Files
memby/server/internal/store/settings.go
T
ponzischeme89andClaude Opus 5 62f6345a40 Server-controlled app updates, optional or forced
The gateway decides whether a TV may keep running its current build.
Clients send X-Memby-Version on every request and ask GET /v1/update on
each launch; the verdict is none, optional or mandatory.

- internal/appupdate holds the decision as pure, tested logic: below
  minimumVersion is mandatory, below latestVersion is optional.
- Admin page gains an App updates section — latest version, APK URL,
  notes, and a "Require this update" toggle that sets the forced floor.
- Client shows a dismissable prompt for optional, and a full-screen
  panel that swallows Back for mandatory. Instructions say what the
  system installer will ask before it asks.

Two safeguards: a client that cannot report its version is never forced,
and the client ignores a verdict with no download URL, so a
half-configured policy cannot produce an unblockable screen with a dead
button. An unreachable gateway shows nothing.

The verdict is deliberately not part of /v1/home: that payload is cached
per user, while this answer depends on the requesting client's version.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-27 08:34:04 +12:00

119 lines
3.7 KiB
Go

package store
import (
"context"
"encoding/json"
"errors"
"fmt"
"time"
"github.com/jackc/pgx/v5"
"github.com/ponzischeme89/memby/server/internal/appupdate"
)
// MaintenanceKey is the app_settings row backing maintenance mode.
const MaintenanceKey = "maintenance"
// Maintenance is the operator switch that takes Memby down independently of Emby.
//
// Deliberately durable: a restart must not quietly bring the app back up while someone
// is still working on it.
type Maintenance struct {
Enabled bool `json:"enabled"`
Message string `json:"message"`
UpdatedAt time.Time `json:"updatedAt"`
}
// DefaultMaintenanceMessage is shown on the TV when the operator did not write one.
const DefaultMaintenanceMessage = "Memby is down for maintenance. Try again shortly."
func (s *Store) Maintenance(ctx context.Context) (Maintenance, error) {
var raw []byte
err := s.pool.QueryRow(ctx, `SELECT value FROM app_settings WHERE key = $1`, MaintenanceKey).Scan(&raw)
if errors.Is(err, pgx.ErrNoRows) {
return Maintenance{}, nil
}
if err != nil {
return Maintenance{}, fmt.Errorf("store: read maintenance: %w", err)
}
var state Maintenance
if err := json.Unmarshal(raw, &state); err != nil {
return Maintenance{}, fmt.Errorf("store: decode maintenance: %w", err)
}
return state, nil
}
func (s *Store) SetMaintenance(ctx context.Context, state Maintenance) error {
state.UpdatedAt = time.Now().UTC()
raw, err := json.Marshal(state)
if err != nil {
return err
}
_, err = s.pool.Exec(ctx, `
INSERT INTO app_settings (key, value, updated_at)
VALUES ($1, $2::jsonb, now())
ON CONFLICT (key) DO UPDATE SET value = EXCLUDED.value, updated_at = now()`,
MaintenanceKey, string(raw))
if err != nil {
return fmt.Errorf("store: write maintenance: %w", err)
}
return nil
}
// UpdatePolicyKey is the app_settings row backing the client update policy.
const UpdatePolicyKey = "update_policy"
func (s *Store) UpdatePolicy(ctx context.Context) (appupdate.Policy, error) {
var raw []byte
err := s.pool.QueryRow(ctx, `SELECT value FROM app_settings WHERE key = $1`, UpdatePolicyKey).Scan(&raw)
if errors.Is(err, pgx.ErrNoRows) {
return appupdate.Policy{}, nil
}
if err != nil {
return appupdate.Policy{}, fmt.Errorf("store: read update policy: %w", err)
}
var policy appupdate.Policy
if err := json.Unmarshal(raw, &policy); err != nil {
return appupdate.Policy{}, fmt.Errorf("store: decode update policy: %w", err)
}
return policy, nil
}
func (s *Store) SetUpdatePolicy(ctx context.Context, policy appupdate.Policy) error {
policy.UpdatedAt = time.Now().UTC()
raw, err := json.Marshal(policy)
if err != nil {
return err
}
_, err = s.pool.Exec(ctx, `
INSERT INTO app_settings (key, value, updated_at)
VALUES ($1, $2::jsonb, now())
ON CONFLICT (key) DO UPDATE SET value = EXCLUDED.value, updated_at = now()`,
UpdatePolicyKey, string(raw))
if err != nil {
return fmt.Errorf("store: write update policy: %w", err)
}
return nil
}
// NewestSession is the fallback credential for the library import: whichever TV signed
// in most recently. It means a fresh deployment can import without configuring a
// service account, at the cost of the import stopping if that user is ever removed.
func (s *Store) NewestSession(ctx context.Context) (Session, error) {
var sess Session
err := s.pool.QueryRow(ctx, `
SELECT token_hash, emby_user_id, emby_token, username, server_id, device_id, last_seen_at
FROM sessions ORDER BY last_seen_at DESC LIMIT 1`).
Scan(&sess.TokenHash, &sess.EmbyUserID, &sess.EmbyToken, &sess.Username,
&sess.ServerID, &sess.DeviceID, &sess.LastSeenAt)
if errors.Is(err, pgx.ErrNoRows) {
return Session{}, ErrNotFound
}
if err != nil {
return Session{}, fmt.Errorf("store: newest session: %w", err)
}
return sess, nil
}