Commit key-purge migration DML (backfill fingerprint, purge plaintext idempotently)
This commit is contained in:
1 parent
c213a489e9
commit
e92e29bac0
1 file changed
+7
-3
+7
-3
@@ -292,13 +292,17 @@ def get_db() -> sqlite3.Connection:
|
|||||||
ak_cols = [r[1] for r in conn.execute("PRAGMA table_info(member_api_keys)").fetchall()]
|
ak_cols = [r[1] for r in conn.execute("PRAGMA table_info(member_api_keys)").fetchall()]
|
||||||
if "fingerprint" not in ak_cols:
|
if "fingerprint" not in ak_cols:
|
||||||
conn.execute("ALTER TABLE member_api_keys ADD COLUMN fingerprint TEXT")
|
conn.execute("ALTER TABLE member_api_keys ADD COLUMN fingerprint TEXT")
|
||||||
# Backfill fingerprints for keys that already have plaintext stored,
|
# Backfill fingerprints for any key still holding plaintext (fingerprint =
|
||||||
# then purge the plaintext. (fingerprint = last-4 of the key.)
|
# last-4 of the key), then purge the plaintext. Idempotent — runs every
|
||||||
|
# time, affects only rows where plaintext is still present.
|
||||||
conn.execute(
|
conn.execute(
|
||||||
"UPDATE member_api_keys SET fingerprint = substr(sk_token, -4) "
|
"UPDATE member_api_keys SET fingerprint = substr(sk_token, -4) "
|
||||||
"WHERE fingerprint IS NULL AND sk_token != ''"
|
"WHERE (fingerprint IS NULL OR fingerprint = '') AND sk_token != ''"
|
||||||
)
|
)
|
||||||
conn.execute("UPDATE member_api_keys SET sk_token = '' WHERE sk_token != ''")
|
conn.execute("UPDATE member_api_keys SET sk_token = '' WHERE sk_token != ''")
|
||||||
|
# Commit the DML above — ALTER TABLE auto-commits, but the UPDATEs open an
|
||||||
|
# implicit transaction that would otherwise roll back when get_db() closes.
|
||||||
|
conn.commit()
|
||||||
return conn
|
return conn
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
Reference in new issue
Block a user