The GitHub Actions job "CI" on 
rocketmq-dashboard.git/codex/session-client-attribution has failed.
Run started by GitHub user tju-yxq (triggered by tju-yxq).

Head commit for run:
0fc5272c0f96f44dafab316d6d92e984609a40d7 / Yxq <[email protected]>
feat(auth): attribute sessions to the client they were issued to

Every session row is anonymous: the drawer shows when a session was
last seen and when it expires, but not where it came from. During an
incident ("why does the departed contractor still have an active
session?", "which of these five sessions is the suspicious one?") the
administrator cannot tell a session issued from the office browser
from one issued by an unknown client.

Record client attribution when a session is issued:

- rmq_studio_session gains client_ip (VARCHAR 64) and user_agent
  (VARCHAR 255); a startup migration adds both columns to databases
  created before the current schema, mirroring the existing
  QueryHistorySchemaMigration pattern (metadata-checked, idempotent,
  tolerant of concurrent instances), and existing rows keep NULL —
  rendered as a dash.
- The login controller forwards the client address and User-Agent.
  Behind a reverse proxy the socket address is the proxy's, so the
  first X-Forwarded-For hop is preferred when present. The values are
  observability metadata for the session drawer only — never used for
  authorization — and are truncated to the column widths rather than
  failing the login.
- The sessions drawer gains an Origin column showing the address,
  with the full User-Agent on hover.

The properties-based (in-memory) auth mode is unchanged: it is the
single-user dev fallback and records no session rows at all.

Report URL: 
https://github.com/apache/rocketmq-dashboard/actions/runs/36906675272

With regards,
GitHub Actions via GitBox

Reply via email to