MutateManagedWarehouse loads the existing warehouse (or a zero value if none), calls mutate to apply changes, and persists the result — all inside a single transaction with a row-level lock on the warehouse row. Closes the read-modify-write race that plain Get+Upsert is exposed to when concurrent PU
(orgID string, mutate func(*configstore.ManagedWarehouse) error)
| 145 | // Service grants (duckgres_service_grants): every minted service |
| 146 | // credential, all statuses (live / expired / revoked). Read carries NO |
| 147 | // secret material (PasswordHash is json:"-"); revoke sets revoked_at and |
| 148 | // blanks the stored hash server-side. Both are ordinary admin-console |
| 149 | // routes behind the group middleware (valid admin session + audit). |
| 150 | r.GET("/orgs/:id/service-grants", h.listServiceGrants) |
no outgoing calls