Optimize encryption, storage, and media streaming performance (#447)

- AES-256-GCM in-place decryption halves peak RAM in encrypted blob backend
- Offload crypto ≥64 KiB to spawn_blocking (unblocks async runtime)
- Fix off-by-one in encrypted range stream (end now exclusive)
- Collapse 3 DB round-trips for quota updates into 1 correlated UPDATE
- Set-based reconciliation sweep replaces per-user task spawning
- Eliminate entity re-read after file overwrite via RETURNING clause
- Lightbox streams video/photos inline instead of fetch→blob
This commit is contained in:
Dionisio Pozo
2026-06-10 14:53:55 +02:00
committed by GitHub
parent 26b396490c
commit fe0053bc79
10 changed files with 440 additions and 227 deletions
+4 -1
View File
@@ -95,7 +95,10 @@ pub trait BlobStorageBackend: Send + Sync + 'static {
/// Stream the full blob content in chunks.
fn get_blob_stream(&self, hash: &str) -> BoxFut<'_, Result<BlobStream, DomainError>>;
/// Stream a byte range of the blob (for HTTP Range requests / video seek).
/// Stream the byte range `[start, end)` of the blob (for HTTP Range
/// requests / video seek). `end` is **exclusive**; `None` means "to the
/// end of the blob". Callers translating inclusive HTTP Range headers
/// must pass `last_byte + 1`.
fn get_blob_range_stream(
&self,
hash: &str,