perf: optimize CMS queries, caching, and asset delivery
CI / check (push) Successful in 27s
CI / release (push) Skipped
CI / deploy (push) Successful in 57s

Database:
- Add missing indexes (users.credits, users_currency(type,amount),
  users_settings.respects_received, camera_web.timestamp,
  messenger_offline.user_id) via migrations 0020/0021
- Use partial .select() everywhere instead of SELECT * (tickets, users,
  rooms, audit logs, catalog tree, polls, radio, password reset)
- Add queryPrepared/queryPreparedOne (server-side prepared statements)
  and switch the login check to a prepared statement; drop dead
  cache options from the pool config
- Raise total_users/total_rooms COUNT(*) cache TTL to 5m

Caching:
- Consolidate the three cache helpers (cached, redisCache, cachedQuery)
  into a single memory-first implementation backed by Redis
- invalidateKey now clears the in-process cache as well as Redis
- Cache homepage sections, news list, and leaderboard tabs; share one
  news_list cache key between homepage and news archive
- siteSettings: in-process cache with TTL so repeated getters no longer
  pay a Redis round-trip per call
- Share a 10s poll cache across all radio SSE connections
- Normalize timestamps after cache reads (Redis JSON round-trip)

Assets:
- Enable AVIF/WebP via images.formats and remove unoptimized from news
  covers and the homepage hero (149KB jpg) with proper sizes/priority
- Support ?format=webp|avif|png in the /imaging proxy via sharp

Other:
- Fix pnpm supply-chain minimumReleaseAge failures by excluding the
  freshly-published packages (next 16.3.1, hookform resolvers 5.8.0,
  resend 6.20.0)
- Remove unused before/after fields from housekeeping AuditEntry
This commit is contained in:
openhands committed 2026-08-14 11:20:37 +02:00
1 parent dc9e5a567c
commit e5ec3c1f06
29 files changed
+532 -322

No files matched your search

+18 -8
View File
@@ -5,6 +5,11 @@ import { redis } from "@/lib/redis";
type CacheEntry<T> = { data: T; expiresAt: number };
const memory = new Map<string, CacheEntry<unknown>>();
/** Drop a key from the in-process cache (used when an upstream value changes). */
export function invalidateMemory(key: string): void {
memory.delete(key);
}
/**
* Redis-first cached query with an in-memory fallback.
* Use for read-heavy endpoints polled by the browser (online count, etc.).
@@ -16,24 +21,29 @@ export async function cached<T>(
): Promise<T> {
const ttlSec = Math.ceil(ttlMs / 1000);
// In-memory fast path — served first so repeated reads within a TTL window
// don't each pay a Redis round-trip (Redis is still the shared fallback).
// `existing &&` short-circuits so Date.now() is never evaluated during
// prerender when the map is empty (keeps `next build` prerendering clean).
const existing = memory.get(key);
if (existing && existing.expiresAt > Date.now()) {
return existing.data as T;
}
// Redis path (shared across instances).
if (redis && redis.status !== "end") {
try {
const cached = await redis.get(key);
if (cached !== null && cached !== undefined) {
return JSON.parse(cached) as T;
const data = JSON.parse(cached) as T;
memory.set(key, { data, expiresAt: Date.now() + ttlMs });
return data;
}
} catch {
/* fall through to DB / memory */
/* fall through to fn */
}
}
// In-memory fallback (single-instance fast path).
const existing = memory.get(key);
if (existing && existing.expiresAt > Date.now()) {
return existing.data as T;
}
const data = await fn();
if (redis && redis.status !== "end") {
+17 -37
View File
@@ -1,52 +1,32 @@
import "server-only";
import { logger } from "@/lib/logger";
import { cached, invalidateMemory } from "@/lib/cache";
import { redis } from "@/lib/redis";
const DEFAULT_CACHE_TTL = 60;
function isRedisAvailable(): boolean {
return !!redis && redis.status !== "end";
}
/**
* Redis-backed cached query with an in-process fast path (see `cached()`).
