Repository navigation
Conversation
Telnet/SSH logins were recorded twice (an untagged row from /api/auth/login and a tagged row from BbsSession), inflating login counts and misattributing half to web, while PacketBBS TOTP logins recorded none and never stamped last_login. Add ActivityTracker::trackLogin(), record the event once at the login boundary with the service and caller IP, drop the BbsSession duplicate, and have PacketBBS LOGIN stamp last_login and record one event. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
TITLE: Record exactly one login event per login (telnet/SSH double count, PacketBBS none)
Problem
POST /api/auth/loginrecords aTYPE_LOGINactivity row for every successful login, with no service tag. Telnet and SSH logins also go through this route (BbsSessionandSshSession::verifyPasswordcall it), and afterwardsBbsSessionrecords a second, taggedTYPE_LOGINrow.users.last_login.Impact
Every telnet/SSH login is counted twice in Today's Callers and the total login count, and half of those rows are misattributed to
webin the login-by-source breakdown. PacketBBS callers are invisible to login stats and keep a stale "last login".Repair
ActivityTracker::trackLogin($userId, $service, $ip)defines the login row:object_name= service,meta.ipwhen known./api/auth/loginand the auto-approved/api/registerpath record the event once, with$serviceand the caller IP.BbsSessionno longer records a second event.LOGINstampslast_login(Auth::updateLastLogin()made public rather than duplicating the UPDATE) and records onepacketbbsevent.docs/PacketBBS.mdanddocs/TerminalServerDevGuide.mdare updated.Note: the developer-only
DEBUG_USERtelnet auto-login does not go through the API, so it no longer records a login event. Historical rows are not rewritten.Proof
tests/Unit/LoginEventAccountingTest.php(no database; a capturing PDO stub plus source-wiring checks) covers:trackLoginwrites one tagged row, with and without an IP;BbsSessionrecords none;last_login.It fails on the current branch (2 errors, 3 failures) and passes with the change. The rest of
tests/Unitis unchanged.