Skip to content

feat(dashboard): surface exclusive managed sessions in Sessions view - #11389

Merged
diegosouzapw merged 1 commit into
diegosouzapw:release/v3.8.51from
KaspaPulse:feat/exclusive-lease-dashboard-sessions
Aug 25, 2026
Merged

diegosouzapw merged 1 commit into
diegosouzapw:release/v3.8.51from
KaspaPulse:feat/exclusive-lease-dashboard-sessions

Conversation

@KaspaPulse

@KaspaPulse KaspaPulse commented Aug 24, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Keep every currently held Exclusive Managed Session Lease visible in the existing Sessions tab for the full valid lease lifetime, including idle gaps between model turns, tools, and local builds.

The current tab is backed by sessionManager, whose in-memory fingerprints are request-derived and swept after inactivity. That is useful for legacy sessions, but it cannot represent an idle exclusive lease whose official SQLite lifetime is still valid. This PR therefore adds a thin observability projection from the existing lease authority instead of changing lease ownership or routing.

Behavior and compatibility

  • Held leases remain visible while idle.
  • A held lease gets the existing localized common.active indication only when existing pending-request accounting reports in-flight work for that connection.
  • Idle leases remain visible without a new IDLE badge.
  • Release or TTL expiry removes the lease-backed row.
  • Legacy and unmanaged session rows remain visible.
  • A request-derived row is suppressed when its connection is already represented by a held lease.
  • Existing /api/sessions fields (count, sessions, and byApiKey) retain their prior meaning. exclusiveSessions is additive, and the UI treats an absent field as an empty array.

Architecture and safety

The implementation reuses:

  • getExclusiveLeaseConnectionIds() for the API-key managed-connection policy;
  • getExclusiveLeaseOccupancy() for authoritative current SQLite occupancy;
  • existing pending-request accounting only as the in-flight-work signal;
  • the existing /api/sessions route, SessionsTab, getAccountDisplayName(), localized labels, and dashboard styles.

It adds no session/lease store, table, migration, router, pool, daemon, waiter, quota/health/cooldown state, or client-specific mapping. Request tracking does not create, renew, release, invalidate, or otherwise mutate a lease.

The dashboard projection contains no raw lease-owner header, owner hash, API-key ID, generation/fencing material, credential, or token. Provider display metadata is read through a credential-free DB helper and formatted by the existing display-name resolver.

Prior-art / duplicate search

Open and closed issues and PRs, discussions, commit search, current code, and recent relevant path history were searched for:

  • exclusive lease dashboard
  • exclusive managed session UI
  • session lease observability
  • active sessions lease
  • SessionsTab exclusive lease
  • idle leased session
  • managed session dashboard

The only relevant results were this PR, merged backend foundation #10362, issue #10514, and discussion #10378. No duplicate or newer upstream dashboard solution was found. Maintainer discussion on #10362 explicitly identified dashboard UI as a possible follow-up.

Files changed

  • src/app/api/sessions/route.ts
  • src/app/(dashboard)/dashboard/usage/components/SessionsTab.tsx
  • src/lib/sessionObservability.ts
  • src/lib/db/providers.ts
  • tests/unit/exclusive-session-observability.test.ts
  • tests/unit/ui/exclusive-session-observability-ui.test.tsx
  • changelog.d/features/11389-exclusive-managed-session-dashboard.md

Validation on Ubuntu / Node 24.18.1

  • Projection, official SQLite lifecycle, API compatibility, sanitization, and privacy: 5 passed, 0 failed.
  • Actual jsdom/Vitest SessionsTab rendering: 3 passed, 0 failed.
  • Existing exclusive-lease, managed-key, session-manager/sweep, pending-request, request-logger, and management-auth regressions: 170 passed, 0 failed.
  • git diff --check: pass.
  • Prettier on all touched files: pass.
  • ESLint on all touched TypeScript/TSX files: pass.
  • typecheck:core: pass.
  • Dashboard typecheck ratchet: pass (220 frozen pre-existing diagnostics; no regression).
  • Changelog integrity, cycles, DB rules, error-helper, complexity, cognitive-complexity, file-size, build-scope, test-discovery, tracked-artifact, and commit-hook gates: pass.
  • Current supported production build (npm run build, Next.js 16.3.1 Turbopack): pass. Its warnings point to untouched paths.
  • Isolated runtime smoke on 127.0.0.1:32189 and a temporary DATA_DIR: official HTTP acquire made an idle lease visible in /api/sessions; renew kept it visible; release and real TTL expiry removed it. The final traced run recorded no outbound IP connections.

External provider/model dispatches: 0. No /v1/responses, /v1/chat/completions, or other model execution endpoint was called.

Remaining limitations / base status

  • Validation was focused to the touched and authoritative lease/session paths rather than the entire repository test matrix.
  • The optional gitleaks binary was unavailable, so the repository's secret gate reported its designed non-blocking skip; the tracked-artifact and source privacy assertions passed.
  • The report-only forgotten-sibling calibration gate passed with broad advisory findings caused by changing the widely imported provider DB module; it reported no masking/deletion risk.
  • No open release/v3.8.51 base-red marker was found, and the supported production build passed at base SHA 3192eb88d5550de4c3fd9985564f6b5641e9d681.

Refs #10514

Follow-up to #10362

KaspaPulse added a commit to KaspaPulse/omniroute-session-lease that referenced this pull request Aug 24, 2026
Complete the dashboard observability follow-up for Exclusive Managed Session Leasing from diegosouzapw#10362 without changing lease or routing semantics.

