Skip to content

fix(auth): map unique email violation to Conflict on register (#55) - #82

Open
Simultech369 wants to merge 1 commit into
StellarSend:mainfrom
Simultech369:fix/issue-55-register-unique-violation
Open

Simultech369 wants to merge 1 commit into
StellarSend:mainfrom
Simultech369:fix/issue-55-register-unique-violation

Conversation

@Simultech369

Copy link
Copy Markdown

Summary

Resolves #55 by catching PostgreSQL unique constraint violations on INSERT INTO users during registration and mapping them to HTTP 409 Conflict (AppError::Conflict("Email".into())), matching the semantic behavior of the preliminary existence check and eliminating spurious 500 INTERNAL_SERVER_ERROR responses under concurrent registration races.

Changes

  1. Shared Unique Violation Detection (src/error.rs):
    • Promoted is_unique_violation(error: &sqlx::Error) -> bool from src/services/batch.rs to src/error.rs.
    • Reused across both batch.rs and routes/auth.rs.
  2. Registration Handler (src/routes/auth.rs):
    • Retained preliminary SELECT EXISTS check as an optimization to avoid paying unnecessary bcrypt hashing computation costs for obvious duplicates.
    • Wrapped INSERT INTO users query execution with .map_err(...):
      • If is_unique_violation(&e) is true, maps to AppError::Conflict("Email".into()) (HTTP 409).
      • Otherwise forwards original AppError::Database(e) (HTTP 500).
  3. Unit Tests (src/error.rs):
    • test_conflict_status_and_code: Asserts AppError::Conflict maps to StatusCode::CONFLICT and machine-readable code "CONFLICT".
    • test_is_unique_violation_non_db_error: Asserts non-unique errors (e.g. RowNotFound) evaluate to false.
    • All 40 unit tests pass hermetically in cargo test.

Closes #55


Stellar Payout (GrantFox): GCK7WCZCOFNYXTH74KADMAIREIJKHIAX4ISJSGXZ4IF2MIRGAFLT4BTH
Base USDC: 0xEa3A353Fb3fc88DB8F0FA1E6Ea541FEdc9F5F0E7

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

register has a check-then-insert email race whose loser gets a 500 instead of 409, unlike batch.rs's unique-violation handling

1 participant