Files
silo-server/internal/notifications/availability_detector.go
T
QuickandClaude Fable 5 b091f0c6c1 feat(notifications): in-app inbox, realtime, webhooks, web push + shared SMTP core
Implements the notification system foundation and all v1 delivery channels
that need no external infrastructure (specs 00/01/04/05 in
docs/superpowers/plans/notifications/):

Foundation (spec 01):
- episode_availability seeding + per-library seed markers: "newly available"
  means newly released to this server, so back-catalog imports and first
  scans never flood (verified on dev: 1.13M episodes seeded silently)
- release_events -> profile_series_interest fanout worker with settling
  delay, per-series burst caps, FOR UPDATE SKIP LOCKED multi-node claims,
  and a guarded last-notified cursor
- interest index maintained via a userstore provider decorator so every
  favorites/watchlist/progress mutation path (REST, jellycompat, imports,
  playback) feeds it; progress writes only recompute on state transitions
- durable per-profile inbox + read state, forward-sync cursor API,
  websocket channel with short-lived single-use handshake tickets
- web UI: sidebar badge, inbox page, toasts, per-profile preferences
- startup/daily tasks: availability seeding, interest rebuild, retention

Outbound webhooks (spec 04):
- Discord embeds (text-only per the v1 privacy contract) and generic
  JSON signed Stripe-style with per-webhook secrets
- HTTPS-only + private-destination guard enforced at registration and at
  connect time (DNS-rebinding mitigation); URLs/secrets encrypted at rest
- durable per-target outbox enqueued in the fanout transaction, lease-based
  claims, 24h exponential retry, 3x-consecutive-4xx auto-disable with an
  in-app notice (loop-guarded)

Web push (spec 05):
- VAPID keypair self-provisioned at startup (single atomic JSON setting,
  private half encrypted at rest) — no third-party accounts needed
- payloads E2E-encrypted (RFC 8291); 404/410 treated as unsubscribe
- service worker + subscribe flow in Settings -> Notifications

Shared SMTP core (internal/mail):
- feature-agnostic mail.Sender over live email.* settings, STARTTLS or
  implicit TLS, encrypted password, admin Email settings page with
  synchronous test send; no consumer yet by design (digest is v1.5)

APNs/FCM (specs 02/03) are deferred to v2; the capability endpoint reports
them unavailable so clients render truthfully.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-06-11 14:55:46 -04:00

101 lines
3.5 KiB
Go

package notifications
import (
"context"
"log/slog"
"time"
)
const availabilityDetectTimeout = 2 * time.Minute
// AvailabilityDetector turns completed ingest runs into episode_availability
// facts and release events. It runs after matching/reconcile is complete so
// a release is tied to an actual resolved episode, and it never blocks or
// fails the ingest itself.
type AvailabilityDetector struct {
releases *ReleaseRepository
settings *Settings
logger *slog.Logger
// nudge wakes the fanout worker after new release events land; may be nil.
nudge func()
}
// NewAvailabilityDetector creates an AvailabilityDetector.
func NewAvailabilityDetector(releases *ReleaseRepository, settings *Settings) *AvailabilityDetector {
return &AvailabilityDetector{
releases: releases,
settings: settings,
logger: slog.Default().With("component", "notifications.availability"),
}
}
// SetFanoutNudge wires the fanout worker wake signal.
func (d *AvailabilityDetector) SetFanoutNudge(nudge func()) {
if d != nil {
d.nudge = nudge
}
}
// HandleIngestCompleted records newly available episodes for a completed
// ingest scope. fullLibrary distinguishes whole-library scans (set-based
// detection, and the scan that seeds a new library) from subtree/file scans
// (path-bounded detection).
//
// Seeding semantics: a library without a seed marker records availability
// silently — "newly available" means newly released to this server, not newly
// seen by the notifications feature. The marker is written when a full scan
// completes successfully, so the next scan onward emits release events.
func (d *AvailabilityDetector) HandleIngestCompleted(ctx context.Context, libraryID int, fullLibrary bool, scopePaths []string) {
if d == nil || d.releases == nil {
return
}
// The scan context is done once the scan finishes; detection runs on its
// own deadline so cancellation of the parent does not drop availability.
detectCtx, cancel := context.WithTimeout(context.WithoutCancel(ctx), availabilityDetectTimeout)
defer cancel()
seeded, err := d.releases.IsLibrarySeeded(detectCtx, libraryID)
if err != nil {
d.logger.Warn("seed state lookup failed", "library_id", libraryID, "error", err)
return
}
emitEvents := seeded && d.settings.ReleaseEventsEnabled(detectCtx)
var inserted, events int
if fullLibrary {
inserted, events, err = d.releases.RecordAvailabilityForLibrary(detectCtx, libraryID, emitEvents)
} else if seeded {
inserted, events, err = d.releases.RecordAvailabilityForPaths(detectCtx, libraryID, scopePaths, emitEvents)
} else {
// Subtree/file ingest on an unseeded library: record silently but do
// not seed-mark — only a successful full scan proves the back catalog
// has been captured.
inserted, events, err = d.releases.RecordAvailabilityForPaths(detectCtx, libraryID, scopePaths, false)
}
if err != nil {
d.logger.Warn("availability detection failed", "library_id", libraryID, "error", err)
return
}
if fullLibrary && !seeded {
if err := d.releases.MarkLibrarySeeded(detectCtx, libraryID); err != nil {
d.logger.Warn("seed marker write failed", "library_id", libraryID, "error", err)
} else {
d.logger.Info("library availability seeded",
"library_id", libraryID, "availability_rows", inserted)
}
}
if inserted > 0 || events > 0 {
d.logger.Info("availability recorded",
"library_id", libraryID,
"full_library", fullLibrary,
"availability_rows", inserted,
"release_events", events,
)
}
if events > 0 && d.nudge != nil {
d.nudge()
}
}