* Use for read-heavy lookups that are safe to serve slightly stale
* (login user, article bodies, …). Redis stays the shared source of truth.
*/
export async function cachedQuery<T>(
cacheKey: string,
queryFn: () => Promise<T>,
ttl: number = DEFAULT_CACHE_TTL,
): Promise<T> {
if (!isRedisAvailable()) {
return queryFn();
}
try {
const cached = await redis?.get(cacheKey);
if (cached !== null && cached !== undefined) {
return JSON.parse(cached) as T;
}
} catch (err) {
logger.warn("[cache] read failed, falling back to DB", {
key: cacheKey,
error: String(err),
});
}
const result = await queryFn();
try {
await redis?.setex(cacheKey, ttl, JSON.stringify(result));
} catch (err) {
logger.warn("[cache] write failed, continuing without cache", {
key: cacheKey,
error: String(err),
});
}
return result;
return cached(cacheKey, ttl * 1000, queryFn);
}
/** Invalidate a single cache key immediately. */
/** Invalidate a single cache key immediately (memory + Redis). */
export async function invalidateKey(key: string): Promise<number> {
if (!isRedisAvailable()) return 0;
if (!redis) return 0;
return redis.del(key);
invalidateMemory(key);
if (redis && redis.status !== "end") {
try {
return await redis.del(key);
} catch {
return 0;
}
}
return 0;
}
+36 -9
View File
@@ -1,4 +1,5 @@
import { drizzle, type MySql2Database } from "drizzle-orm/mysql2";
import { drizzle } from "drizzle-orm/mysql2";
import type { Pool as MySqlPool } from "mysql2/promise";
import mysql from "mysql2/promise";
import * as relations from "@/db/relations";
import * as schema from "@/db/schema";
@@ -8,10 +9,10 @@ import { resolveConnectionLimit } from "@/lib/db-pool";
const fullSchema = { ...schema, ...relations };
const globalForDb = globalThis as unknown as {
db?: MySql2Database<typeof fullSchema>;
db?: ReturnType<typeof createDb>;
};
function createDb(): MySql2Database<typeof fullSchema> {
function createDb() {
const url = new URL(env.DATABASE_URL);
const isBuild =
process.env.NEXT_PHASE === "phase-production-build" ||
@@ -35,11 +36,6 @@ function createDb(): MySql2Database<typeof fullSchema> {
connectTimeout,
idleTimeout: env.DATABASE_IDLE_TIMEOUT_MS,
enableKeepAlive: true,
// Prepared-statement caching via mysql2's native support (Node 22+).
// Saves query-parse per request on hot paths.
...("cache" in mysql.createPool && {
cache: { type: "prepared" },
}),
// Allow :placeholder syntax for raw SQL helpers.
namedPlaceholders: true,
// Reject multiple statements (SQL injection hardening).
@@ -65,6 +61,37 @@ export const db = globalForDb.db ?? createDb();
if (env.NODE_ENV !== "production") globalForDb.db = db;
export type Db = MySql2Database<typeof fullSchema>;
export type Db = ReturnType<typeof createDb>;
type PreparedValue = string | number | bigint | boolean | Date | null | Buffer;
/**
* Server-side prepared statements (mysql2 pool.execute()).
*
* Drizzle's mysql2 driver runs `.select()` through the text protocol
* (pool.query()), so it never uses server-side prepared statements. For
* hot-path queries the SQL is parsed once on the server per connection
* instead of every execution. Column aliases let you pick exactly the
* columns you need (no SELECT *).
*/
export async function queryPrepared<T extends Record<string, unknown>>(
sql: string,
params?: PreparedValue[],
): Promise<T[]> {
const client = db.$client as MySqlPool;
const [rows] = (await client.execute(sql, params)) as unknown as [
T[],
unknown,
];
return rows ?? [];
}
export async function queryPreparedOne<T extends Record<string, unknown>>(
sql: string,
params?: PreparedValue[],
): Promise<T | null> {
const rows = await queryPrepared<T>(sql, params);
return rows[0] ?? null;
}
export * from "@/db/schema";
+4 -23
View File
@@ -1,36 +1,17 @@
import "server-only";
import { redis } from "@/lib/redis";
import { cached } from "@/lib/cache";
/**
* Cache the result of a fetch function in Redis.
* Falls back to the fresh fetch if Redis is unavailable.
* Cache the result of a fetch function, memory-first with a Redis fallback
* (see `cached()`). TTL is given in seconds.
*/
export async function redisCache<T>(
key: string,
ttlSeconds: number,
fetch: () => Promise<T>,
): Promise<T> {
if (!redis) return fetch();
try {
const cached = await redis.get(key);
if (cached !== null) {
return JSON.parse(cached) as T;
}
} catch {
// cache miss or error — fall through to fresh fetch
}
const fresh = await fetch();
try {
await redis.setex(key, ttlSeconds, JSON.stringify(fresh));
} catch {
// ignore write errors
}
return fresh;
return cached(key, ttlSeconds * 1000, fetch);
}
/**
+9 -1
View File
@@ -87,7 +87,15 @@ export async function getAuditLogs(options: GetLogsOptions = {}) {
const [rows, totalResult] = await Promise.all([
db
.select()
.select({
id: AdminAuditLog.id,
userId: AdminAuditLog.userId,
action: AdminAuditLog.action,
target: AdminAuditLog.target,
targetId: AdminAuditLog.targetId,
diff: AdminAuditLog.diff,
createdAt: AdminAuditLog.createdAt,
})
.from(AdminAuditLog)
.where(where)
.orderBy(desc(AdminAuditLog.id))
+11 -1
View File
@@ -60,7 +60,17 @@ export async function getCatalogItemCounts(
*/
export async function getTreeFlat(): Promise<TreeNode[]> {
const allPages = await db
.select()
.select({
id: CatalogPages.id,
parentId: CatalogPages.parentId,
caption: CatalogPages.caption,
pageLayout: CatalogPages.pageLayout,
iconColor: CatalogPages.iconColor,
iconImage: CatalogPages.iconImage,
orderNum: CatalogPages.orderNum,
visible: CatalogPages.visible,
enabled: CatalogPages.enabled,
})
.from(CatalogPages)
.orderBy(asc(CatalogPages.orderNum));
const itemCountMap = await getCatalogItemCounts();
+57
View File
@@ -0,0 +1,57 @@
import "server-only";
import { desc } from "drizzle-orm";
import { cached } from "@/lib/cache";
import { db, WebsiteArticles } from "@/lib/db";
export interface NewsListItem {
slug: string;
title: string;
shortStory: string;
image: string;
createdAt: Date | null;
}
interface NewsListRow {
slug: string;
title: string;
shortStory: string;
image: string;
createdAt: Date | null;
}
const TTL_MS = 300_000;
const CACHE_KEY = "news_list";
const FETCH_LIMIT = 30;
/**
* Shared, cached news list used by both the homepage and the news archive so
* a single "news_list" cache entry serves both routes. Returns at most
* `limit` rows with `createdAt` normalized to a Date (the cache round-trip
* serializes timestamps to ISO strings).
