Repository navigation
feat(server): client list shows when each paired client was last seen - #26
Merged
Merged
Conversation
The Connections page only knew when a client last opened a socket, and only in a tooltip, so a client that stayed connected for weeks and then dropped read as weeks stale while HTTP-only clients never moved at all. Auth sessions now persist last_seen_at: socket open and close always write it, and a verified HTTP request advances it at most once an hour. The access stream publishes the update, the web client row shows "Connected" or "Last seen 2h ago" inline, and the CLI listing prints it.
…lescing map on removal
Review follow-ups for the last-seen column: - SessionStore.verify no longer bumps last seen. EnvironmentAuth records it after the DPoP branch, so a proof-bound token sent without a valid proof is rejected without advancing the client or publishing an update. - AuthClientSession.lastSeenAt decodes to null when absent, so a newer web or mobile client still reads the access stream from an older server. - Migration 051 gets the same column test as 041.
Owner
Author
|
Follow-up from the fresh review, all three findings applied:
Server/contracts/web typecheck clean; touched suites 35/35. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #24.
What was wrong
Settings → Connections only knew when a client last opened a socket (
lastConnectedAt), and only showed it in a hover tooltip. A client that stayed connected for three weeks and then dropped read as "last connected three weeks ago", and HTTP-only traffic never moved it. Deciding what to revoke needs "last seen".How it's fixed
auth_sessions.last_seen_at(migration 051, nullable; existing rows read as null). The update is monotonic and skips revoked rows.SessionStorewrites it on socket open and on the last socket close, and a verified HTTP request advances it at most once per hour per session (in-memory coalescing map, pruned when a session is removed). Each write publishesclientUpsertedon the access stream so an open Connections page updates.AuthClientSession.lastSeenAton the contract; the web client row shows "Connected" / "Last seen 2h ago" / "Not seen yet" inline;t3 authlisting printslast seen:in text and JSON.Display signal only — #19's inactivity deadline keys on explicit activity, not traffic, and stays a separate field.
Verification
SessionStoretests written first: open/close writes, coalesced HTTP touches within and across the hour, stream emit only when the value changes, revoked session never advances. WebclientSessionPresenceLabeltests; CLI listing test.vp test runon server auth/persistence/HTTP suites (317 passing; one pre-existingServerSecretStorerace flake fails intermittently on clean main too), web presence tests; typecheck clean on server, web, mobile, client-runtime.🤖 Generated with Claude Code