diff options
| author | Christophe Besson <cbesson@gmail.com> | 2026-09-12 13:47:49 +0200 |
|---|---|---|
| committer | Christophe Besson <cbesson@gmail.com> | 2026-09-12 16:36:54 +0200 |
| commit | e671b931fd594a39fc840916c81b5d4b1f1e3227 (patch) | |
| tree | 886b1e5eac7d178606510f330b1faa2b4b177892 /packages/meshbay-hub/src/meshbay_hub/db/migrations | |
| parent | 17c06bc23252929af13f4361c4a6300ee76a0c51 (diff) | |
| download | meshbay-e671b931fd594a39fc840916c81b5d4b1f1e3227.tar.gz | |
fix(hub): the mail allowance is written down, and recovery keeps a share
Two dicts in `mail.py` held the budget, so every deploy handed out a fresh
one — and this hub is deployed several times a day. A bound a restart forgets
is not a bound, for the reason the denylist is persisted rather than held in
memory (S3). It is a `mail_quota` table now, one row per counter, the
recipient hashed so the table does not become a list of plaintext addresses.
The counting moves with it, into an async `reserve` that has a session, and
`send_off_loop` is the one door it stands in. `_send` keeps the purpose
allow-list: that half needs no state, and it is what stops anything which
puts a message on the wire from naming a reason this hub does not send for.
The caller owns the commit, so a request that fails afterwards is not charged
for mail nobody received.
`hourly_reserved_for_recovery` is new. A flood of sign-ups used to be able to
spend the whole hour and lock out the person waiting on a passphrase reset;
registration and address changes may now spend only the unreserved share.
Values changed as agreed: 10 messages a day to one recipient, 300 s between
two reset codes. The address-change ceiling and its cooldown were two bounds
on one thing — 3 a day and 60 s apart — and collapse into one 48-hour delay.
Asking again for the address already pending is exempt: it reaches no new
recipient, that recipient is bounded anyway, and without the exemption a typo
locked the account out of correcting it for two days.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01T4YmK41VsEURWFdop4EEeT
Diffstat (limited to 'packages/meshbay-hub/src/meshbay_hub/db/migrations')
| -rw-r--r-- | packages/meshbay-hub/src/meshbay_hub/db/migrations/versions/e5f6a7b8c9d0_add_mail_quota.py | 36 |
1 files changed, 36 insertions, 0 deletions
diff --git a/packages/meshbay-hub/src/meshbay_hub/db/migrations/versions/e5f6a7b8c9d0_add_mail_quota.py b/packages/meshbay-hub/src/meshbay_hub/db/migrations/versions/e5f6a7b8c9d0_add_mail_quota.py new file mode 100644 index 0000000..8f2e4d2 --- /dev/null +++ b/packages/meshbay-hub/src/meshbay_hub/db/migrations/versions/e5f6a7b8c9d0_add_mail_quota.py @@ -0,0 +1,36 @@ +"""add mail_quota + +The hub's outbound mail allowance, kept across restarts. It lived in two +dicts in `mail.py`, so every deploy handed out a fresh budget — and the hub is +deployed often. A bound a restart forgets is not a bound. + +Revision ID: e5f6a7b8c9d0 +Revises: d4e5f6a7b8c9 +""" + +from typing import Sequence, Union + +import sqlalchemy as sa +from alembic import op + +revision: str = "e5f6a7b8c9d0" +down_revision: Union[str, Sequence[str], None] = "d4e5f6a7b8c9" +branch_labels: Union[str, Sequence[str], None] = None +depends_on: Union[str, Sequence[str], None] = None + + +def upgrade() -> None: + op.create_table( + "mail_quota", + sa.Column("key", sa.String(64), primary_key=True), + sa.Column("window_start", sa.DateTime(timezone=True), nullable=False), + sa.Column("count", sa.Integer(), nullable=False, server_default="0"), + sa.Column("last_sent", sa.DateTime(timezone=True), nullable=True), + ) + + +def downgrade() -> None: + # Dropping this returns the hub to sending with no recorded history, not to + # sending without a bound: the limits themselves live in `hub_settings` and + # in the configuration file. + op.drop_table("mail_quota") |