Files
mattermost/server/channels
2966a87163 Automated cherry pick of #36999 (#37160)
The GET /api/v4/limits/server endpoint ran expensive active-user and
single-channel-guest count queries for every user on login and app
refresh, even though non-admins never receive those counts. The
single-channel-guest count is a full ChannelMembers scan, so this put a
full-table-scan query on a high-frequency hot path.

Add an includeUserCounts parameter to App.GetServerLimits so the user
and guest count queries only run when the caller needs them. The api4
handler passes the existing admin check, keeping the cheap
license-derived and post-history fields for all users while skipping the
expensive queries for non-admins. Internal callers that genuinely need
the counts (isAtUserLimit, user creation/activation) pass true.


(cherry picked from commit 08c3f6faa9)

Co-authored-by: Ben Schumacher <ben.schumacher@mattermost.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-23 10:35:43 +00:00
..
2026-04-01 13:03:36 +00:00

Server Channels Review Guidelines

When reviewing or writing code in the server channels package, focus on SQL query performance and API layer efficiency.

SQL Store Layer

  • Run EXPLAIN ANALYZE on new or modified queries against a large dataset before merging. A query that performs well on a 12M-post database may degrade significantly at 100M+ posts.
  • Watch for sequential scans on large tables. Ensure appropriate indexes exist for new query patterns.
  • When adding new queries to the store, check whether an existing query already fetches the needed data. Avoid duplicate round trips to the database.

API Layer

  • Minimize database round trips. If an endpoint calls a Get followed by a Delete on the same row, consider using DELETE ... RETURNING to combine them into a single query.
  • Don't add queries that are unnecessary for the operation. The most efficient work is the work you don't do.
  • When adding new API endpoints, add them to the load test tooling so performance can be validated under realistic concurrency.

Permissions and Security

  • Verify that new endpoints enforce appropriate permissions. Rely on the dedicated security review for thorough coverage, but flag anything obviously missing (e.g., an endpoint that skips permission checks entirely).