feat(console): add batch workspace block endpoints - #48491
Merged
Conversation
Contributor
|
This PR doesn't fully meet our contributing guidelines and PR template. What needs to be fixed:
Please edit this PR description to address the above within 2 hours, or it will be automatically closed. If you believe this was flagged incorrectly, please let a maintainer know. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Workspace.blockBatch/Workspace.unblockBatchtopackages/console/core/src/workspace.ts: setis_blockedfor an arbitrary list of workspace IDs in one call, reporting{ blocked | unblocked, notFound }per itemSUPPORT_API_KEYbearer auth:POST /api/support/actions/block-workspaces— body{ "workspaceIDs": ["wrk_...", ...] }POST /api/support/actions/unblock-workspaces— same shape, the rollback path for a mistaken batchMotivation
Fraud response regularly needs to block hundreds of workspaces at once. Calling the existing single-workspace endpoint per ID means hundreds of round trips from the caller and hundreds of separate UPDATE statements. This endpoint takes the whole list in one request and reports per-item results.
Design
INlists degrade on Vitess, so the core chunks the work into fixed groups of 500 executed sequentially inside oneDatabase.use— sequential keeps the statements on one connection inside ambient transactions.CLIENT_FOUND_ROWS), sorowsAffectedcannot distinguish "already blocked" from "missing" — the select can.notFoundwith HTTP 200 and the full result body. This deliberately differs from the single endpoints' not-found → 400; two stale IDs should not discard 298 successful blocks. The caller (the OpenCode support agent, see the companion PR) surfacesnotFoundfor operator follow-up.Usage
200—{"success":true,"message":"Workspaces blocked","result":{"blocked":[...],"notFound":[...]}}400— invalid body (empty list, non-wrk_IDs)401— missing/incorrect support keyRelated
block-workspaceendpoint); no shared code paths.anomalyco/experiments#567); that PR executes 404 →faileduntil this endpoint merges and deploys, so this PR should land first.