principals p
|
||||
WHERE p.id = principal_preferences.principal_id
|
||||
AND (pg_catalog.current_setting('thoth_sessions.is_admin', true) = 'true'
|
||||
OR (p.issuer = pg_catalog.current_setting('thoth_sessions.actor_issuer', true)
|
||||
AND p.subject = pg_catalog.current_setting('thoth_sessions.actor_subject', true)))
|
||||
)
|
||||
)
|
||||
WITH CHECK (
|
||||
EXISTS (
|
||||
SELECT 1 FROM thoth_sessions.principals p
|
||||
WHERE p.id = principal_preferences.principal_id
|
||||
AND (pg_catalog.current_setting('thoth_sessions.is_admin', true) = 'true'
|
||||
OR (p.issuer = pg_catalog.current_setting('thoth_sessions.actor_issuer', true)
|
||||
AND p.subject = pg_catalog.current_setting('thoth_sessions.actor_subject', true)))
|
||||
)
|
||||
);
|
||||
|
||||
CREATE POLICY sessions_owner_or_admin ON thoth_sessions.sessions
|
||||
FOR ALL
|
||||
USING (
|
||||
EXISTS (
|
||||
SELECT 1 FROM thoth_sessions.principals p
|
||||
WHERE p.id = sessions.principal_id
|
||||
AND (pg_catalog.current_setting('thoth_sessions.is_admin', true) = 'true'
|
||||
OR (p.issuer = pg_catalog.current_setting('thoth_sessions.actor_issuer', true)
|
||||
AND p.subject = pg_catalog.current_setting('thoth_sessions.actor_subject', true)))
|
||||
)
|
||||
)
|
||||
WITH CHECK (
|
||||
EXISTS (
|
||||
SELECT 1 FROM thoth_sessions.principals p
|
||||
WHERE p.id = sessions.principal_id
|
||||
AND (pg_catalog.current_setting('thoth_sessions.is_admin', true) = 'true'
|
||||
OR (p.issuer = pg_catalog.current_setting('thoth_sessions.actor_issuer', true)
|
||||
AND p.subject = pg_catalog.current_setting('thoth_sessions.actor_subject', true)))
|
||||
)
|
||||
);
|
||||
|
||||
CREATE POLICY artifacts_owner_or_admin ON thoth_sessions.session_artifacts
|
||||
FOR ALL
|
||||
USING (
|
||||
EXISTS (SELECT 1 FROM thoth_sessions.sessions s WHERE s.id = session_artifacts.session_id)
|
||||
)
|
||||
WITH CHECK (
|
||||
EXISTS (SELECT 1 FROM thoth_sessions.sessions s WHERE s.id = session_artifacts.session_id)
|
||||
);
|
||||
|
||||
CREATE POLICY decisions_owner_or_admin ON thoth_sessions.review_decisions
|
||||
FOR ALL
|
||||
USING (
|
||||
EXISTS (SELECT 1 FROM thoth_sessions.sessions s WHERE s.id = review_decisions.session_id)
|
||||
)
|
||||
WITH CHECK (
|
||||
EXISTS (SELECT 1 FROM thoth_sessions.sessions s WHERE s.id = review_decisions.session_id)
|
||||
);
|
||||
|
||||
CREATE POLICY audit_admin_read ON thoth_sessions.audit_log
|
||||
FOR SELECT
|
||||
USING (pg_catalog.current_setting('thoth_sessions.is_admin', true) = 'true');
|
||||
CREATE POLICY audit_actor_write ON thoth_sessions.audit_log
|
||||
FOR INSERT
|
||||
WITH CHECK (
|
||||
pg_catalog.current_setting('thoth_sessions.is_admin', true) = 'true'
|
||||
OR (actor_issuer = pg_catalog.current_setting('thoth_sessions.actor_issuer', true)
|
||||
AND actor_subject = pg_catalog.current_setting('thoth_sessions.actor_subject', true))
|
||||
);
|
||||
Reference in New Issue
Block a user