feat: add network calls summary to AI session threads API (#27417)

Backend for the AI session network summary. Exposes total/blocked
network calls and top destination domains on the session threads
endpoint (`GET /api/v2/ai-gateway/sessions/{id}`).

Total and blocked reuse the existing Agent Firewall aggregation from the
sessions list query, so the numbers match the sessions table. Top
domains are a new server-side aggregation
(`GetAIBridgeSessionTopDomains`) over boundary logs, using the same
interception-window correlation. There is no network-error state,
matching the current data model.

Frontend consuming these fields is in a separate stacked PR.

### PR map (merge strictly bottom-up)

This change is a 4-PR stack. Each PR depends on all the ones below it,
so merge in this exact order:

1. #27417 — backend network summary (base `main`)
2. #27418 — frontend summary rows (base #27417)
3. #27425 — backend per-call list `network_call_logs` (base #27418)
4. #27426 — frontend network-calls panel (base #27425)

Refs AIGOV-463

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Co-authored-by: Cian Johnston <cian@coder.com>
This commit is contained in:
Sas Swart
2026-07-30 13:09:46 +02:00
committed by GitHub
co-authored by Claude Opus 4.8 Cian Johnston
parent 3660ffecdd
commit 841a1765f7
16 changed files with 644 additions and 21 deletions
+21
View File
@@ -309,6 +309,21 @@ type sqlcQuerier interface {
// the root), we return its own ID as the root.
GetAIBridgeInterceptionLineageByToolCallID(ctx context.Context, toolCallID string) (GetAIBridgeInterceptionLineageByToolCallIDRow, error)
GetAIBridgeInterceptions(ctx context.Context) ([]AIBridgeInterception, error)
// Returns the most contacted destination hosts for an AI session, ordered by
// call count descending and limited to the top @limit_ rows. total_domains is
// the number of distinct domains across the whole session, used to render a
// "+N more" overflow beyond the returned rows. Only HTTP egress is considered;
// dns/git/fs boundary logs do not carry a domain in the same shape.
//
// Windowing mirrors the network_calls aggregation in ListAIBridgeSessions:
// each interception's boundary logs fall in the open interval (this seq, next
// interception's seq) within the same firewall session. The exclusive lower
// bound drops the interception's own LLM-provider call. next_seq considers all
// interceptions in the firewall session so windows never bleed across AI
// sessions that share one firewall session, and falls back to the maximum
// sequence_number for the last interception so the window stays an
// index-satisfiable range.
GetAIBridgeSessionTopDomains(ctx context.Context, arg GetAIBridgeSessionTopDomainsParams) ([]GetAIBridgeSessionTopDomainsRow, error)
GetAIBridgeTokenUsagesByInterceptionID(ctx context.Context, interceptionID uuid.UUID) ([]AIBridgeTokenUsage, error)
GetAIBridgeToolUsagesByInterceptionID(ctx context.Context, interceptionID uuid.UUID) ([]AIBridgeToolUsage, error)
GetAIBridgeUserPromptsByInterceptionID(ctx context.Context, interceptionID uuid.UUID) ([]AIBridgeUserPrompt, error)
@@ -1250,6 +1265,12 @@ type sqlcQuerier interface {
// Pagination-first strategy: identify the page of sessions cheaply via a
// single GROUP BY scan, then do expensive lateral joins (tokens, prompts,
// first-interception metadata) only for the ~page-size result set.
// The last interception in a session has no next row, so next_seq uses
// the largest sequence_number instead of NULL. The lookup stays a plain
// range, so the (session_id, sequence_number) index answers it alone.
// With NULL and an OR check, the index cannot bound the range: each
// interception reads every log to the end of the session and throws
// most of them away.
ListAIBridgeSessions(ctx context.Context, arg ListAIBridgeSessionsParams) ([]ListAIBridgeSessionsRow, error)
ListAIBridgeTokenUsagesByInterceptionIDs(ctx context.Context, interceptionIds []uuid.UUID) ([]AIBridgeTokenUsage, error)
ListAIBridgeToolUsagesByInterceptionIDs(ctx context.Context, interceptionIds []uuid.UUID) ([]AIBridgeToolUsage, error)