Skip to content

feat(metrics): accept a time range on dashboard metrics and anomalies - #364

Merged
Bccorb merged 2 commits into
mainfrom
feat/ranged-internal-metrics
Oct 7, 2026
Merged

Bccorb merged 2 commits into
mainfrom
feat/ranged-internal-metrics

Conversation

@Bccorb

@Bccorb Bccorb commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Closes #132.

Depends on @seamless-auth/types 0.28.0 (fells-code/seamless-auth-types#91), now published and pinned here. Rebased onto main after #363 and #365.

What changed

  • GET /internal/metrics/dashboard takes from/to (DashboardMetricsQuerySchema, the same range rules as /internal/auth-events/*), defaulting to the last 24 hours.
    • The *24h fields keep meaning the last 24 hours whatever window is asked for. That was the agreed answer to the naming question.
    • New window-neutral fields newUsers, loginSuccess, loginFailed, successRate, otpUsage, passkeyUsage cover the requested window, and window says which one.
    • Without a range the window is the last 24 hours, so the counts run once rather than twice.
  • GET /internal/security/anomalies takes from/to, limit (1 to 200, default 200) and offset (SecurityAnomaliesQuerySchema). It uses findAndCountAll, so total is every match in the window rather than the length of the capped page. It also returns window, limit and offset.
  • Both routes declare their query schemas, so they now 400 on a bad range. Both gain an OpenAPI description of the window semantics, and docs/admin-operations.md explains them.

Contract / ripple

  • @seamless-auth/types 0.28.0 (types#91) adds the query schemas and the optional response fields. Older clients keep parsing.
  • seamless-auth-server: getDashboardMetricsHandler and getSecurityAnomaliesHandler in core are built without a query today, so the range never reaches the API. They need to switch to the WithQuery shape and join the query-forwarding tests. I'll do that next.
  • Dashboard: this unblocks the rest of Date range on the data screens (export delivered) seamless-auth-admin-dashboard#148, so the Overview tiles and the Security anomaly feed can follow the range control.

Checks

npm run typecheck, npm run lint, npm run format:check, npm run build, npm run coverage (1722 passed, 95.21% branches). New integration tests cover the default window and paging, a requested window with a real total, rejection of a reversed range and an oversized page, ranged dashboard figures beside unchanged *24h ones, and the no-range path counting once.

Bccorb added 2 commits October 6, 2026 22:47
The two internal endpoints that fed the operator screens without a range now
take from and to, so a console can offer one range control. Dashboard
metrics keeps its 24 hour fields and adds window-neutral ones; anomalies
pages and reports a real total.

Closes #132.
@Bccorb
Bccorb force-pushed the feat/ranged-internal-metrics branch from 7342db5 to 1bbcb4f Compare October 7, 2026 02:53
@Bccorb
Bccorb marked this pull request as ready for review October 7, 2026 02:53
@Bccorb
Bccorb merged commit c2edfbc into main Oct 7, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Feature]: Dashboard metrics and security anomalies accept no time range

1 participant