db: report a missing pre-auth key on expire and destroy

Both updated by id without checking RowsAffected, so expiring or deleting
an unknown key silently succeeded. Return ErrPreAuthKeyNotFound, matching
DestroyPreAuthKey's documented contract.
This commit is contained in:
Kristoffer Dalby
2026-06-18 07:37:02 +00:00
parent deee874bc8
commit c386dfe0fd
+18 -4
View File
@@ -309,9 +309,13 @@ func DestroyPreAuthKey(tx *gorm.DB, id uint64) error {
}
// Then delete the pre-auth key
err = tx.Unscoped().Delete(&types.PreAuthKey{}, id).Error
if err != nil {
return err
res := tx.Unscoped().Delete(&types.PreAuthKey{}, id)
if res.Error != nil {
return res.Error
}
if res.RowsAffected == 0 {
return ErrPreAuthKeyNotFound
}
return nil
@@ -356,5 +360,15 @@ func UsePreAuthKey(tx *gorm.DB, k *types.PreAuthKey) error {
// ExpirePreAuthKey marks a [types.PreAuthKey] as expired.
func ExpirePreAuthKey(tx *gorm.DB, id uint64) error {
now := time.Now()
return tx.Model(&types.PreAuthKey{}).Where("id = ?", id).Update("expiration", now).Error
res := tx.Model(&types.PreAuthKey{}).Where("id = ?", id).Update("expiration", now)
if res.Error != nil {
return res.Error
}
if res.RowsAffected == 0 {
return ErrPreAuthKeyNotFound
}
return nil
}