All checks were successful
Release / Test backend (push) Successful in 29s
Release / Check ui (push) Successful in 41s
Release / Docker / caddy (push) Successful in 50s
Release / Docker / ui (push) Successful in 2m8s
Release / Docker / backend (push) Successful in 3m17s
Release / Docker / runner (push) Successful in 3m13s
Release / Gitea Release (push) Successful in 12s
OAuth callbacks were creating a new session record on every login from the same device because user-agent/IP were hardcoded as empty strings, producing a pile-up of 6+ identical 'Unknown browser' sessions. - Add upsertUserSession(): looks up existing session by user_id + device_fingerprint (SHA-256 of ua::ip, first 16 hex chars); reuses and touches it (returning the same authSessionId) if found, creates a new record otherwise - Add device_fingerprint field to UserSession interface - Fix OAuth callback to read real user-agent/IP from request headers (they are available in RequestHandler via request.headers) - Switch both OAuth and password login to upsertUserSession so the returned authSessionId is used for the auth token - Extend pruneStaleUserSessions to also cap sessions at 10 per user - Keep createUserSession as a deprecated shim for gradual migration