mirror of
https://github.com/maziggy/bambuddy.git
synced 2026-09-30 03:01:21 +02:00
Two or three concurrent UI logins exhausted the PostgreSQL pool on the reporter's 93-printer farm: QueuePool limit of size 10 overflow 20 reached, with all 30 sessions idle in transaction on the auth_enabled SELECT. Three regressions had landed on dev after an earlier configurable-pool change was reverted and never re-applied (only the route-by-route session fixes were). - Pool sizing is env-configurable again (DB_POOL_SIZE / DB_MAX_OVERFLOW / DB_POOL_TIMEOUT / DB_POOL_RECYCLE); the PostgreSQL default returns to 20 + 80 with pool_pre_ping and pool_recycle=1800, and GET /api/v1/system/db-pool reports resolved config + live gauges without checking out a connection. SQLite unchanged (20 + 200). - is_auth_enabled caches for 30s again. Only enabled=True is ever cached, so a stale read can only fail closed (require auth), never open; set_auth_enabled invalidates immediately. An autouse test fixture resets the module cache between tests to keep ordering deterministic. - Every authenticated request checked out two pooled connections: the permission dependency held one and the revoked-jti check opened another. is_jti_revoked now reuses the caller's session; the token dependencies and the auth-middleware gateway were restructured to open one session and pass it in, so each request makes a single checkout.