Skip to content

Add active API key count to profile response - #651

Merged
thomasluizon merged 2 commits into
redesign/mainfrom
feature/ticket-919-api-key-count
Sep 29, 2026
Merged

thomasluizon merged 2 commits into
redesign/mainfrom
feature/ticket-919-api-key-count

Conversation

@thomasluizon

@thomasluizon thomasluizon commented Sep 29, 2026 •

Copy link
Copy Markdown
Owner

Change

Adds optional activeApiKeyCount to ProfileResponse in src/Orbit.Application/Profile/Queries/GetProfileQuery.cs. The profile handler uses the existing API key repository count operation with the authenticated profile user ID. It excludes revoked keys and keys whose UTC expiry has passed. The API key list and its emailed code requirement remain in place.

Regenerates src/Orbit.Api/openapi.json for the appended response field. Updates the profile handler tests in tests/Orbit.Application.Tests/Queries/Profile/GetProfileQueryHandlerTests.cs and the constructor setup in tests/Orbit.Application.Tests/Behaviors/ColorSchemeRoundTripTests.cs.

The count query runs in the database and returns only an integer. The profile response exposes no API key name, prefix, secret, or date.

An active key is one that is neither revoked nor expired. One shared predicate defines it for both the profile count and the five-key creation limit, so expired keys no longer block creating a new key.

Links thomasluizon/orbit-tickets#919.

Assumptions

  • Used the optional profile response field instead of a dedicated GET because the existing profile request serves the drawn value and the repository already supports a count query.
  • Treats a key whose expiry equals the current UTC instant as inactive instead of counting it until a later request.
  • Used a shared expression predicate in the application layer instead of adding a count operation to the generic repository.

Test evidence

  • dotnet test tests/Orbit.Application.Tests --filter FullyQualifiedName~GetProfileQueryHandlerTests.Handle_UserFound_ReturnsProfile --no-restore exited 0 with the existing test before the change.
  • A failing strengthened run before implementation was not captured because the new field and its test were added together. No such failure is claimed.
  • dotnet test tests/Orbit.Application.Tests --filter FullyQualifiedName~GetProfileQueryHandlerTests --verbosity quiet passed all 34 tests, including zero, one, and several active keys with revoked, expired, and foreign account keys excluded.
  • dotnet build Orbit.slnx --verbosity quiet completed with zero errors.
  • dotnet test --verbosity quiet passed all 8,068 tests.
  • Existing focused tests, unchanged and with the defect present: dotnet test tests/Orbit.Application.Tests --filter 'FullyQualifiedName~CreateApiKeyCommandHandlerTests|FullyQualifiedName~GetProfileQueryHandlerTests.Handle_CountsOnlyCallersActiveApiKeys' --no-restore exited 0; 10 passed.
  • New Handle_CountsOnlyCallersActiveKeysAgainstLimit theory: dotnet test tests/Orbit.Application.Tests --filter 'FullyQualifiedName~CreateApiKeyCommandHandlerTests.Handle_CountsOnlyCallersActiveKeysAgainstLimit' --no-restore exited 1 before the fix. All four cases failed because expired keys were counted.
  • After the fix, the focused command and profile tests exited 0; 14 passed. env -u LANG LC_ALL=en_US.UTF-8 dotnet build Orbit.slnx exited 0 with zero errors. dotnet test Orbit.slnx exited 0; 8,072 tests passed.

Manual steps

None.

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Important

The profile reports fewer active API keys than the creation limit counts when keys have expired, so users can be told they have capacity but still be rejected when creating a key.

Reviewed changes: Reviewed the optional profile API key count, its OpenAPI schema, and handler tests against the key lifecycle and the mobile consumer contract.

  • Profile response: Appends a nullable count and queries unrevoked, unexpired keys owned by the profile user.
  • Contract and tests: Regenerates OpenAPI and exercises count filtering and JSON serialization; updates the color scheme test fixture for the new dependency.

Pullfrog  | Fix all ➔ | Fix 👍s ➔ | View workflow run | Using GPT Sol | 𝕏

Comment thread src/Orbit.Application/Profile/Queries/GetProfileQuery.cs Outdated

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ No new issues found.

Reviewed changes: Re-reviewed the active API key creation limit and its tests since the previous Pullfrog review.

  • Aligned quota: Shared the active-key predicate between the profile count and the creation limit, so expired keys no longer consume capacity.
  • Covered key states: Added exact-count tests for active, expired, revoked, and other-account keys at the creation limit.

Pullfrog  | View workflow run | Using GPT Sol | 𝕏

@thomasluizon
thomasluizon merged commit 4a2032c into redesign/main Sep 29, 2026
22 checks passed
@thomasluizon
thomasluizon deleted the feature/ticket-919-api-key-count branch September 29, 2026 04:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant