perf: optimize DB layer with caching and pool tuning
CI / check (push) Successful in 36s
CI / release (push) Skipped
CI / deploy (push) Successful in 1m35s

- Add Redis cache wrapper (cached-db.ts) — cachedQuery + invalidate helpers
- Add cached login user lookup (auth.ts: getLoginUser) — short 15s TTL
  for brute-force protection, cache invalidation on password/rank changes
- Switch auth.ts login flow from Prisma facade to raw SQL via db.execute
  (avoids abstraction overhead for this hot path)
- Cache invalidation wired in: login password upgrade, updateUser, resetPassword
- Connection pool tuning: enableKeepAlive, namedPlaceholders,
  prepared statement cache (Node 22+), multipleStatements off (SQLi hardening)
- 0 tsc errors, 583 tests passing
This commit is contained in:
openhands committed 2026-07-31 15:01:34 +02:00
1 parent c0bbcae5d6
commit ef5e706ee1
4 files changed
+152 -4

No files matched your search

+3
View File
@@ -3,6 +3,7 @@
import crypto from "node:crypto";
import { z } from "zod";
import { hashPassword } from "@/lib/auth/password";
import { invalidateLoginCache } from "@/lib/auth";
import { PERMS } from "@/lib/permissions";
import { prisma } from "@/lib/prisma";
import { adminAction } from "@/lib/safe-action";
@@ -119,6 +120,7 @@ export const updateUser = adminAction(
}
await prisma.user.update({ where: { id }, data: userData });
invalidateLoginCache(targetUser.username);
if (diamonds !== undefined) {
await prisma.usersCurrency.upsert({
@@ -313,6 +315,7 @@ export const resetPassword = adminAction(
where: { id: ctx.data.userId },
data: { password: hashed },
});
invalidateLoginCache(target.username);
logAudit({
userId: ctx.session.user.id,