Skip to content

Record exactly one login event per login - #486

Open
SkrawlCO wants to merge 1 commit into
awehttam:claudesbbsfrom
SkrawlCO:upstream/up-025-login-event-accounting
Open

SkrawlCO wants to merge 1 commit into
awehttam:claudesbbsfrom
SkrawlCO:upstream/up-025-login-event-accounting

Conversation

@SkrawlCO

@SkrawlCO SkrawlCO commented Oct 5, 2026

Copy link
Copy Markdown

TITLE: Record exactly one login event per login (telnet/SSH double count, PacketBBS none)

Problem

  • POST /api/auth/login records a TYPE_LOGIN activity row for every successful login, with no service tag. Telnet and SSH logins also go through this route (BbsSession and SshSession::verifyPassword call it), and afterwards BbsSession records a second, tagged TYPE_LOGIN row.
  • PacketBBS TOTP logins record no login event and do not stamp users.last_login.

Impact

Every telnet/SSH login is counted twice in Today's Callers and the total login count, and half of those rows are misattributed to web in the login-by-source breakdown. PacketBBS callers are invisible to login stats and keep a stale "last login".

Repair

  • New ActivityTracker::trackLogin($userId, $service, $ip) defines the login row: object_name = service, meta.ip when known.
  • /api/auth/login and the auto-approved /api/register path record the event once, with $service and the caller IP.
  • BbsSession no longer records a second event.
  • PacketBBS LOGIN stamps last_login (Auth::updateLastLogin() made public rather than duplicating the UPDATE) and records one packetbbs event.
  • docs/PacketBBS.md and docs/TerminalServerDevGuide.md are updated.

Note: the developer-only DEBUG_USER telnet auto-login does not go through the API, so it no longer records a login event. Historical rows are not rewritten.

Proof

tests/Unit/LoginEventAccountingTest.php (no database; a capturing PDO stub plus source-wiring checks) covers:

  • trackLogin writes one tagged row, with and without an IP;
  • the login route records the event with service and IP;
  • BbsSession records none;
  • the PacketBBS login records one event and stamps last_login.

It fails on the current branch (2 errors, 3 failures) and passes with the change. The rest of tests/Unit is unchanged.

Telnet/SSH logins were recorded twice (an untagged row from
/api/auth/login and a tagged row from BbsSession), inflating login
counts and misattributing half to web, while PacketBBS TOTP logins
recorded none and never stamped last_login.

Add ActivityTracker::trackLogin(), record the event once at the login
boundary with the service and caller IP, drop the BbsSession duplicate,
and have PacketBBS LOGIN stamp last_login and record one event.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant