mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat(coderd): filter expired API tokens server-side (#22263)
## Summary
Moves expired token filtering from client-side to server-side by adding
an `include_expired` parameter to the `GetAPIKeysByLoginType` and
`GetAPIKeysByUserID` database queries. This is more efficient for large
deployments with many expired/short-lived tokens.
## Changes
- Add `include_expired` parameter to SQL queries using `OR`
short-circuit
- Add `include_expired` query parameter to `GET
/users/{user}/keys/tokens`
- Add `IncludeExpired` field to `codersdk.TokensFilter`
- Remove client-side filtering from CLI `tokens list` command
- Add `TestTokensFilterExpired` test
Fixes coder/internal#1357
This commit is contained in:
@@ -105,8 +105,13 @@ expires the token, (soft-delete):
|
||||
coder tokens remove <name|id>
|
||||
```
|
||||
|
||||
Expired tokens can no longer be used for authentication but remain visible in
|
||||
token listings.
|
||||
Expired tokens can no longer be used for authentication and are hidden from
|
||||
token listings by default. To include expired tokens, use the
|
||||
`--include-expired` flag:
|
||||
|
||||
```console
|
||||
coder tokens list --include-expired
|
||||
```
|
||||
|
||||
To hard-delete a token, use the `--delete` flag:
|
||||
|
||||
|
||||
Reference in New Issue
Block a user