diff --git a/ARCHITECTURE.md b/ARCHITECTURE.md index 5a223ac..ac061f4 100644 --- a/ARCHITECTURE.md +++ b/ARCHITECTURE.md @@ -431,9 +431,9 @@ that matches its predicate exactly. What remains, honestly: **`sort=priority` pays a join** over the management layer on top of a rank that was never index-servable, ~3.8x its pre-split cost. -`schema.ts` and `migrations.ts` must agree statement for statement: the drizzle -table object is a public export, so a host pointing `drizzle-kit` at it would -otherwise recreate indexes the migrations do not have. +`schema.ts` and `migrations.ts` must agree statement for statement: the +runtime queries read through the drizzle table object, so a drift between the +two would query columns or rely on indexes the migrations never created. `src/schema-ddl-parity.test.ts` diffs the two against a live database. ## Migrations diff --git a/CHANGELOG.md b/CHANGELOG.md index 04fa4da..d4fa6ad 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -214,6 +214,12 @@ always called out under their own heading. ### Breaking +- **The barrel no longer exports schema objects or internal constants.** + `principalMail`, `mailboxPgSchema`, `expectedColumnTypes`, + `assertExpectedColumnTypes`, `MESSAGE_ID_FALLBACK_DOMAIN`, and + `MAX_PENDING_SSE_EVENTS`, and the `PrincipalMailRow`/`PrincipalMailInsert` + row types are gone from `@corbits/mailbox`. + `runMailboxMigrations` still asserts column types on every boot. - **Hard caps on frame size and transport recipient fan-out.** Frames above `MAX_MAILBOX_FRAME_BYTES` (1 MiB) and transport recipient lists longer than `MAX_MAILBOX_RECIPIENTS` (50) are refused with `RangeError` before durable diff --git a/src/index.ts b/src/index.ts index 78e025f..8c7fc67 100644 --- a/src/index.ts +++ b/src/index.ts @@ -2,11 +2,7 @@ // human principals. This library exists ONLY to give a human principal a // native `@intx/mailbox` `MailboxStore` over Postgres, and the routes that // let a host's UI list, read, and file it — nothing else. -export { - mountMailbox, - MAX_MAILBOX_PAGE_LIMIT, - MAX_PENDING_SSE_EVENTS, -} from "./mount.js"; +export { mountMailbox, MAX_MAILBOX_PAGE_LIMIT } from "./mount.js"; export type { MountMailboxOpts, ResolvedPrincipal, @@ -15,15 +11,7 @@ export type { export { runMailboxMigrations, MigrationChecksumError } from "./migrations.js"; -// Boot-time assertion that the live column types are the ones this package's -// codec assumes — `CREATE TABLE IF NOT EXISTS` matches on the table NAME alone, -// so a host that already owns a `mailbox` or `principal_mail` table would -// otherwise have its columns read through our decoder in silence. -export { - assertExpectedColumnTypes, - expectedColumnTypes, - SchemaTypeMismatchError, -} from "./schema-check.js"; +export { SchemaTypeMismatchError } from "./schema-check.js"; export { createMailboxDb } from "./db.js"; export type { MailboxDb } from "./db.js"; @@ -38,9 +26,6 @@ export { } from "./native-store.js"; export type { NativeMailboxStore } from "./native-store.js"; -export { principalMail, mailboxPgSchema } from "./schema.js"; -export type { PrincipalMailRow, PrincipalMailInsert } from "./schema.js"; - // Blank-scope refusal at the boundary (nicer than an FK violation's stack), // and explicit offboarding tools for hosts that manage deletion themselves — // the control-plane FKs cascade on tenant/principal delete either way. @@ -79,11 +64,7 @@ export type { DeliveredInboxItem, } from "./write.js"; -export { - buildMailFrame, - generateMailboxMessageId, - MESSAGE_ID_FALLBACK_DOMAIN, -} from "./frame.js"; +export { buildMailFrame, generateMailboxMessageId } from "./frame.js"; export { createMailboxPersist, MAX_MAILBOX_RECIPIENTS } from "./persist.js"; export type {