Files
dsh_shenxian/src/db/sqlite.ts
T
admin 918f1d3a51 feat(models): 平台自建「模型设置」—— 用户自配厂家 / 条目各自开关 / 共享模型开关(档案 87)
- 官方「设置 → 模型」页在平台环境**必然报错**(判据在**浏览器页面**的 loopback 判定;官方 README 原文 Non-loopback pages get no durable settings)⇒ 该分区对全角色(含 admin)隐藏,用户自配改走平台自建页(插件 0.3.11)
- DB 迁移 V6:credential_vault.route/base_url/api/models + users.shared_model_enabled;并**重定义 getEnabledCredentialKeyRef**(互斥删除后原实现无 ORDER BY ⇒ 「任取一条」)
- 新落地层 src/web/model-landing.ts:spawn 时把「已启用条目」写进实例 .credentials.yaml 与 settings.yaml 的 llm-pi-ai.providers.<route>;字段名与官方包实测对齐(apiKeyEnv / baseURL / api,**不是** protocol);只碰自己写过的 + 一次性交接
- 接口 /api/me/keys、/api/me/keys/:id/toggle、/api/me/models/shared;前端新增「设置 → 模型设置」分区(settings.section id=model-settings / order 100 / 全角色)
- 顺手修两处:ensure-role-profile-patch.cjs 的 --force 整文件覆盖会抹掉 admin 的 disable-hmr 与 workspace-scoped-picker 两个平台块(改为 stripManagedBlock 只替换自己那段);verify-mem-model.mjs 因档案 86 重构而长期失败的陈旧断言

⚠️ 本提交同时包含**档案 86(admin 跨用户实例管理 + 两处改名)**的代码改动 —— 该部分已上线并端到端验证;其 import/register 与本次改动同处 src/web/server.ts、poc/business-plugins/lib/client.js 等文件,按**文件粒度无法拆分**,且不带它会让仓库 tsc 直接失败(缺 src/web/routes/admin-user-ops.ts)。
2026-09-14 00:00:15 +08:00

328 lines
9.8 KiB
TypeScript

/**
* SQLite backend for {@link DbAdapter}. Wraps the synchronous better-sqlite3
* repo in async methods and maps constraint errors onto the shared hierarchy.
* Used when `deployMode=local` (no `DSHS_DB_URL`).
*
* NOTE: better-sqlite3 is synchronous; the `async` here only matches the
* interface — the underlying calls still block the event loop. Fine for the
* small single-machine local mode this backend targets (see docs/k8s.md §5.1).
* @module dshs/db/sqlite
*/
import type { DbAdapter } from './adapter.js'
import { openDatabase, type Database } from './connection.js'
import { mapSqliteError } from './errors.js'
import {
audit as auditSync,
countAdmins as countAdminsSync,
createSession as createSessionSync,
createUser as createUserSync,
deleteBusinessPlugin as deleteBusinessPluginSync,
deleteCredentialKey as deleteCredentialKeySync,
deleteInstance as deleteInstanceSync,
deleteSession as deleteSessionSync,
deleteUser as deleteUserSync,
deleteUserInstances as deleteUserInstancesSync,
deleteUserSessions as deleteUserSessionsSync,
findBusinessPlugin as findBusinessPluginSync,
findDomainById as findDomainByIdSync,
findDomainByUser as findDomainByUserSync,
findInstance as findInstanceSync,
findSession as findSessionSync,
findSessionWithUser as findSessionWithUserSync,
hasActiveSession as hasActiveSessionSync,
findUserById as findUserByIdSync,
findUserBySlug as findUserBySlugSync,
findUserByUsername as findUserByUsernameSync,
findUserInstance as findUserInstanceSync,
findWorkspaceByPath as findWorkspaceByPathSync,
getEnabledCredentialKeyRef as getEnabledCredentialKeyRefSync,
getEnabledPluginIds as getEnabledPluginIdsSync,
getOrCreateWorkspace as getOrCreateWorkspaceSync,
getSharedModelEnabled as getSharedModelEnabledSync,
listBusinessPlugins as listBusinessPluginsSync,
listCredentialKeys as listCredentialKeysSync,
listCredentialLandingRows as listCredentialLandingRowsSync,
listDomains as listDomainsSync,
listEnabledCredentialKeys as listEnabledCredentialKeysSync,
listInstancesByRole as listInstancesByRoleSync,
listPublicUsers as listPublicUsersSync,
listUsersWithoutUid as listUsersWithoutUidSync,
selectCredentialKey as selectCredentialKeySync,
setCredentialKey as setCredentialKeySync,
setDomainVerified as setDomainVerifiedSync,
setFolderPlugins as setFolderPluginsSync,
setInstanceStatus as setInstanceStatusSync,
setSharedModelEnabled as setSharedModelEnabledSync,
setUserRole as setUserRoleSync,
setUserUid as setUserUidSync,
toggleCredentialKey as toggleCredentialKeySync,
upsertBusinessPlugin as upsertBusinessPluginSync,
upsertDomain as upsertDomainSync,
upsertInstance as upsertInstanceSync,
} from './repo.js'
import type {
BusinessPlugin,
CredentialKey,
CredentialKeyMeta,
CredentialLandingRow,
CreateSessionInput,
CreateUserInput,
Domain,
DshInstance,
DshInstanceRole,
DshInstanceStatus,
PublicUser,
SessionRow,
SessionUser,
UpsertBusinessPluginInput,
UpsertDshInstanceInput,
User,
UserRole,
Workspace,
} from './types.js'
export class SqliteAdapter implements DbAdapter {
private readonly db: Database
constructor(path: string, private readonly baseUid: number) {
this.db = openDatabase(path)
}
async createUser(input: CreateUserInput): Promise<User> {
try {
return createUserSync(this.db, input, this.baseUid)
} catch (e) {
mapSqliteError(e)
}
}
async findUserByUsername(username: string): Promise<User | undefined> {
return findUserByUsernameSync(this.db, username)
}
async findUserBySlug(slug: string): Promise<User | undefined> {
return findUserBySlugSync(this.db, slug)
}
async findUserById(id: string): Promise<User | undefined> {
return findUserByIdSync(this.db, id)
}
async listPublicUsers(): Promise<PublicUser[]> {
return listPublicUsersSync(this.db)
}
async countAdmins(): Promise<number> {
return countAdminsSync(this.db)
}
async setUserRole(id: string, role: UserRole, approvedBy?: string): Promise<boolean> {
return setUserRoleSync(this.db, id, role, approvedBy)
}
async setUserUid(userId: string, uid: number): Promise<void> {
setUserUidSync(this.db, userId, uid)
}
async listUsersWithoutUid(): Promise<string[]> {
return listUsersWithoutUidSync(this.db)
}
async createSession(input: CreateSessionInput): Promise<void> {
try {
createSessionSync(this.db, input)
} catch (e) {
mapSqliteError(e)
}
}
async findSession(tokenHash: string): Promise<SessionRow | undefined> {
return findSessionSync(this.db, tokenHash)
}
async deleteSession(tokenHash: string): Promise<void> {
deleteSessionSync(this.db, tokenHash)
}
async deleteUserSessions(userId: string): Promise<void> {
deleteUserSessionsSync(this.db, userId)
}
async findSessionWithUser(tokenHash: string): Promise<SessionUser | undefined> {
return findSessionWithUserSync(this.db, tokenHash)
}
async hasActiveSession(userId: string): Promise<boolean> {
return hasActiveSessionSync(this.db, userId)
}
async audit(actor: string | null, action: string, detail?: string | null): Promise<void> {
auditSync(this.db, actor, action, detail)
}
async findWorkspaceByPath(userId: string, relPath: string): Promise<Workspace | undefined> {
return findWorkspaceByPathSync(this.db, userId, relPath)
}
async getOrCreateWorkspace(userId: string, relPath: string): Promise<Workspace> {
try {
return getOrCreateWorkspaceSync(this.db, userId, relPath)
} catch (e) {
mapSqliteError(e)
}
}
async setFolderPlugins(
workspaceId: string,
selections: ReadonlyArray<{ id: string; enabled: boolean }>,
): Promise<void> {
try {
setFolderPluginsSync(this.db, workspaceId, selections)
} catch (e) {
mapSqliteError(e)
}
}
async getEnabledPluginIds(workspaceId: string): Promise<string[]> {
return getEnabledPluginIdsSync(this.db, workspaceId)
}
async listBusinessPlugins(): Promise<BusinessPlugin[]> {
return listBusinessPluginsSync(this.db)
}
async findBusinessPlugin(id: string): Promise<BusinessPlugin | undefined> {
