Draft implementation PR: https://github.com/badbundle/track-slash/pull/100
Description
Problem
Every successful AuthenticateToken call performs an unconditional UPDATE auth_tokens SET last_used_at = now() (internal/store/auth.go:69-108). Both API and UI authentication middleware call this function, so ordinary reads—including page fragments and authenticated image/content requests—become database writes.
Impact
- Avoidable WAL, row-version churn, replication traffic, and vacuum work.
- Concurrent requests using one token contend on the same row.
- A token-valid read fails if the usage timestamp update fails, coupling read availability to a non-critical audit write.
Acceptance criteria
- Throttle persistence (for example, update only when
last_used_atis older than a configured interval) or otherwise coalesce usage writes. - Keep authentication/revocation/expiry checks strongly consistent.
- Define whether a usage-write failure should fail the user request.
- Add a test showing repeated authentications inside the throttle window do not repeatedly change the row while usage eventually advances.
Sub-issues
0Linked issues
0GitHub
0No branches or pull requests linked.