Behavior:
- every currently valid exclusive lease remains visible in the existing Sessions view across idle, tool, and build gaps;
- a leased connection with in-flight work receives the existing localized Active label;
- an idle lease remains visible but is not mislabeled inactive;
- release or TTL expiry removes the durable lease row through the official lease authority;
- legacy/unmanaged session-fingerprint rows remain visible, with duplicate rows suppressed when the same connection is currently leased.

Upstream alignment:
- diegosouzapw#10362 deliberately excluded dashboard/UI scope;
- the maintainer review on diegosouzapw#10362 explicitly identified dashboard UI as a useful follow-up;
- public issue/PR searches found no separate implementation of this Sessions/lease integration.

Architecture:
- reuse getExclusiveLeaseConnectionIds() for the managed candidate set;
- reuse getExclusiveLeaseOccupancy() as the durable lease authority;
- reuse existing pending-request accounting only to decorate a valid lease as active;
- extend the existing /api/sessions response and SessionsTab rather than adding a new store, route family, router, pool, daemon, or migration;
- never expose lease owner hashes, API-key IDs, generations, credentials, or tokens.

UI/i18n:
- use the existing common.active translation instead of hardcoded status text;
- keep idle lease rows present without inventing a new untranslated IDLE label across the 43-locale UI surface.

Validation included:
- pure projection tests for ACTIVE versus idle visibility;
- real SQLite lease acquire/occupancy/release lifecycle coverage with zero model calls;
- privacy/fencing-material assertions;
- a jsdom rendering regression proving idle rows remain visible, duplicate legacy rows are removed, and only in-flight leases receive the localized Active badge;
- a changelog fragment for PR diegosouzapw#11389.

EXTERNAL_PROVIDER_MODEL_CALLS=0 by design.

Refs diegosouzapw#10514
Follow-up to diegosouzapw#10362
@KaspaPulse
KaspaPulse force-pushed the feat/exclusive-lease-dashboard-sessions branch from ac86ca5 to eb0ec4f Compare August 24, 2026 13:02
Reuse the official exclusive-lease authority for durable idle visibility, and use pending-request accounting only for the localized active indication. Preserve legacy session fields and rows while de-duplicating leased connections and withholding lease ownership and fencing data.

Refs diegosouzapw#10514

Follow-up to diegosouzapw#10362
@KaspaPulse
KaspaPulse force-pushed the feat/exclusive-lease-dashboard-sessions branch from eb0ec4f to 85b2a06 Compare August 24, 2026 13:54
@diegosouzapw
diegosouzapw marked this pull request as ready for review August 25, 2026 00:42
@diegosouzapw
diegosouzapw self-requested a review as a code owner August 25, 2026 00:42
@diegosouzapw

Copy link
Copy Markdown
Owner

This is a model follow-up PR — the projection layer cleanly separates lease authority from observability, the DB helper stays inside src/lib/db/providers.ts with parameterized non-credential SQL, and the privacy assertions (no owner hash/generation/apiKeyId in the payload) are baked into the tests rather than promised in prose. We reproduced your results on the current release/v3.8.51 tip: the node:test suite passes 5/5 including the real SQLite acquire/renew/expiry lifecycle, and the jsdom SessionsTab render passes 3/3 under the vitest UI config. Two notes for the record: (1) the header badge now shows merged row count instead of the raw /api/sessions count — intentional per your description, but worth one line in the release notes; (2) getProviderConnectionDisplayMetadata interpolates one bind parameter per leased connection — fine at any realistic lease count, just keep it in mind if managed-connection sets ever grow into the thousands. Nothing blocking from our side.

@diegosouzapw
diegosouzapw merged commit c8ca024 into diegosouzapw:release/v3.8.51 Aug 25, 2026
20 of 24 checks passed
diegosouzapw pushed a commit that referenced this pull request Aug 26, 2026
…11469)

Validated in a combined sub-batch worktree off release/v3.8.51 tip.
- Focused test: exclusive-session-observability.test.ts — part of sub-batch's 165/165 node:test run
- typecheck:core, file-size, changelog-integrity, complexity, cognitive-complexity — all OK
- Full-repo lint: 228 pre-existing dashboard react-hooks/* findings, unrelated to this diff

Thanks for the narrow failure boundary and the privacy-conscious warning (proven not to leak the caught error's sensitive fields) — a projection failure discarding valid legacy data was a real regression from #11389.
@KaspaPulse
KaspaPulse deleted the feat/exclusive-lease-dashboard-sessions branch August 31, 2026 11:12
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
…iegosouzapw#11389)

Merged into release/v3.8.51 via batch validation: exclusive-session-observability unit+UI suites green on the combined tree, static gates green. Nice additive observability layer over the diegosouzapw#10362 lease backend — thanks @KaspaPulse!
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
…iegosouzapw#11469)

Validated in a combined sub-batch worktree off release/v3.8.51 tip.
- Focused test: exclusive-session-observability.test.ts — part of sub-batch's 165/165 node:test run
- typecheck:core, file-size, changelog-integrity, complexity, cognitive-complexity — all OK
- Full-repo lint: 228 pre-existing dashboard react-hooks/* findings, unrelated to this diff

Thanks for the narrow failure boundary and the privacy-conscious warning (proven not to leak the caught error's sensitive fields) — a projection failure discarding valid legacy data was a real regression from diegosouzapw#11389.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants