Files
OmniRoute/src/lib/db/gamification.ts
Diego Rodrigues de Sa e Souza 9350a5d6c6 Release v3.8.22 (#3623)
* chore(release): open v3.8.22 development cycle

* refactor(dashboard): extract ProviderDetailPageClient — #3501 Phase 0 (#3633)

#3501 Phase 0: extract ProviderDetailPageClient + smoke test.

Co-authored-by: oyi77 <oyi77@users.noreply.github.com>

* refactor(dashboard): extract auth-import modals — #3501 Phase 1a (#3634)

#3501 Phase 1a: extract 3 auth-import modal clusters.

Co-authored-by: oyi77 <oyi77@users.noreply.github.com>

* fix(db): reclassify localDb unexported modules as intentionally-internal (#3499) (#3635)

Closes #3499 — reclassify localDb unexported modules as intentionally-internal (audit + honest gate framing).

* refactor(db): move call_logs aggregations into callLogStats db module (#3500) (#3636)

#3500 slice 1: call_logs aggregations → src/lib/db/callLogStats.ts (Rule #5). Byte-identical queries; TDD 6/6.

* refactor(dashboard): extract EditCompatibleNodeModal — #3501 Phase 1b (#3638)

#3501 Phase 1b: extract EditCompatibleNodeModal (cycle-safe via leaf constants module).

Co-authored-by: oyi77 <oyi77@users.noreply.github.com>

* refactor(db): move community_servers SQL into gamification db module (#3500 slice 3) (#3639)

#3500 slice 3: community_servers SQL → gamification db module.

* refactor(db): move usage_history SQL into usageAnalytics module (#3500 slice 2) (#3644)

#3500 slice 2: usage_history/daily_usage_summary SQL → usageAnalytics db module.

* refactor(db): move skills UPDATE + db-backups SQL into db modules (#3500 slice 5) (#3647)

#3500 slice 5: skills UPDATE (allowlist) + db-backups SQL → db modules.

* refactor(db): move usage_logs/semantic_cache/proxy_logs SQL into db modules (#3500 slice 4) (#3648)

#3500 slice 4: usage_logs/semantic_cache/proxy_logs SQL → db modules. All internal routes done (2 external by-design remain).

* chore(db-gate): reclassify external-DB reads, fully close #3500 (#3649)

Closes #3500: reclassify external-DB reads; all internal raw-SQL migrated to db/ modules.

* refactor(dashboard): extract pure helpers to providerPageHelpers — #3501 Phase 2 (#3653)

#3501 Phase 2: extract pure helpers to providerPageHelpers (leaf, cycle-safe).

Co-authored-by: oyi77 <oyi77@users.noreply.github.com>

* refactor(dashboard): extract remaining shared helpers to providerPageHelpers — #3501 Phase 2b (#3658)

#3501 Phase 2b: extract remaining shared helpers to providerPageHelpers (leaf, cycle-safe). Heavy modals unblocked.

Co-authored-by: oyi77 <oyi77@users.noreply.github.com>

* fix(reasoning): replay reasoning_content on plain DeepSeek turns (#1682) (#3632)

Integrated into release/v3.8.22

* fix(kiro): route enterprise IAM Identity Center accounts to their regional endpoint (#3631)

Integrated into release/v3.8.22

* refactor: small code cleanup (#3523)

Integrated into release/v3.8.22

* fix(combo): skip same-provider targets on 408/500/502/503/504/524 errors (#3637)

Integrated into release/v3.8.22 — circuit-breaker guard added in review (#1731v2)

* feat(providers): add MiMoCode free-tier provider with bootstrap JWT auth (#3659)

Integrated into release/v3.8.22 — page.tsx conflict resolved + NoAuthAccountCard re-applied to ProviderDetailPageClient in review. MiMoCode endpoint validated live.

* Log Responses WebSocket calls in history (#3616)

Integrated into release/v3.8.22 — Codex Responses WebSocket call history logging.

* Add Claude Code routing preference for unprefixed Claude models (#3540)

Integrated into release/v3.8.22 — page.tsx conflict resolved (re-applied toggle to ProviderDetailPageClient) + disable-test updated for catalog drift in review.

