<img width="2284" height="2028" alt="CleanShot 2026-05-01 at 18 53
50@2x"
src="https://github.com/user-attachments/assets/4f58cbb1-0168-40fb-a523-017f2ba625a1"
/>
## Performance
- **Per-request DB hit**: `getUserId` runs `getEffectiveSessionDuration`
(User lookup + Org `aggregate`) on *every* authenticated request,
including each fetcher poll. Consider caching the effective duration in
the session cookie with a short TTL (e.g. 60s) and revalidating in the
background.
- **Double session commit in `root.tsx`**: `getUser` already runs the
expiry check; then `commitAuthenticatedSessionLazy` commits the cookie
again. Fine, but doubles `Set-Cookie` headers on every page load — worth
a quick perf check.
## Correctness / Edge cases
- **Lazy backfill assumes a root.tsx hit first**: users whose first
post-deploy request is a fetcher/API route (`/resources/*`) skip the
backfill until they navigate to a page. Not a security hole, but
`getUserId` could backfill itself for completeness.
- **No upper bound on `Organization.maxSessionDuration`**: admin API
accepts `1` second, which would instant-logout every member on next
request. Add a `min(60)` (or `min(300)` to match the lowest user option)
to the Zod schema.
- **No clock-skew tolerance**: `isSessionExpired` is exact-millisecond.
Multi-instance deploys with skewed clocks could log users out a few
seconds early/late. Probably fine for the 5-min minimum, but worth
noting.
## Security
- **Auto-logout audit log lacks IP/orgId**: HIPAA forensics typically
wants source IP and which org context. Currently logs only `userId` +
path. IP isn't PII for audit purposes; orgIds help correlate. Add both.
- **Cookie `Max-Age` is 1 year regardless of user's setting**:
intentional (server-side `issuedAt` is the source of truth), but
reviewers will ask. Add a one-line comment on the cookie config
explaining why.
## API surface
- **`maxSessionDuration` is admin-PAT only**: no in-app UI for org
owners to set/change their own cap. If this is "Trigger staff sets it
during HIPAA onboarding", say so in the PR description; otherwise add an
org-settings UI.
- **Auto-submit dropdown has no confirmation**: misclicking "5 minutes"
immediately shortens the user's session window with no undo. Consider a
save button or 3-sec undo toast.
## Schema / migration
- **`User.sessionDuration NOT NULL DEFAULT 31556952`**: instant on PG
11+ (metadata-only), but call out in the PR description so reviewers
don't worry about a table rewrite on the User table.
- **No DB-level constraint matching `SESSION_DURATION_OPTIONS`**: if the
option list changes, existing users keep orphaned values. The dropdown's
tag-along behaviour hides this — fine for now, but if you ever drop an
option you'll need a backfill.
## UX
- **Session expiry only fires on next request**: an idle authenticated
tab keeps showing UI past the cap (until SSE/polling catches it, ~60s).
Add a client-side timer based on the user's effective duration that
triggers a fetcher to `/account` or `/logout` at expiry.
- **No "you were signed out" message on logout**: users hitting their
cap are bounced to `/` with no explanation. Was intentionally reverted
in this PR — call that out so reviewers don't request it.
## Tests
- Unit coverage on `sessionDuration.server.ts` is solid (215 lines).
Missing: integration test for `getUserId` → expired session → redirect
to `/logout`, and one for the loader's clamping fix (the most recent
bug). Add at least the second one to lock in the regression.
---------
Co-authored-by: Matt Aitken <matt@mattaitken.com>
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
* Add schemas for gh app installations
* Implement gh app installation flow
* Make the gh app configs optional
* Add additional org check on gh app installation callback
* Save account handle and repo default branch on install
* Do repo hard deletes in favor of simplicity
* Disable github app by default
* Fix gh env schema union issue
* Use octokit's iterator for paginating repos
* Parse gh app install callback with a discriminated union
* Remove duplicate env vars
* Use bigint for github integer IDs
* Sanitize redirect paths in the gh installation and auth flow
* Regenerate migration after rebase on main to fix ordering
* Handle gh install updates separately from new installs
* Added ProjectVersion to projects, defaults to V2
* Moved v3Enabled to the existing feature flags
* Update to using the v3Enabled feature flag
* Allow people to choose v3 when creating a new project
* Added version to the ProjectPresenter
* v2 project and v3 project redirecting
* .env.example for the v3-catalog
* Added sdkVersion and cliVersion columns to the BackgroundWorker table
* Added additional classes for environments
* First draft of the Tasks table
* Link to the task page
* V3 side menu project items
* Moved the ListPagination component into the components folder
* Moved the TaskListPresenter to a v3 folder
* Bare bones task page with tabs
* Task page, we’re going to delete this though
* Bare bones runs table working
* Rejigged the columns
* The run table status
* Environment and status filtering working
* Added time filters
* Cursor and direction is working… I think it’s tricky to know for sure
* Added TaskRun numbers
* Selecting a task now links to the runs page with filters turned on
* Added support for the enqueued status
* Reworked the task table
* Link to the task and environment runs
* The run page is rendering a tree of the events
* Change the task table column to “Created at"
* WIP on making the run tree view look good
* Improvements to the run tree
* Removed the janky scroll bar flash
* Change the title of the task logs to just the task ID
* Live timer when a span is running
* Added “Show parent items” link
* Fixed the bug jumping to parent items
* Style improvements to the run
* Added the resizable handle to the run page
* Moved formatDuration to core/v3
* Wait for now has nice log messages
* The run detail panel is working with just a title for now
* Navigating to a span and persisting between page reloads is working
* The run detail timeline
* Wrap log dates in a paragraph
* Latest span detail view
* Scrolling in the right-hand panel
* Tweak default resizable layout for the run page
* Attempted improvements to stop a recursive issue on TreeView
* TreeView useReducer WIP
* Changed the change callback
* Add changes to the state
* Use the new onSelectedIdChanged in the app
* Don’t update the state from the outside
* Filtering fix, although navigation doesn’t work nicely
* Filtering working when changing the content and clearing it
* Don’t allow the same selectedId callback to be called twice…
* useDebounce hook
* Switch from using defer to just typedjson for now
* Latest attempt at span navigation
* Removed log
* Turn off filtering for now, it’s causing the Links to break somehow
* Fix for page height issue
* Added (Developer Preview) to the v3 project select box
* Revert "Filtering working when changing the content and clearing it"
This reverts commit 20d9fbe36ded619e9d3eb0b23d4ed0568a88a615.
# Conflicts:
# apps/webapp/app/components/primitives/TreeView/TreeView.tsx
* Switch to using the old filtering
* Added useThrottle hook
* Instantly close the panel when deselecting a node, use debounce when navigating to a span
* Better spacing in the right hand panel
* Comment out the v3 side menu pages that don’t exist yet
* Fix for typecheck fail
* Clear the statuses too
* Initial commit - started work on new billing components
* Added a slider component
* Added features to the pricing tiers
* Small pricing tier margin tweaks
* WIP on a concurrecy chart
* Reworked the pricing tiers to include a segmented controller and tooltips
* Renamed the charts storybook page
* Made the way data is added more flexible and added some definition tool tips
* Term definitions are used properly in the tiers
* Callouts can now have an optional CTA on the right hand side
* Alignment fix for the callouts
* organize imports
* Definition tooltip now its own component
* renamed the storybook story
* WIP new volume discount table and usage sliders
* Added pricing calculator sliders
* Fixed alignment of the legend
* Breadcrumb now has an upgrade prompt and button
* New Join our Slack button in the side menu
* New progress meter in the side menu
* Use the highest of 2 values to show progress
* An attempt to fix the step count in the calculator slider
* WIP usage progress bar
* Added the 4 progress bars
* More examples of the usage bar
* Better way to include the percentage in the free plan progress meter
* The usage bar now works with the extra runs over the free limit
* Pricing calculator has better slider logic
* Moved the free plan usage bar into it’s own component and added it to storybook
* Usage bar chart now supports a paying customer option and optional billing limit. Also added more usage examples to storybook
* Added more examples of usage to storybook
* tooltip takes classname
* Format numbers nicely
* Added a tooltip to show the precise numbers in the chart
* small improvements to the billing calculator
* New onboarding choose plan page
* pricing tiers better fill the size of their container
* Removed unused code
* Usage bars animate
* Wording tweak
* Callouts fit the button size better
* Added new routes for the 2 new billing pages
* import cleanup
* Added meta info in the header for bill price, plan type and billing period
* made free a noun
* Added pricing calculator to the plans page
* Fixed some illegal markup when using tooltips
* Added container query support
* Added new concurrency chart to the usage page
* billing now has a green theme
* Simplified the plan summary info int the header
* Fixed padding alignment
* Use a custom lable for the concurrent runs chart
* Removed the Job runs table
* Latest lockfile
* Show a message if you haven’t done runs yet
* Added a layoutId to the pageTabs
* Show a message callout if you’ve exceeeded 10k runs on the free plan
* Added a callout on the plans page if you’re over the runs limit
* Fixed button inside button bug
* Removed the background gradients from the app
* The billing package is importing properly
* Getting the curent plan for an org
* Reading the current plan and usage
* Hooked up the free plan bar
* Render basic billing details
* vol discount table has optional values
* Added a new page to show new subscribers
* Created a new hook for confetti on the subscribed page
* Toast styling updated
* The Invoice and Manage card details links are working
* Meta appEnv data optional
* Data for the plans page
* Format the billing period duration in days
* Switch to 20 icons
* URL for the subscribed page now includes the org path
* New pathBuilder path for the subscribed page
* Plans are upgraded/downgraded successfully
* Fixed badly named paths
* Improved some of the display
* Deal with when the user has canceled so they can re-upgrade
* Subscribing from Stripe is working, and canceling
* Tidied up some bits, latest billing package
* The tiers are now rendering using the real data
* The onboarding screen is hooked up, but not linked to yet
* Onboarding price selection working
* Pricing slider working
* Price estimation working
* Pricing calculator working on the select a plan page
* Button copy change
* Improved the layout of the run calculator marker
* Fix for the period end when you’ve canceled
* Improved the formatting in the calculator
* Pricing table tooltip uses the vol discount pricing table
* Remove the vertical lines from the calculator
* Contact us button in Enterprise tier opens the contact us form
* Added composite index to triggerdotdev_events.run_executions for event_time and organization_id
* Concurrent run chart data
* Improves styling, fix for React error with Enterprise contact button
* Show warning box when you’ve hit the concurrency in the past 30 days
* Lots of work o the usage page
* Improvements to the usage page
* Show 31 days of data, fix for not showing the current date…
* Stripe portal links are generated when the user clicks through
* Better alignment of the reference line and x-axis label
* Readme update
* Fixed pricing button loading buttons
* Show warnings about concurrency and runs on the plans page
* Removed some storybook stories
* Join Slack channel shows if you’re subscribed with instructions
* Added a gap between the runs charts
* Improved the definitions
* Added some margin to the page loading spinner
* A wider, cleaner feedback panel
* Modal backgrounds match the Sheet style
* Fixed menu item text being clipped
* Improved icons for execution time and exclusion count
* Concurrency chart now renders the dates nicely
* Fix for plans data on the plans page
* The healthcheck doesn’t need to do a HEAD request to /
* Better disabled states and fixed the disabled hover state issue
* Improved the segmented controller style
* loading spinner now centered inside the button
* Redirect to the project page when selecting the free plan
* Fix for “Runs” and added real date to upgrade warning
* DeCAPITALIZED some things
---------
Co-authored-by: James Ritchie <james@jamesritchie.co.uk>
* WIP execution concurrency controls implemented via Redis
- Split up resuming a run and executing a run
- Added some new statuses to better show what is going on in a run
- Removed preprocessing runs
* WIP
* Convert to using ZSETs and adding env vars
* Removed unused import
* Improve run number generation using advistory locks, and only on start
* More execution concurrency stuff
* Add support for job concurrency limits and concurrency limit groups
* Create wild-swans-battle.md
* Increase slots refresh timeout to 10s
* Try to fix Redis connection issues
* Don’t be so strict about the APP_ENV
* Add the blank tls option to the normal redis client as well
* Add docs
* Setup project-wide prettier
* Remove old workspace file
* Remove old debugging directives
* New top-level .prettierignore
* Updated Prettier config settings
* Contrubuting guide: Fix for some bad code blocks
* Added more ignores
* Improved the format script command
* printWidth set to 100
* Formatted entire repo (pnpm run format)