upaas/internal/models
clawbot 763e722607 fix: prevent setup endpoint race condition (closes #26)
Add mutex and INSERT ON CONFLICT to CreateUser to prevent TOCTOU race
where concurrent requests could create multiple admin users.

Changes:
- Add sync.Mutex to auth.Service to serialize CreateUser calls
- Add models.CreateUserAtomic using INSERT ... ON CONFLICT(username) DO NOTHING
- Check RowsAffected to detect conflicts at the DB level (defense-in-depth)
- Add concurrent race condition test (10 goroutines, only 1 succeeds)

The existing UNIQUE constraint on users.username was already in place.
This fix adds the application-level protection (items 1 & 2 from #26).
2026-02-15 21:35:16 -08:00
..
app.go fix: use hashed webhook secrets for constant-time comparison 2026-02-15 14:06:53 -08:00
deployment.go Add commit URL to Slack notifications with link and backtick formatting 2025-12-31 16:29:22 -08:00
env_var.go Initial commit with server startup infrastructure 2025-12-29 15:46:03 +07:00
label.go Initial commit with server startup infrastructure 2025-12-29 15:46:03 +07:00
models_test.go fix: use hashed webhook secrets for constant-time comparison 2026-02-15 14:06:53 -08:00
port.go Add TCP/UDP port mapping support 2025-12-30 12:11:57 +07:00
user.go fix: prevent setup endpoint race condition (closes #26) 2026-02-15 21:35:16 -08:00
volume.go Initial commit with server startup infrastructure 2025-12-29 15:46:03 +07:00
webhook_event.go Add commit URL to Slack notifications with link and backtick formatting 2025-12-31 16:29:22 -08:00