do_insert_validation.c (3131B)
1 /* 2 This file is part of Challenger 3 Copyright (C) 2023 Taler Systems SA 4 5 Challenger is free software; you can redistribute it and/or modify it under the 6 terms of the GNU General Public License as published by the Free Software 7 Foundation; either version 3, or (at your option) any later version. 8 9 Challenger is distributed in the hope that it will be useful, but WITHOUT ANY 10 WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR 11 A PARTICULAR PURPOSE. See the GNU General Public License for more details. 12 13 You should have received a copy of the GNU General Public License along with 14 Challenger; see the file COPYING. If not, see <http://www.gnu.org/licenses/> 15 */ 16 /** 17 * @file src/challengerdb/do_insert_validation.c 18 * @brief Implementation of the do_insert_validation function for Postgres 19 * @author Christian Grothoff 20 */ 21 #include "platform.h" 22 #include <taler/taler_error_codes.h> 23 #include <taler/taler_dbevents.h> 24 #include <taler/taler_pq_lib.h> 25 #include "do_insert_validation.h" 26 #include "pg_helper.h" 27 28 29 enum GNUNET_DB_QueryStatus 30 CHALLENGERDB_do_insert_validation (struct CHALLENGERDB_PostgresContext *ctx, 31 uint64_t client_id, 32 const char *client_secret, 33 const struct 34 CHALLENGER_ValidationNonceP *nonce, 35 struct GNUNET_TIME_Absolute expiration_time, 36 const json_t *initial_address) 37 { 38 struct GNUNET_PQ_QueryParam params[] = { 39 GNUNET_PQ_query_param_uint64 (&client_id), 40 GNUNET_PQ_query_param_string (client_secret), 41 GNUNET_PQ_query_param_auto_from_type (nonce), 42 GNUNET_PQ_query_param_absolute_time (&expiration_time), 43 NULL == initial_address 44 ? GNUNET_PQ_query_param_null () 45 : TALER_PQ_query_param_json (initial_address), 46 GNUNET_PQ_query_param_end 47 }; 48 49 /* Authenticating the client, charging it for the validation and creating 50 the validation row must happen together: the counter may only move if 51 the validation is really created. Doing it in one statement also saves 52 the round trips of an explicit transaction. A client that does not 53 exist (or presents the wrong secret) leaves the CTE empty, so nothing is 54 inserted and the caller sees NO_RESULTS. */ 55 PREPARE (ctx, 56 "do_insert_validation", 57 "WITH charged AS (" 58 " UPDATE clients" 59 " SET validation_counter=validation_counter+1" 60 " WHERE client_serial_id=$1" 61 " AND client_secret=$2" 62 " RETURNING client_serial_id, uri" 63 ") INSERT INTO validations" 64 " (client_serial_id" 65 " ,nonce" 66 " ,expiration_time" 67 " ,client_redirect_uri" 68 " ,address" 69 ") SELECT client_serial_id, $3, $4, uri, $5" 70 " FROM charged;"); 71 return GNUNET_PQ_eval_prepared_non_select (ctx->conn, 72 "do_insert_validation", 73 params); 74 }