trackslash
TRACK-4 P2

Stop writing auth token usage on every request

0
All issues

Description

Problem

Every successful AuthenticateToken call performs an unconditional UPDATE auth_tokens SET last_used_at = now() (internal/store/auth.go:69-108). Both API and UI authentication middleware call this function, so ordinary reads—including page fragments and authenticated image/content requests—become database writes.

Impact

  • Avoidable WAL, row-version churn, replication traffic, and vacuum work.
  • Concurrent requests using one token contend on the same row.
  • A token-valid read fails if the usage timestamp update fails, coupling read availability to a non-critical audit write.

Acceptance criteria

  • Throttle persistence (for example, update only when last_used_at is older than a configured interval) or otherwise coalesce usage writes.
  • Keep authentication/revocation/expiry checks strongly consistent.
  • Define whether a usage-write failure should fail the user request.
  • Add a test showing repeated authentications inside the throttle window do not repeatedly change the row while usage eventually advances.

Sub-issues

0

Linked issues

0

GitHub

0

No branches or pull requests linked.

Comments

1