* docs(changelog): credit #3632/#3631/#3637/#3659/#3540/#3616/#3523 (v3.8.22 targeted review round)

* fix(mimocode): add required authHeader:"none" to registry entry (#3659 follow-up)

The mimocode RegistryEntry omitted the required authHeader field, which broke
typecheck:core (TS2741). Match the no-auth convention (authType:"none" + authHeader:"none")
used by veoaifree-web and other free providers. Follow-up to #3659 (@pizzav-xyz).

* fix(responses): detect stream readiness for tool-call-only and object-less chunks (#3612) (#3661)

Closes #3612

* fix(mitm): remove duplicated 'Command failed:' error prefix (#3641) (#3662)

Closes #3641

* fix(cli): honor HERMES_HOME for Hermes Agent config path (#3628) (#3663)

Closes #3628

* fix(api): fetch live OpenCode model catalog for no-auth model picker (#3611) (#3664)

Closes #3611

* fix(api): flag provider topology error state by current status, not stale history (#3619) (#3666)

Closes #3619

* fix(electron): launch peer-stamping server-ws.mjs entrypoint to avoid 403 LOCAL_ONLY (#3386) (#3665)

Closes #3386

* fix(dashboard): restore home topology live in-flight pulse (#3507) (#3667)

Closes #3507

* fix(oauth): name Kiro/AWS auto-imported accounts and dedupe by profileArn (#3615) (#3671)

Closes #3615

* fix(resilience): clear stale transient connection cooldowns on startup (#3625) (#3672)

Closes #3625

* fix(i18n): use logical CSS direction utilities for sidebar and key overlays (RTL #3541) (#3670)

Closes #3541

* fix(dashboard): honor auto-hide and switch to visible filter on passthrough Test-all (#3610) (#3669)

Closes #3610

* refactor(dashboard): extract AddApiKeyModal + EditConnectionModal — #3501 Phase 1c (#3674)

#3501 Phase 1c: extract AddApiKeyModal, EditConnectionModal, WebSessionCredentialGuide into components/; god-component 10,166->8,092 LOC. Reconciles the v3.8.22 file-size drift for this file.

Co-authored-by: oyi77 <oyi77@users.noreply.github.com>

* docs(changelog): reconcile v3.8.22 — credit #3621/#3622 + MiMoCode follow-up roll-up

* refactor(dashboard): extract ConnectionRow + ModelCompatPopover + SiliconFlowEndpointModal — #3501 Phase 1d (#3676)

#3501 Phase 1d: god-component 8,092->6,838 LOC.

Co-authored-by: oyi77 <oyi77@users.noreply.github.com>

* feat(obsidian): add WebDAV config route + encrypt creds at rest (#3485 part 1) (#3677)

Part 1 of #3485. Adds /api/settings/obsidian/webdav (GET/POST/DELETE) wiring the ready obsidianSync lib, encrypts webdav password + obsidian token at rest, removes the duplicate UI block, drops the KNOWN_MISSING entry. WebDAV file server is part 2.

* feat(obsidian): add /api/v1/webdav file server for Obsidian vault sync (#3485 part 2) (#3678)

Part 2 of #3485. WebDAV server (PROPFIND/GET/PUT/DELETE/MKCOL/MOVE/OPTIONS) handled in the custom server layer (standalone-server-ws.mjs) since the App Router cannot export WebDAV methods. Basic-Auth (constant-time), path-traversal hardened, password decrypt ported from encryption.ts (parity-tested), DATA_DIR resolution parity-tested against dataPaths.ts. End-to-end Obsidian-over-Tailscale validation is a live VPS step (Rule #18).

* fix(combo): stop premature context compaction — real auto-combo windows + per-target compression limit (#3680)

Integrated into release/v3.8.22

* feat(dashboard): deactivate/activate accounts from the quota overview (#3675)

Integrated into release/v3.8.22

* fix(dashboard): close review gaps in bulk provider connection actions (#3271 follow-up) (#3673)

Integrated into release/v3.8.22 — page.tsx conflict (god-component split #3501) resolved by re-applying the bulk-action deltas to ProviderDetailPageClient.tsx

* refactor(dashboard): extract useModelCompatState hook + model sections — #3501 Phase 1e (#3683)

#3501 Phase 1e: extract useModelCompatState hook (unblocks the model sections) + ModelRow/PassthroughModelsSection/PassthroughModelRow/CustomModelsSection/CompatibleModelsSection. god-component 6,838->4,921 LOC.

Co-authored-by: oyi77 <oyi77@users.noreply.github.com>

* refactor(dashboard): extract useProviderConnections/Settings/Models hooks — #3501 Phase 1f (#3684)

#3501 Phase 1f: god-component 4,948->4,062 LOC. Connection state+handlers, settings, and model metadata moved into hooks/.

Co-authored-by: oyi77 <oyi77@users.noreply.github.com>

* chore(release): v3.8.22 CHANGELOG + env-doc sync

- Set release date in CHANGELOG [3.8.22] to 2026-06-11
- Add HERMES_HOME to .env.example (from #3628/#3663)
- Add HERMES_HOME + OMNIROUTE_PREFER_CLAUDE_CODE_FOR_UNPREFIXED_CLAUDE_MODELS to ENVIRONMENT.md (#3628/#3540)

* docs(changelog): credit #3673 + #3675 — leninejunior bulk-actions + quota-toggle

---------

Co-authored-by: oyi77 <oyi77@users.noreply.github.com>
Co-authored-by: Abhishek Divekar <adivekar@utexas.edu>
Co-authored-by: NOXX - Commiter <artur1992123@mail.ru>
Co-authored-by: Nicolas Lorin <androw95220@gmail.com>
Co-authored-by: Hernan Javier Ardila Sanchez <hjasgr@gmail.com>
Co-authored-by: PizzaV <103120356+pizzav-xyz@users.noreply.github.com>
Co-authored-by: kkkayye <98376609+kkkayye@users.noreply.github.com>
Co-authored-by: Witroch4 <witalo_rocha@hotmail.com>
Co-authored-by: Lenine Júnior <lenine@engrene.com.br>
2026-06-11 18:52:29 -03:00

614 lines
18 KiB
TypeScript

/**
* gamification.ts — DB domain module for the Gamification & Leaderboard system.
*
* Manages leaderboards, XP/levels, badges, token ledger, invite tokens,
* and community server connections.
*/
import { getDbInstance } from "./core";
import { calculateLevel } from "../gamification/xp";
// ──────────────── Types ────────────────
export interface LeaderboardRow {
apiKeyId: string;
scope: string;
score: number;
updatedAt: string;
}
export interface UserLevelRow {
apiKeyId: string;
totalXp: number;
currentLevel: number;
updatedAt: string;
}
export interface BadgeDefinition {
id: string;
name: string;
description: string | null;
icon: string | null;
category: string | null;
rarity: string;
criteria: string | null;
hidden: number;
createdAt: string;
}
export interface UserBadge {
apiKeyId: string;
badgeId: string;
unlockedAt: string;
badgeName?: string;
badgeDescription?: string | null;
badgeIcon?: string | null;
badgeCategory?: string | null;
badgeRarity?: string;
}
export interface XpAuditLogEntry {
id: number;
apiKeyId: string;
action: string;
xpEarned: number;
metadata: string | null;
createdAt: string;
}
export interface TokenLedgerEntry {
id: number;
fromApiKeyId: string;
toApiKeyId: string;
amount: number;
reason: string | null;
idempotencyKey: string | null;
createdAt: string;
}
export interface InviteToken {
id: string;
code: string;
tokenHash: string;
createdBy: string;
usedBy: string | null;
serverUrl: string | null;
maxUses: number;
useCount: number;
expiresAt: string | null;
revokedAt: string | null;
createdAt: string;
}
export interface CommunityServer {
id: string;
name: string;
url: string;
apiKeyHash: string;
connectedAt: string;
lastSyncAt: string | null;
status: string;
errorMessage: string | null;
}
// ──────────────── Helper ────────────────
interface StatementLike<TRow = unknown> {
all: (...params: unknown[]) => TRow[];
get: (...params: unknown[]) => TRow | undefined;
run: (...params: unknown[]) => { changes: number };
}
interface DbLike {
prepare: <TRow = unknown>(sql: string) => StatementLike<TRow>;
}
function db(): DbLike {
return getDbInstance() as unknown as DbLike;
}
// ──────────────── Leaderboard ────────────────
export function updateScore(apiKeyId: string, scope: string, points: number): void {
db()
.prepare(
`INSERT INTO leaderboard (api_key_id, scope, score, updated_at)
VALUES (?, ?, ?, datetime('now'))
ON CONFLICT(api_key_id, scope)
DO UPDATE SET score = score + excluded.score, updated_at = datetime('now')`
)
.run(apiKeyId, scope, points);
}
export function getRank(apiKeyId: string, scope: string): number {
const row = db()
.prepare(`SELECT score FROM leaderboard WHERE api_key_id = ? AND scope = ?`)
.get(apiKeyId, scope) as { score: number } | undefined;
if (!row) return 0;
const rankRow = db()
.prepare(`SELECT COUNT(*) + 1 AS rank FROM leaderboard WHERE scope = ? AND score > ?`)
.get(scope, row.score) as { rank: number };
return rankRow.rank;
}
export function getTopN(scope: string, limit: number, offset: number = 0): LeaderboardRow[] {
const rows = db()
.prepare(
`SELECT api_key_id, scope, score, updated_at FROM leaderboard
WHERE scope = ? ORDER BY score DESC LIMIT ? OFFSET ?`
)
.all(scope, limit, offset) as Array<{
api_key_id: string;
scope: string;
score: number;
updated_at: string;
}>;
return rows.map((r) => ({
apiKeyId: r.api_key_id,
scope: r.scope,
score: r.score,
updatedAt: r.updated_at,
}));
}
// ──────────────── XP & Levels ────────────────
export function addXp(apiKeyId: string, action: string, amount: number, metadata?: string): void {
db()
.prepare(
`INSERT INTO xp_audit_log (api_key_id, action, xp_earned, metadata)
VALUES (?, ?, ?, ?)`
)
.run(apiKeyId, action, amount, metadata ?? null);
db()
.prepare(
`INSERT INTO user_levels (api_key_id, total_xp, current_level, updated_at)
VALUES (?, ?, ?, datetime('now'))
ON CONFLICT(api_key_id)
DO UPDATE SET total_xp = total_xp + excluded.total_xp, updated_at = datetime('now')`
)
.run(apiKeyId, amount, calculateLevel(amount));
}
export function getXp(apiKeyId: string): UserLevelRow | null {
const row = db()
.prepare(
`SELECT api_key_id, total_xp, current_level, updated_at FROM user_levels WHERE api_key_id = ?`
)
.get(apiKeyId) as
| {
api_key_id: string;
total_xp: number;
current_level: number;
updated_at: string;
}
| undefined;
if (!row) return null;
return {
apiKeyId: row.api_key_id,
totalXp: row.total_xp,
currentLevel: row.current_level,
updatedAt: row.updated_at,
};
}
export function updateLevel(apiKeyId: string, level: number): void {
db()
.prepare(
`INSERT INTO user_levels (api_key_id, total_xp, current_level, updated_at)
VALUES (?, 0, ?, datetime('now'))
ON CONFLICT(api_key_id)
DO UPDATE SET current_level = ?, updated_at = datetime('now')`
)
.run(apiKeyId, level, level);
}
// ──────────────── Badges ────────────────
export function unlockBadge(apiKeyId: string, badgeId: string): void {
db()
.prepare(`INSERT OR IGNORE INTO user_badges (api_key_id, badge_id) VALUES (?, ?)`)
.run(apiKeyId, badgeId);
}
/**
* Whether a specific badge has already been awarded to an API key.
*
* Reads `user_badges` directly (no JOIN), so the "already unlocked?" check is correct even
* when `badge_definitions` is unpopulated. `getBadges()` INNER-JOINs `badge_definitions`, so
* it returns nothing until the definitions are seeded — using it as a dedup guard caused
* badge-unlock events to re-fire on every request (#3472).
*/
export function hasBadge(apiKeyId: string, badgeId: string): boolean {
const row = db()
.prepare(`SELECT 1 FROM user_badges WHERE api_key_id = ? AND badge_id = ? LIMIT 1`)
.get(apiKeyId, badgeId);
return !!row;
}
export function getBadges(apiKeyId: string): UserBadge[] {
const rows = db()
.prepare(
`SELECT ub.api_key_id, ub.badge_id, ub.unlocked_at,
bd.name, bd.description, bd.icon, bd.category, bd.rarity
FROM user_badges ub
JOIN badge_definitions bd ON bd.id = ub.badge_id
WHERE ub.api_key_id = ?`
)
.all(apiKeyId) as Array<{
api_key_id: string;
badge_id: string;
unlocked_at: string;
name: string;
description: string | null;
icon: string | null;
category: string | null;
rarity: string;
}>;
return rows.map((r) => ({
apiKeyId: r.api_key_id,
badgeId: r.badge_id,
unlockedAt: r.unlocked_at,
badgeName: r.name,
badgeDescription: r.description,
badgeIcon: r.icon,
badgeCategory: r.category,
badgeRarity: r.rarity,
}));
}
export function getBadgeDefinitions(category?: string): BadgeDefinition[] {
const sql = category
? `SELECT * FROM badge_definitions WHERE category = ?`
: `SELECT * FROM badge_definitions`;
const rows = (category ? db().prepare(sql).all(category) : db().prepare(sql).all()) as Array<{
id: string;
name: string;
description: string | null;
icon: string | null;
category: string | null;
rarity: string;
criteria: string | null;
hidden: number;
created_at: string;
}>;
return rows.map((r) => ({
id: r.id,
name: r.name,
description: r.description,
icon: r.icon,
category: r.category,
rarity: r.rarity,
criteria: r.criteria,
hidden: r.hidden,
createdAt: r.created_at,
}));
}
/**
* Aggregate XP across every API key (the operator-wide profile view used by the
* dashboard profile page, which is not scoped to a single key). Sums total XP and
* takes the highest reached level. (#3484)
*/
export function getAggregateXp(): UserLevelRow {
const row = db()
.prepare(
`SELECT COALESCE(SUM(total_xp), 0) AS total_xp,
COALESCE(MAX(current_level), 1) AS current_level,
MAX(updated_at) AS updated_at
FROM user_levels`
)
.get() as { total_xp: number; current_level: number; updated_at: string | null };
return {
apiKeyId: "*",
totalXp: row?.total_xp ?? 0,
currentLevel: row?.current_level ?? 1,
updatedAt: row?.updated_at ?? "",
};
}
/**
* Distinct badges earned by any API key (operator-wide earned set for the profile
* page). Deduplicated by badge id, keeping the earliest unlock. (#3484)
*/
export function getAllEarnedBadges(): UserBadge[] {
const rows = db()
.prepare(
`SELECT ub.badge_id, MIN(ub.unlocked_at) AS unlocked_at,
bd.name, bd.description, bd.icon, bd.category, bd.rarity
FROM user_badges ub
JOIN badge_definitions bd ON bd.id = ub.badge_id
GROUP BY ub.badge_id`
)
.all() as Array<{
badge_id: string;
unlocked_at: string;
name: string;
description: string | null;
icon: string | null;
category: string | null;
rarity: string;
}>;
return rows.map((r) => ({
apiKeyId: "*",
badgeId: r.badge_id,
unlockedAt: r.unlocked_at,
badgeName: r.name,
badgeDescription: r.description,
badgeIcon: r.icon,
badgeCategory: r.category,
badgeRarity: r.rarity,
}));
}
// ──────────────── Token Ledger ────────────────
export function transferTokens(
fromId: string,
toId: string,
amount: number,
reason: string,
idempotencyKey: string
): { success: boolean; error?: string } {
// Atomic transaction: balance check + insert
const instance = getDbInstance();
const txn = instance.transaction(() => {
// Check for duplicate
const existing = instance
.prepare(`SELECT id FROM token_ledger WHERE idempotency_key = ?`)
.get(idempotencyKey) as { id: number } | undefined;
if (existing) return { success: true };
// Balance check (inside transaction to prevent race)
const balance = getBalance(fromId);
if (balance < amount) {
return { success: false, error: "insufficient_balance" };
}
instance
.prepare(
`INSERT INTO token_ledger (from_api_key_id, to_api_key_id, amount, reason, idempotency_key)
VALUES (?, ?, ?, ?, ?)`
)
.run(fromId, toId, amount, reason, idempotencyKey);
return { success: true };
});
return txn();
}
export function getBalance(apiKeyId: string): number {
const received = db()
.prepare(`SELECT COALESCE(SUM(amount), 0) AS total FROM token_ledger WHERE to_api_key_id = ?`)
.get(apiKeyId) as { total: number };
const sent = db()
.prepare(`SELECT COALESCE(SUM(amount), 0) AS total FROM token_ledger WHERE from_api_key_id = ?`)
.get(apiKeyId) as { total: number };
return received.total - sent.total;
}
export function getHistory(apiKeyId: string, limit: number): TokenLedgerEntry[] {
const rows = db()
.prepare(
`SELECT * FROM token_ledger
WHERE from_api_key_id = ? OR to_api_key_id = ?
ORDER BY created_at DESC LIMIT ?`
)
.all(apiKeyId, apiKeyId, limit) as Array<{
id: number;
from_api_key_id: string;
to_api_key_id: string;
amount: number;
reason: string | null;
idempotency_key: string | null;
created_at: string;
}>;
return rows.map((r) => ({
id: r.id,
fromApiKeyId: r.from_api_key_id,
toApiKeyId: r.to_api_key_id,
amount: r.amount,
reason: r.reason,
idempotencyKey: r.idempotency_key,
createdAt: r.created_at,
}));
}
// ──────────────── Invite Tokens ────────────────
export function createInviteToken(
id: string,
code: string,
tokenHash: string,
createdBy: string,
serverUrl?: string,
maxUses?: number
): void {
db()
.prepare(
`INSERT INTO invite_tokens (id, code, token_hash, created_by, server_url, max_uses)
VALUES (?, ?, ?, ?, ?, ?)`
)
.run(id, code, tokenHash, createdBy, serverUrl ?? null, maxUses ?? 1);
}
export function getInviteByCode(code: string): InviteToken | null {
const row = db().prepare(`SELECT * FROM invite_tokens WHERE code = ?`).get(code) as
| {
id: string;
code: string;
token_hash: string;
created_by: string;
used_by: string | null;
server_url: string | null;
max_uses: number;
use_count: number;
expires_at: string | null;
revoked_at: string | null;
created_at: string;
}
| undefined;
if (!row) return null;
return {
id: row.id,
code: row.code,
tokenHash: row.token_hash,
createdBy: row.created_by,
usedBy: row.used_by,
serverUrl: row.server_url,
maxUses: row.max_uses,
useCount: row.use_count,
expiresAt: row.expires_at,
revokedAt: row.revoked_at,
createdAt: row.created_at,
};
}
export function redeemInvite(code: string, usedBy: string): boolean {
const result = db()
.prepare(
`UPDATE invite_tokens
SET use_count = use_count + 1, used_by = ?
WHERE code = ? AND revoked_at IS NULL
AND use_count < max_uses
AND (expires_at IS NULL OR expires_at > datetime('now'))`
)
.run(usedBy, code);
return result.changes > 0;
}
export function revokeInvite(id: string): void {
db().prepare(`UPDATE invite_tokens SET revoked_at = datetime('now') WHERE id = ?`).run(id);
}
// ──────────────── Community Servers ────────────────
/**
* Look up a connected community server by its API key hash.
* Returns the server id if the key hash matches a 'connected' server, or undefined.
* Used by federation routes to authenticate bearer tokens.
*/
export function getConnectedServerByKeyHash(apiKeyHash: string): { id: string } | undefined {
return db()
.prepare("SELECT id FROM community_servers WHERE api_key_hash = ? AND status = 'connected'")
.get(apiKeyHash) as { id: string } | undefined;
}
export function connectServer(id: string, name: string, url: string, apiKeyHash: string): void {
db()
.prepare(
`INSERT OR REPLACE INTO community_servers (id, name, url, api_key_hash)
VALUES (?, ?, ?, ?)`
)
.run(id, name, url, apiKeyHash);
}
export function disconnectServer(id: string): void {
db().prepare(`UPDATE community_servers SET status = 'disconnected' WHERE id = ?`).run(id);
}
/** List community servers (excludes api_key_hash for security). */
export function listServers(): Omit<CommunityServer, "apiKeyHash">[] {
const rows = db()
.prepare(
`SELECT id, name, url, connected_at, last_sync_at, status, error_message FROM community_servers`
)
.all() as Array<{
id: string;
name: string;
url: string;
connected_at: string;
last_sync_at: string | null;
status: string;
error_message: string | null;
}>;
return rows.map((r) => ({
id: r.id,
name: r.name,
url: r.url,
connectedAt: r.connected_at,
lastSyncAt: r.last_sync_at,
status: r.status,
errorMessage: r.error_message,
}));
}
/**
* Get neighbors around a user on the leaderboard.
*/
export function getLeaderboardNeighbors(
apiKeyId: string,
scope: string,
radius: number = 5
): {
above: Array<{ apiKeyId: string; score: number }>;
below: Array<{ apiKeyId: string; score: number }>;
} {
const d = db();
const scoreRow = d
.prepare("SELECT score FROM leaderboard WHERE api_key_id = ? AND scope = ?")
.get(apiKeyId, scope) as { score: number } | undefined;
if (!scoreRow) return { above: [], below: [] };
const above = d
.prepare(
`SELECT api_key_id, score FROM leaderboard
WHERE scope = ? AND score > ?
ORDER BY score ASC LIMIT ?`
)
.all(scope, scoreRow.score, radius) as Array<{ api_key_id: string; score: number }>;
const below = d
.prepare(
`SELECT api_key_id, score FROM leaderboard
WHERE scope = ? AND score < ?
ORDER BY score DESC LIMIT ?`
)
.all(scope, scoreRow.score, radius) as Array<{ api_key_id: string; score: number }>;
return {
above: above.reverse().map((r) => ({ apiKeyId: r.api_key_id, score: r.score })),
below: below.map((r) => ({ apiKeyId: r.api_key_id, score: r.score })),
};
}
/**
* Rotate weekly/monthly scopes. Archive old data, reset current.
* Uses two-step approach (SELECT then parameterized INSERT) to avoid SQL injection.
* Skips if archive scope already has data for this period (double-run protection).
*/
export function rotateLeaderboardScope(scope: "weekly" | "monthly"): void {
const d = db();
const archiveSuffix =
scope === "weekly"
? `week_${new Date().toISOString().slice(0, 10)}`
: `month_${new Date().toISOString().slice(0, 7)}`;
// Double-run protection: skip if archive scope already has data
const existing = d
.prepare("SELECT COUNT(*) AS cnt FROM leaderboard WHERE scope = ?")
.get(archiveSuffix) as { cnt: number };
if (existing.cnt > 0) return;
// Step 1: SELECT rows into memory
const rows = d
.prepare("SELECT api_key_id, score, updated_at FROM leaderboard WHERE scope = ?")
.all(scope) as Array<{ api_key_id: string; score: number; updated_at: string }>;
// Step 2: INSERT with parameters (no string interpolation)
if (rows.length > 0) {
const insert = d.prepare(
"INSERT OR IGNORE INTO leaderboard (api_key_id, scope, score, updated_at) VALUES (?, ?, ?, ?)"
);
for (const row of rows) {
insert.run(row.api_key_id, archiveSuffix, row.score, row.updated_at);
}
}
d.prepare("DELETE FROM leaderboard WHERE scope = ?").run(scope);
}