fix(cache): stop serving stale site-settings defaults after deploy
CI / check (push) Successful in 1m3s
CI / deploy (push) Successful in 57s

The site-settings loader kept an in-process map forever after a Redis miss
and promoted DEFAULTS (no logo/theme) to Redis on any DB error, so a build
that started before the DB was reachable stuck the site on the preset logo
and default theme until a manual reload or full restart.

- Redis miss now reloads from the database instead of the stale in-process map
- a DB failure returns defaults only as an in-process last resort and never
  writes them to Redis, so the shared cache can't be poisoned by a transient
  error at startup
- regression tests: DB re-read on Redis miss after cache expiry, defaults never
  promoted to Redis, recovery from transient DB failure
This commit is contained in:
openhands committed 2026-09-06 12:56:29 +02:00
1 parent 9dc9d1fa4b
commit 35f66d879f
2 files changed
+81 -19

No files matched your search

+46 -1
View File
@@ -1,6 +1,14 @@
import { beforeEach, describe, expect, it, vi } from "vitest";
const { selectFrom } = vi.hoisted(() => ({ selectFrom: vi.fn() }));
const { selectFrom, redisMock } = vi.hoisted(() => ({
selectFrom: vi.fn(),
redisMock: {
get: vi.fn(),
setex: vi.fn(),
del: vi.fn(),
},
}));
vi.mock("@/lib/db", () => ({
db: {
select: () => ({
@@ -15,10 +23,18 @@ vi.mock("@/lib/db", () => ({
WebsiteSetting: { key: "WebsiteSetting.key", value: "WebsiteSetting.value" },
}));
vi.mock("@/lib/redis", () => ({ redis: redisMock }));
import { siteSettings } from "./site-settings";
beforeEach(async () => {
selectFrom.mockReset();
redisMock.get.mockReset();
redisMock.setex.mockReset();
redisMock.del.mockReset();
redisMock.get.mockResolvedValue(null);
redisMock.setex.mockResolvedValue(undefined);
redisMock.del.mockResolvedValue(undefined);
await siteSettings.reload();
});
@@ -53,4 +69,33 @@ describe("siteSettings", () => {
await siteSettings.get("hotel_name");
expect(selectFrom).toHaveBeenCalledTimes(2);
});
it("re-reads the database on a Redis miss instead of serving stale cache", async () => {
vi.useFakeTimers();
try {
selectFrom.mockResolvedValue([{ key: "hotel_name", value: "First" }]);
expect(await siteSettings.get("hotel_name")).toBe("First");
selectFrom.mockResolvedValue([{ key: "hotel_name", value: "Second" }]);
vi.setSystemTime(Date.now() + 2 * 60_000); // expire the in-memory cache
expect(await siteSettings.get("hotel_name")).toBe("Second");
} finally {
vi.useRealTimers();
}
});
it("does not promote defaults to Redis when the database fails", async () => {
selectFrom.mockRejectedValue(new Error("db down"));
expect(await siteSettings.get("hotel_name", "fallback")).toBe("fallback");
expect(redisMock.setex).not.toHaveBeenCalled();
});
it("recovers from a transient database failure on the next load", async () => {
selectFrom.mockRejectedValueOnce(new Error("db down"));
expect(await siteSettings.get("hotel_name", "fallback")).toBe("fallback");
selectFrom.mockResolvedValueOnce([{ key: "hotel_name", value: "Live" }]);
expect(await siteSettings.get("hotel_name")).toBe("Live");
expect(redisMock.setex).toHaveBeenCalledTimes(1);
});
});
+35 -18
View File
@@ -32,15 +32,15 @@ class SiteSettings {
// not each hammer Redis/DB (cache-stampede protection).
private inFlight: Promise<Map<string, string>> | null = null;
private async loadFromDb(): Promise<Map<string, string>> {
private async loadFromDb(): Promise<Map<string, string> | null> {
try {
const rows = await db
.select({ key: WebsiteSetting.key, value: WebsiteSetting.value })
.from(WebsiteSetting);
return new Map(rows.map((r) => [r.key, r.value]));
} catch {
logger.warn("Failed to load site settings from database, using defaults");
return new Map(Object.entries(DEFAULTS));
logger.warn("Failed to load site settings from database");
return null;
}
}
@@ -59,26 +59,43 @@ class SiteSettings {
}
}
// Expired but usable fallback — keeps the site up if both Redis and DB fail.
if (this.cache !== null) return this.cache.map;
// Redis miss/unavailable → the database is authoritative. Reloading here
// (instead of serving the in-process map) is what picks up changes made
// by other instances after the Redis TTL expires.
const map = await this.loadFromDb();
this.cache = { map, expiresAt: Date.now() + MEMORY_TTL_MS };
if (map) {
this.cache = { map, expiresAt: Date.now() + MEMORY_TTL_MS };
if (redis) {
try {
const obj = Object.fromEntries(map.entries());
await redis.setex(
REDIS_CACHE_KEY,
Math.ceil(CACHE_TTL_MS / 1000),
JSON.stringify(obj),
);
} catch {
logger.warn("Failed to write site settings to Redis cache");
if (redis) {
try {
const obj = Object.fromEntries(map.entries());
await redis.setex(
REDIS_CACHE_KEY,
Math.ceil(CACHE_TTL_MS / 1000),
JSON.stringify(obj),
);
} catch {
logger.warn("Failed to write site settings to Redis cache");
}
}
return map;
}
return map;
// DB unavailable → keep serving the last known-good map from memory.
if (this.cache !== null) {
logger.warn("Site settings: database unreachable, serving stale cache");
return this.cache.map;
}
// Nothing cached in this process and the DB is down → last resort. These
// defaults are kept in-memory only and never written to Redis, so a
// momentary DB failure at startup can't poison the shared cache and
// downgrade every instance to the default/preset branding.
logger.warn(
"Site settings: database unreachable and no cached copy, using defaults",
);
return new Map(Object.entries(DEFAULTS));
}
private async load(): Promise<Map<string, string>> {