return findBusinessPluginSync(this.db, id)
}
async upsertBusinessPlugin(input: UpsertBusinessPluginInput): Promise<BusinessPlugin> {
try {
return upsertBusinessPluginSync(this.db, input)
} catch (e) {
mapSqliteError(e)
}
}
async deleteBusinessPlugin(id: string): Promise<boolean> {
return deleteBusinessPluginSync(this.db, id)
}
async findDomainByUser(userId: string): Promise<Domain | undefined> {
return findDomainByUserSync(this.db, userId)
}
async findDomainById(id: string): Promise<Domain | undefined> {
return findDomainByIdSync(this.db, id)
}
async listDomains(): Promise<Domain[]> {
return listDomainsSync(this.db)
}
async upsertDomain(userId: string, domain: string, nginxConfig: string): Promise<Domain> {
try {
return upsertDomainSync(this.db, userId, domain, nginxConfig)
} catch (e) {
mapSqliteError(e)
}
}
async setDomainVerified(id: string, verified: boolean): Promise<boolean> {
return setDomainVerifiedSync(this.db, id, verified)
}
async listCredentialKeys(userId: string): Promise<CredentialKey[]> {
return listCredentialKeysSync(this.db, userId)
}
async listEnabledCredentialKeys(userId: string): Promise<CredentialKey[]> {
return listEnabledCredentialKeysSync(this.db, userId)
}
async listCredentialLandingRows(userId: string): Promise<CredentialLandingRow[]> {
return listCredentialLandingRowsSync(this.db, userId)
}
async getEnabledCredentialKeyRef(userId: string): Promise<string | null> {
return getEnabledCredentialKeyRefSync(this.db, userId)
}
async setCredentialKey(
userId: string,
name: string,
encryptedRef: string,
meta?: CredentialKeyMeta,
): Promise<CredentialKey> {
try {
return setCredentialKeySync(this.db, userId, name, encryptedRef, meta)
} catch (e) {
mapSqliteError(e)
}
}
async selectCredentialKey(userId: string, id: string): Promise<boolean> {
return selectCredentialKeySync(this.db, userId, id)
}
async toggleCredentialKey(userId: string, id: string, enabled: boolean): Promise<boolean> {
return toggleCredentialKeySync(this.db, userId, id, enabled)
}
async getSharedModelEnabled(userId: string): Promise<boolean> {
return getSharedModelEnabledSync(this.db, userId)
}
async setSharedModelEnabled(userId: string, enabled: boolean): Promise<boolean> {
return setSharedModelEnabledSync(this.db, userId, enabled)
}
async deleteCredentialKey(userId: string, id: string): Promise<boolean> {
return deleteCredentialKeySync(this.db, userId, id)
}
async deleteUser(userId: string): Promise<boolean> {
return deleteUserSync(this.db, userId)
}
async upsertInstance(input: UpsertDshInstanceInput): Promise<void> {
try {
upsertInstanceSync(this.db, input)
} catch (e) {
mapSqliteError(e)
}
}
async findInstance(id: string): Promise<DshInstance | undefined> {
return findInstanceSync(this.db, id)
}
async findUserInstance(userId: string, role: DshInstanceRole): Promise<DshInstance | undefined> {
return findUserInstanceSync(this.db, userId, role)
}
async listInstancesByRole(role: DshInstanceRole): Promise<DshInstance[]> {
return listInstancesByRoleSync(this.db, role)
}
async setInstanceStatus(
id: string,
status: DshInstanceStatus,
outcome?: { exitCode?: number; lastError?: string },
): Promise<boolean> {
return setInstanceStatusSync(this.db, id, status, outcome)
}
async deleteInstance(id: string): Promise<boolean> {
return deleteInstanceSync(this.db, id)
}
async deleteUserInstances(userId: string): Promise<void> {
deleteUserInstancesSync(this.db, userId)
}
async close(): Promise<void> {
this.db.close()
}
}