feat(notifications): grouped email digest, new music as a daily summary (#5346)
release / govulncheck (push) Successful in 21s
release / web (push) Successful in 1m19s
release / go (push) Successful in 1m39s
release / integration (push) Successful in 5m27s
release / android (push) Successful in 5m47s
release / Build signed APK (releases and dev) (push) Successful in 5m34s
release / Attach APK to the Release (tag releases only) (push) Skipped
release / Build + push container image (push) Successful in 26s
release / Verify release artifacts (tag releases only) (push) Skipped
release / govulncheck (push) Successful in 21s
release / web (push) Successful in 1m19s
release / go (push) Successful in 1m39s
release / integration (push) Successful in 5m27s
release / android (push) Successful in 5m47s
release / Build signed APK (releases and dev) (push) Successful in 5m34s
release / Attach APK to the Release (tag releases only) (push) Skipped
release / Build + push container image (push) Successful in 26s
release / Verify release artifacts (tag releases only) (push) Skipped
Nothing is emailed per event. New music (request_completed) goes out at most once a day, at the summary hour in each user's own timezone, grouped by artist. Everything else is batched: one email a window after the first un-emailed item, holding whatever accumulated. - Migration 0074: notification_email_settings (summary hour, batch window, admin-configurable) and user_notification_email_state (batch start, last sent, failures and retry_after per user and group). Existing rows are stamped emailed so the upgrade sends no backlog. - The Notifier stamps emailed_at at write time when the recipient's email channel is off, so turning email on later doesn't send old items. - Read rows are never selected. A row is stamped only after the mailer accepts, in one transaction with the state, against the read's clock, so a coalesced row updated mid-send stays pending. - A failed send backs off 5m doubling to 6h; SMTP not configured just waits. - Links come from the public address; without one the email has none. - The mailer now RFC 2047-encodes subjects and strips line breaks from them. - Admin → Integrations gains a Notification emails card. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -3,8 +3,12 @@
|
||||
-- recipient's inbox preference before it reaches these.
|
||||
|
||||
-- name: InsertNotification :one
|
||||
INSERT INTO user_notifications (user_id, kind, payload)
|
||||
VALUES (sqlc.arg(user_id), sqlc.arg(kind), sqlc.arg(payload))
|
||||
-- email_wanted is the recipient's email channel for this kind as of now. A
|
||||
-- row nobody wants emailed is stamped at once, so the digest never has to
|
||||
-- judge it and a later "email on" doesn't send an old backlog.
|
||||
INSERT INTO user_notifications (user_id, kind, payload, emailed_at)
|
||||
VALUES (sqlc.arg(user_id), sqlc.arg(kind), sqlc.arg(payload),
|
||||
CASE WHEN sqlc.arg(email_wanted)::boolean THEN NULL ELSE now() END)
|
||||
RETURNING id;
|
||||
|
||||
-- name: UpsertCoalescedNotification :one
|
||||
@@ -18,8 +22,10 @@ RETURNING id;
|
||||
--
|
||||
-- emailed_at is cleared so the newer state goes out in the next batch; an
|
||||
-- emailed-but-unread row that keeps growing is news the user hasn't seen.
|
||||
INSERT INTO user_notifications (user_id, kind, payload, coalesce_key)
|
||||
VALUES (sqlc.arg(user_id), sqlc.arg(kind), sqlc.arg(payload), sqlc.arg(coalesce_key))
|
||||
-- Unless email_wanted is false, as in InsertNotification.
