Skip to content

feat: follow the range on headline metrics and anomalies; warn on review accounts - #285

Merged
Bccorb merged 2 commits into
mainfrom
feat/ranged-metrics-review-notice
Oct 7, 2026
Merged

Bccorb merged 2 commits into
mainfrom
feat/ranged-metrics-review-notice

Conversation

@Bccorb

@Bccorb Bccorb commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Depends on @seamless-auth/types 0.28.0 (fells-code/seamless-auth-types#91), now published and pinned here (check:types-current passes).

Depends on fells-code/seamless-auth-api#364 (#132), fells-code/seamless-auth-api#365 (#331) and fells-code/seamless-auth-server#194.

Ranged headline metrics and anomalies (finishes #148)

  • useDashboard and useAnomalies take { from, to }, and Overview and Security pass the same bounds the charts already use. Both keep the range in the URL as before.
  • A small dashboardFigures helper picks the window-neutral fields (loginSuccess, successRate, ...) when the API echoes a window, and the *24h fields otherwise. Every label is driven by which one was used:
    • against a ranged API, tiles say "in last 7 days" (or whatever range is selected)
    • against an older API, they keep "24h auth attempts (fixed window)" and the existing explanation
      So a tile never claims to follow the selector while showing a fixed window. Date range on the data screens (export delivered) #148 required exactly that.
  • Security does the same for the suspicious-activity feed, pill, stat card and table description, using total (now every match in the window) for "Showing X of Y reported signals".
  • The Sessions tile's hint said "Active sessions in the last 24 hours". It now says "Currently active sessions", which is what the API has always counted.

Review accounts notice (#331)

  • useReviewAccounts reads GET /admin/review-accounts, with no retries.
  • ReviewAccountsNotice, at the top of Overview, shows a warning only while enabled. It lists the addresses, sign-ins with the fixed code in the last 30 days (and the most recent), wrong codes entered, and the instruction to clear REVIEW_ACCOUNT_EMAILS. The code itself is never part of the response.
  • Against an API or adapter without the route (404) it renders nothing.

Checks

  • npm run typecheck, npm run lint, npm run format:check, npm run build
  • npm run coverage: 89 files, 580 tests pass
  • npm run test:e2e: 149 pass, including new specs for the range reaching /internal/metrics/dashboard and the tiles relabelling, and for the review notice. The e2e seed registers a disabled /admin/review-accounts by default, since Overview now calls it.

Bccorb added 2 commits October 6, 2026 22:32
…iew accounts

Overview's tiles and Security's anomaly feed now take the selected range,
labelling each figure by the window it shows. Overview warns while store
review accounts are enabled.

Refs fells-code/seamless-auth-api#132 and #331. Closes #148.
@Bccorb
Bccorb marked this pull request as ready for review October 7, 2026 02:53
@Bccorb
Bccorb merged commit 89e383b into main Oct 7, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant