()
| 6976 | // ------------------------------------------------------------------ |
| 6977 | |
| 6978 | const makeAdmin = (): ExecutorAdmin => { |
| 6979 | const platformCore = makeCoreDb( |
| 6980 | makeFumaClient( |
| 6981 | withQueryContext(rootDbUntyped, { |
| 6982 | ...ownerContext, |
| 6983 | reach: "tenant", |
| 6984 | } satisfies ExecutorOwnerPolicyContext), |
| 6985 | ), |
| 6986 | ); |
| 6987 | |
| 6988 | const rowToAdminSubject = (row: CoreRow<"subject">): AdminSubject => ({ |
| 6989 | externalId: row.external_id, |
| 6990 | createdAt: row.created_at instanceof Date ? row.created_at : new Date(row.created_at), |
| 6991 | // bigint on drivers that return one, and a blob on SQLite — hence the |
| 6992 | // ORM read rather than raw SQL (see `subject-registry.ts`). |
| 6993 | lastSeenAt: row.last_seen_at == null ? null : Number(row.last_seen_at), |
| 6994 | status: row.status ?? null, |
| 6995 | }); |
| 6996 | |
| 6997 | const rowToAdminConnection = (row: ConnectionRow): AdminConnection => { |
| 6998 | const owner = row.owner as Owner; |
| 6999 | return { |
| 7000 | owner, |
| 7001 | // Org rows carry the empty-string sentinel, not a principal. |
| 7002 | subject: owner === "org" ? null : row.subject, |
| 7003 | integration: IntegrationSlug.make(row.integration), |
| 7004 | name: ConnectionName.make(row.name), |
| 7005 | oauthScope: row.oauth_scope == null ? null : String(row.oauth_scope), |
| 7006 | lastHealth: presentedLastHealth(row), |
| 7007 | }; |
| 7008 | }; |
| 7009 | |
| 7010 | const listSubjects = ( |
| 7011 | options?: AdminListSubjectsOptions, |
| 7012 | ): Effect.Effect<readonly AdminSubject[], StorageFailure> => { |
| 7013 | // Always both, always integers — see `normalizeAdminPaging`. Passing |
| 7014 | // them through independently produced a bare OFFSET, which SQLite |
| 7015 | // rejects outright. |
| 7016 | const { limit, offset } = normalizeAdminPaging(options); |
| 7017 | const externalIds = options?.externalIds; |
| 7018 | // An empty id set is a query that cannot match; answer it without a |
| 7019 | // round trip rather than emitting `in ()`, which some drivers reject. |
| 7020 | if (externalIds !== undefined && externalIds.length === 0) return Effect.succeed([]); |
| 7021 | return platformCore |
| 7022 | .findMany("subject", { |
| 7023 | // The id filter is the ONLY predicate here; the tenant clause is |
| 7024 | // the policy's, added to every read the same way `getSubject` |
| 7025 | // relies on it. |
| 7026 | ...(externalIds === undefined |
| 7027 | ? {} |
| 7028 | : { where: (b: AnyCb) => b("external_id", "in", [...externalIds]) }), |
| 7029 | // Oldest first, ties broken on the unique key so the order is |
| 7030 | // total and paging can't repeat or skip a row. |
| 7031 | orderBy: [ |
| 7032 | ["created_at", "asc"], |
| 7033 | ["external_id", "asc"], |
| 7034 | ], |
| 7035 | limit, |
no test coverage detected