mirror of
https://github.com/mattermost/mattermost.git
synced 2026-09-01 15:00:08 +08:00
5d5d4e2752
* [MM-70389] Add Android to the user_agent_platform session attribute uasurfer has no Android platform, so Android devices were reported as Linux and "Android" was missing from the user_agent_platform select list, leaving no way to write a permission policy rule that matches Android sessions. Derive the platform name "Android" when the parsed OS is Android (or the Mattermost Mobile user agent is not iOS) and add the matching option to the seeded session attribute schema. Co-authored-by: mattermost-code <matty-code@mattermost.com> * [MM-70389] Cover the Android platform value end to end Add a drift guard tying the platform names the server derives to the options the user_agent_platform select offers, a session attribute test proving an Android session stores "Android", and a migration test proving a newly declared option reaches an already-seeded field without regenerating the IDs of the options around it. Co-authored-by: mattermost-code <matty-code@mattermost.com> * [MM-70389] Trim comments and tighten the platform drift guard Assert getPlatformName's own output against the schema options so a platform name returned directly, rather than looked up in platformNames, cannot drift out of the select either. Co-authored-by: mattermost-code <matty-code@mattermost.com> --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: mattermost-code <matty-code@mattermost.com>
Server Channels Review Guidelines
When reviewing or writing code in the server channels package, focus on SQL query performance and API layer efficiency.
SQL Store Layer
- Run
EXPLAIN ANALYZEon new or modified queries against a large dataset before merging. A query that performs well on a 12M-post database may degrade significantly at 100M+ posts. - Watch for sequential scans on large tables. Ensure appropriate indexes exist for new query patterns.
- When adding new queries to the store, check whether an existing query already fetches the needed data. Avoid duplicate round trips to the database.
API Layer
- Minimize database round trips. If an endpoint calls a
Getfollowed by aDeleteon the same row, consider usingDELETE ... RETURNINGto combine them into a single query. - Don't add queries that are unnecessary for the operation. The most efficient work is the work you don't do.
- When adding new API endpoints, add them to the load test tooling so performance can be validated under realistic concurrency.
Permissions and Security
- Verify that new endpoints enforce appropriate permissions. Rely on the dedicated security review for thorough coverage, but flag anything obviously missing (e.g., an endpoint that skips permission checks entirely).