@objectstack/driver-sql@16.0.0
Minor Changes
-
efbcfe1: feat(observability): admin-only richer per-request timing detail via
X-OS-Debug-Timing: json(#2408)Completes the optional "richer JSON" diagnostic from #2408. In addition to the
basicServer-Timingheader, an admin/service caller can now request a
per-query breakdown — the slowest SQL statements and a query count — by sending
X-OS-Debug-Timing: json. The detail is returned in a separate
X-OS-Debug-Timing-Detailresponse header (compact JSON) and is admin-only,
even under global mode: an ordinary caller never sees SQL shapes.- observability:
PerfTiminggains opt-in per-event detail capture
(enableDetail/recordDetail/details) plus the ambient
recordServerTimingDetail. The disclosure gate gains aprivilegedlevel
(set byallowPerfDisclosure, read viaisPerfDisclosurePrivileged) so the
richer detail can be gated independently of the basic header. - driver-sql: when detail capture is on, the query listener additionally
records each query's parametrized statement (knex'sq.sql,?
placeholders) — never the bindings, so no literal row value ever enters the
collector. Zero overhead when detail is off. - plugin-hono-server:
X-OS-Debug-Timing: jsonenables detail capture; the
middleware emitsX-OS-Debug-Timing-Detail(slowest queries, capped and
sanitized to header-safe ASCII) only when the principal is a proven admin.
Basic and global behavior are unchanged;
jsonis purely additive. - observability:
Patch Changes
-
47d923c: fix(driver-sql): drop the vestigial
sqlite3peerDependency — the SQLite path usesbetter-sqlite3(#3277)package.jsonadvertisedpeerDependencies.sqlite3: "^5.0.0", but the driver never
loadssqlite3at runtime. Every first-party SQLite construction site builds a
client: 'better-sqlite3'Knex driver (resolveSqliteDriverin
@objectstack/service-datasource, the datasource driver factory, and the whole
driver test suite), and the README already tells consumers topnpm add better-sqlite3.
better-sqlite3is auto-provided as anoptionalDependency(with the native → wasm →
memory step-down of #2229 covering a failed native build), so the SQLite requirement is
already satisfied without the consumer installing anything.The stale
sqlite3peer only misled: a consumer resolving peer deps couldpnpm add sqlite3(never used) while believing they'd satisfied the SQLite requirement. Removing
it aligns the declared contract with the code and the docs. Thesqlite3string alias
still maps tobetter-sqlite3in the driver factory and dialect detection, so
driver: 'sqlite3'config keeps working — it just resolves tobetter-sqlite3like
everything else. -
ce468c8: feat(observability): decompose
Server-Timinginto auth / db / hooks / serialize spans (perf-tuning mode)The opt-in
Server-Timingheader now breaks a request's server time into the phases that actually explain it, so an operator can open DevTools → Network → Timing and see where the time went without standing up an external tracing backend:db— total SQL time with a query count. The SQL driver wires knex'squery/query-responseevents (keyed by__knexQueryUid) and folds each query into one aggregate member (db;dur=210;desc="6 queries") — the query count is the number most useful for spotting N sequential round-trips. Timing is attributed to the originating request viaAsyncLocalStorage, so it is correct under concurrency and never cross-attributes. SQL text is never emitted, only durations and a count.auth— identity / session resolution in the dispatcher, the prime suspect for unexplained data-API overhead.hooks— total business-hook execution time with a hook count, fed through the engine's existingHookMetricsRecorderseam (wired from the runtime, so@objectstack/objectql's leancoretier stays observability-free).serialize— response JSON encoding in the HTTP adapter.
Adds
countServerTiming(name, dur, unit)(andPerfTiming.count) to fold high-frequency phases into a single aggregate member instead of flooding the header. Every phase is a no-op when perf-tuning is off (serverTiming: true/OS_SERVER_TIMING=true), so there is zero measurable overhead on the normal path.Closes #2408.
-
86d30af: fix(tenancy): platform-global (
tenancy.enabled:false) objects are never driver-org-scoped (#3249)An org-context read of a platform-global object (e.g.
sys_license, ADR-0066)
could return 0 rows for an authenticated caller while an anonymous read saw the
data: the engine stampedexecCtx.tenantIdinto driver options unconditionally,
and the SQL driver's tenant-field cache could be re-corrupted to
organization_idby a partial re-registration (lifecycle archivesyncSchema,
schema-drift re-sync) whose schema omitted thetenancyblock.- New
isTenancyDisabled(schema)export from@objectstack/spec/data— the
single source of truth for the ADR-0066 platform-global posture, now shared by
the registry (tenant-column injection), the ObjectQL engine, and the SQL
driver. ObjectQL.buildDriverOptionsno longer stampstenantIdfor objects whose
registered schema declarestenancy.enabled: false(an explicitly-passed
optionstenantIdstill wins — deliberate caller intent).SqlDriver(andSqliteWasmDriver) now keep a sticky record of an explicit
tenancy.enabled:falsedeclaration: a later registration without atenancy
block preserves the opt-out instead of re-scoping via the implicit
organization_idheuristic; a registration that carries atenancy
declaration stays authoritative.
- New
-
Updated dependencies [f972574]
-
Updated dependencies [6289ec3]
-
Updated dependencies [22013aa]
-
Updated dependencies [3ad3dd5]
-
Updated dependencies [8efa395]
-
Updated dependencies [3a18b60]
-
Updated dependencies [a8aa34c]
-
Updated dependencies [e057f42]
-
Updated dependencies [a3823b2]
-
Updated dependencies [43a3efb]
-
Updated dependencies [524696a]
-
Updated dependencies [bfa3c3f]
-
Updated dependencies [5e3301d]
-
Updated dependencies [dd9f223]
-
Updated dependencies [46e876c]
-
Updated dependencies [5f05de2]
-
Updated dependencies [021ba4c]
-
Updated dependencies [158aa14]
-
Updated dependencies [62a2117]
-
Updated dependencies [83e8f7d]
-
Updated dependencies [d2723e2]
-
Updated dependencies [fefcd54]
-
Updated dependencies [efbcfe1]
-
Updated dependencies [2049b6a]
-
Updated dependencies [beaf2de]
-
Updated dependencies [369eb6e]
-
Updated dependencies [06ff734]
-
Updated dependencies [b659111]
-
Updated dependencies [5754a23]
-
Updated dependencies [6c270a6]
-
Updated dependencies [290e2f0]
-
Updated dependencies [668dd17]
-
Updated dependencies [8abf133]
-
Updated dependencies [e0859b1]
-
Updated dependencies [92f5f19]
-
Updated dependencies [32899e6]
-
Updated dependencies [ce468c8]
-
Updated dependencies [04ecd4e]
-
Updated dependencies [4d5a892]
-
Updated dependencies [16cebeb]
-
Updated dependencies [86d30af]
-
Updated dependencies [8923843]
-
Updated dependencies [a2795f6]
-
Updated dependencies [f16b492]
-
Updated dependencies [4b6fde8]
-
Updated dependencies [2018df9]
-
Updated dependencies [fc5a3a2]
-
Updated dependencies [8ff9210]
- @objectstack/spec@16.0.0
- @objectstack/core@16.0.0
- @objectstack/types@16.0.0
- @objectstack/observability@16.0.0