[management] Confine the activity writes to the reverse proxy

The user half reused nothing: SaveUserLastLogin already exists and is the
same call the dashboard and device login paths make, so the parallel
RefreshUserLastLogin is gone and the proxy uses the established one.

Reaching it no longer widens shared interfaces. The proxy service already
receives the store, narrowed to ProxyTokenChecker; that interface now
carries the two writes the proxy makes, so users.Manager, peers.Manager and
Peer are untouched and the exclusion predicate moved into the proxy package
next to its only caller.

RefreshPeerLastSeen stays on the store because nothing there fits:
SavePeerStatus rewrites the connected flag and session token from a caller
snapshot, which would race the sync stream that owns them.
This commit is contained in:
mlsmaycon
2026-08-09 08:11:30 +00:00
parent 48d9161056
commit d2f93fcd90
12 changed files with 71 additions and 195 deletions
-12
View File
@@ -3,7 +3,6 @@ package users
import (
"context"
"errors"
"time"
"github.com/netbirdio/netbird/management/server/store"
"github.com/netbirdio/netbird/management/server/types"
@@ -12,9 +11,6 @@ import (
type Manager interface {
GetUser(ctx context.Context, userID string) (*types.User, error)
GetUserWithGroups(ctx context.Context, userID string) (*types.User, []*types.Group, error)
// RefreshLastLogin records an interactive login on the user without
// rewriting the rest of the row, keeping a newer stored timestamp.
RefreshLastLogin(ctx context.Context, accountID, userID string, loginAt time.Time) error
}
type managerImpl struct {
@@ -30,10 +26,6 @@ func NewManager(store store.Store) Manager {
}
}
func (m *managerImpl) RefreshLastLogin(ctx context.Context, accountID, userID string, loginAt time.Time) error {
return m.store.RefreshUserLastLogin(ctx, accountID, userID, loginAt)
}
func (m *managerImpl) GetUser(ctx context.Context, userID string) (*types.User, error) {
return m.store.GetUserByUserID(ctx, store.LockingStrengthNone, userID)
}
@@ -82,10 +74,6 @@ func (m *managerMock) GetUser(ctx context.Context, userID string) (*types.User,
}
}
func (m *managerMock) RefreshLastLogin(_ context.Context, _, _ string, _ time.Time) error {
return nil
}
func (m *managerMock) GetUserWithGroups(ctx context.Context, userID string) (*types.User, []*types.Group, error) {
user, err := m.GetUser(ctx, userID)
if err != nil {