Skip to content

[Studio] feat: add per-user session details - #4231

Merged
lizhimins merged 1 commit into
apache:rocketmq-studiofrom
coder999o:fix-091101
Sep 16, 2026
Merged

lizhimins merged 1 commit into
apache:rocketmq-studiofrom
coder999o:fix-091101

Conversation

@coder999o

Copy link
Copy Markdown
Contributor

What is the purpose of the change

Add per-user active session details to Studio user management, so administrators can inspect which active sessions belong to a user before revoking them.

Brief changelog

  • Add a safe per-user active session detail API without exposing session token hashes.
  • Add a Studio user session detail drawer with session status, idle time, remaining TTL, refresh, and revoke-all actions.
  • Add backend and frontend tests for the new session detail flow.

Verifying this change

  • mvn -q -Dtest=StudioUserControllerTest,AuthServiceSessionOverviewIntegrationTest test
  • npm test -- src/api/studioUsers.test.ts src/pages/studio/tests/UserManagement.test.tsx
  • npx eslint src/api/studioUsers.ts src/api/studioUsers.test.ts src/pages/studio/UserManagement.tsx src/pages/studio/tests/UserManagement.test.tsx
  • npm run build
  • git diff --check

@RockteMQ-AI RockteMQ-AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Summary

Adds per-user active session details to Studio user management. Backend exposes a new GET /api/studio/users/{userId}/sessions endpoint that returns session status, idle time, remaining TTL, and last-seen info — without exposing token hashes. Frontend adds a drawer component with refresh and revoke-all actions.

Findings

  • [Warning] AuthService.java:272 — listActiveSessionsForUser calls getUser(userId) which throws if the user doesn't exist. This is correct behavior, but the error message should be clear (e.g. 404 vs generic 500). Verify the exception handler maps this to a user-friendly response.
  • [Info] StudioUserSessionDetailVO.java — Good design decision to exclude tokenHash from the per-user detail VO. The session overview VO still includes the count, which is the right level of detail for the UI.
  • [Info] Frontend tests cover both the happy path and the empty-state case. The onClose callback pattern for the drawer is clean.

LGTM — well-structured feature with good test coverage on both backend and frontend.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants