fix: mark users seen when activating on login (#21305)

fixes #21303

Update user last_seen_at when we mark them active on login. This prevents a narrow race where they can be re-marked dormant and fail to log in.
This commit is contained in:
Spike Curtis
2025-12-17 16:49:40 +04:00
committed by GitHub
parent f9087d6feb
commit bd753d9cb9
6 changed files with 43 additions and 26 deletions
+8 -6
View File
@@ -648,9 +648,10 @@ func ActivateDormantUser(logger slog.Logger, auditor *atomic.Pointer[audit.Audit
//nolint:gocritic // System needs to update status of the user account (dormant -> active).
newUser, err := db.UpdateUserStatus(dbauthz.AsSystemRestricted(ctx), database.UpdateUserStatusParams{
ID: user.ID,
Status: database.UserStatusActive,
UpdatedAt: dbtime.Now(),
ID: user.ID,
Status: database.UserStatusActive,
UpdatedAt: dbtime.Now(),
UserIsSeen: true,
})
if err != nil {
logger.Error(ctx, "unable to update user status to active", slog.Error(err))
@@ -1799,9 +1800,10 @@ func (api *API) oauthLogin(r *http.Request, params *oauthLoginParams) ([]*http.C
dormantConvertAudit.Old = user
//nolint:gocritic // System needs to update status of the user account (dormant -> active).
user, err = tx.UpdateUserStatus(dbauthz.AsSystemRestricted(ctx), database.UpdateUserStatusParams{
ID: user.ID,
Status: database.UserStatusActive,
UpdatedAt: dbtime.Now(),
ID: user.ID,
Status: database.UserStatusActive,
UpdatedAt: dbtime.Now(),
UserIsSeen: true,
})
if err != nil {
logger.Error(ctx, "unable to update user status to active", slog.Error(err))