|
||||
INSERT INTO user_notifications (user_id, kind, payload, coalesce_key, emailed_at)
|
||||
VALUES (sqlc.arg(user_id), sqlc.arg(kind), sqlc.arg(payload), sqlc.arg(coalesce_key),
|
||||
CASE WHEN sqlc.arg(email_wanted)::boolean THEN NULL ELSE now() END)
|
||||
ON CONFLICT (user_id, coalesce_key) WHERE read_at IS NULL AND coalesce_key IS NOT NULL
|
||||
DO UPDATE SET
|
||||
payload = CASE
|
||||
@@ -30,7 +36,7 @@ DO UPDATE SET
|
||||
ELSE EXCLUDED.payload
|
||||
END,
|
||||
created_at = now(),
|
||||
emailed_at = NULL
|
||||
emailed_at = EXCLUDED.emailed_at
|
||||
RETURNING id;
|
||||
|
||||
-- name: ListNotifications :many
|
||||
@@ -97,3 +103,58 @@ ON CONFLICT (user_id, kind) DO UPDATE SET
|
||||
phone = EXCLUDED.phone,
|
||||
email = EXCLUDED.email,
|
||||
updated_at = now();
|
||||
|
||||
-- Email digest (#5346) ------------------------------------------------------
|
||||
|
||||
-- name: ListEmailPendingNotifications :many
|
||||
-- Every unread, un-emailed row of a user who has an address, oldest first.
|
||||
-- Read rows are never selected: the user has seen them, so they are not news.
|
||||
-- read_as_of is the database's clock at the read, handed back to
|
||||
-- MarkNotificationsEmailed.
|
||||
SELECT n.id, n.user_id, n.kind, n.payload, n.created_at,
|
||||
u.email::text AS email, u.username, u.display_name, u.timezone,
|
||||
now()::timestamptz AS read_as_of
|
||||
FROM user_notifications n
|
||||
JOIN users u ON u.id = n.user_id
|
||||
WHERE n.read_at IS NULL
|
||||
AND n.emailed_at IS NULL
|
||||
AND u.email IS NOT NULL AND u.email <> ''
|
||||
ORDER BY n.user_id, n.created_at, n.id;
|
||||
|
||||
-- name: MarkNotificationsEmailed :execrows
|
||||
-- Stamps the rows an email carried, or that were judged not to need one.
|
||||
-- read_as_of is from ListEmailPendingNotifications: a coalesced row updated
|
||||
-- since that read carries a later created_at, holds newer news, and stays
|
||||
-- pending for the next email.
|
||||
UPDATE user_notifications
|
||||
SET emailed_at = now()
|
||||
WHERE id = ANY(sqlc.arg(ids)::uuid[])
|
||||
AND created_at <= sqlc.arg(read_as_of)::timestamptz
|
||||
AND emailed_at IS NULL;
|
||||
|
||||
-- name: ListNotificationEmailState :many
|
||||
SELECT user_id, email_group, batch_opened_at, last_sent_at, failures, retry_after
|
||||
FROM user_notification_email_state;
|
||||
|
||||
-- name: UpsertNotificationEmailState :exec
|
||||
INSERT INTO user_notification_email_state
|
||||
(user_id, email_group, batch_opened_at, last_sent_at, failures, retry_after)
|
||||
VALUES (sqlc.arg(user_id), sqlc.arg(email_group), sqlc.narg(batch_opened_at),
|
||||
sqlc.narg(last_sent_at), sqlc.arg(failures), sqlc.narg(retry_after))
|
||||
ON CONFLICT (user_id, email_group) DO UPDATE SET
|
||||
batch_opened_at = EXCLUDED.batch_opened_at,
|
||||
last_sent_at = EXCLUDED.last_sent_at,
|
||||
failures = EXCLUDED.failures,
|
||||
retry_after = EXCLUDED.retry_after;
|
||||
|
||||
-- name: GetNotificationEmailSettings :one
|
||||
SELECT * FROM notification_email_settings WHERE id = true;
|
||||
|
||||
-- name: UpdateNotificationEmailSettings :one
|
||||
-- Migration 0074's CHECKs are the backstop behind the service's validation.
|
||||
UPDATE notification_email_settings
|
||||
SET summary_hour = sqlc.arg(summary_hour),
|
||||
batch_window_minutes = sqlc.arg(batch_window_minutes),
|
||||
updated_at = now()
|
||||
WHERE id = true
|
||||
RETURNING *;
|
||||
|
||||
Reference in New Issue
Block a user