*/
export async function getNewsList(limit: number): Promise<NewsListItem[]> {
try {
const rows = await cached<NewsListRow[]>(CACHE_KEY, TTL_MS, () =>
db
.select({
slug: WebsiteArticles.slug,
title: WebsiteArticles.title,
shortStory: WebsiteArticles.shortStory,
image: WebsiteArticles.image,
createdAt: WebsiteArticles.createdAt,
})
.from(WebsiteArticles)
.orderBy(desc(WebsiteArticles.createdAt))
.limit(FETCH_LIMIT),
);
return rows
.map((a) => ({
...a,
createdAt: a.createdAt ? new Date(a.createdAt) : null,
}))
.slice(0, limit);
} catch {
return [];
}
}
+17 -2
View File
@@ -27,6 +27,21 @@ export interface NowPlaying {
artist: string | null;
}
// Shared in-process poll cache: every connected SSE client (players, widgets)
// would otherwise hit the radio API once per 10s each. With one cache entry per
// endpoint, N connections cost 1 request per interval regardless of N.
const POLL_CACHE_TTL_MS = 10_000;
const pollCache = new Map<string, { data: unknown; expiresAt: number }>();
async function cachedFetchJson(url: string, ms = 4000): Promise<unknown> {
const now = Date.now();
const hit = pollCache.get(url);
if (hit && hit.expiresAt > now) return hit.data;
const data = await fetchJson(url, ms);
pollCache.set(url, { data, expiresAt: now + POLL_CACHE_TTL_MS });
return data;
}
async function fetchJson(url: string, ms = 4000): Promise<unknown> {
if (!isSafeUrl(url)) return null;
const controller = new AbortController();
@@ -88,13 +103,13 @@ function parseNowPlaying(d: unknown): NowPlaying | null {
export async function fetchNowPlaying(): Promise<NowPlaying | null> {
const url = (await siteSettings.get("radio_now_playing_api_url", "")) ?? "";
if (!url) return null;
return parseNowPlaying(await fetchJson(url));
return parseNowPlaying(await cachedFetchJson(url));
}
export async function fetchListeners(): Promise<number | null> {
const url = (await siteSettings.get("radio_listeners_api_url", "")) ?? "";
if (!url) return null;
const d = await fetchJson(url);
const d = await cachedFetchJson(url);
if (d == null) return null;
const obj = d as { listeners?: unknown; current_listeners?: unknown };
const raw =
+24 -4
View File
@@ -15,9 +15,20 @@ const DEFAULTS: Record<string, string> = {
const CACHE_TTL_MS = 300_000;
const REDIS_CACHE_KEY = "site_settings";
// Short in-process window so repeated getters in one request (header, nav,
// footer all read hotel_name / logo) don't each pay a Redis round-trip.
// Redis stays the source of truth across instances.
const MEMORY_TTL_MS = 60_000;
// During `next build`, pages are prerendered and `Date.now()` is treated as an
// unstable prerender value — always serve the in-process cache then (settings
// cannot change mid-build). Runtime keeps the normal TTL check.
const IS_PRERENDER =
process.env.NEXT_PHASE === "phase-production-build" ||
process.env.NEXT_PHASE === "phase-production-compile";
class SiteSettings {
private cache: Map<string, string> | null = null;
private cache: { map: Map<string, string>; expiresAt: number } | null = null;
private async loadFromDb(): Promise<Map<string, string>> {
try {
@@ -32,22 +43,31 @@ class SiteSettings {
}
private async load(): Promise<Map<string, string>> {
if (this.cache !== null) {
if (IS_PRERENDER || this.cache.expiresAt > Date.now()) {
return this.cache.map;
}
}
if (redis) {
try {
const cached = await redis.get(REDIS_CACHE_KEY);
if (cached) {
const parsed = JSON.parse(cached) as Record<string, string>;
return new Map(Object.entries(parsed));
const map = new Map(Object.entries(parsed));
this.cache = { map, expiresAt: Date.now() + MEMORY_TTL_MS };
return map;
}
} catch {
logger.warn("Redis cache read failed for site settings");
}
}
if (this.cache !== null) return this.cache;
// Expired but usable fallback — keeps the site up if both Redis and DB fail.
if (this.cache !== null) return this.cache.map;
const map = await this.loadFromDb();
this.cache = map;
this.cache = { map, expiresAt: Date.now() + MEMORY_TTL_MS };
if (redis) {
try {