pub fn save_vault(
conn: &Connection,
data: Value,
ctx: SaveCtx<'_>,
) -> Result<String, String>Expand description
Serialises data to the vault, updating version_history on key changes
and appending to the vault_audit hash chain. Returns the new version.
§Concurrency
When ctx.expect_version is set this is a compare-and-swap: the whole
operation runs inside one BEGIN IMMEDIATE transaction, and if another
writer has changed the vault since the caller read it, nothing is written and
CONFLICT_ERR is returned.
Doing the check here rather than in each caller matters for two reasons.
A caller that reads, compares, then writes has a race between the compare and
the write — which is what the server’s If-Match handling used to be. And a
caller that simply forgets is silently unprotected, which is how the desktop
could clobber a LAN peer’s edit.
The audit appends are inside the same transaction. They used to run before it, so a rejected or failed write still left audit rows describing changes that never happened.