2026-10-10-auth-key-last-used-nullable
title: A session key's lastUsedAt is null until its first use affects: dartway_core_shared: "0.21.0-dev.17" dartway_core_server: "0.21.0-dev.17"
Who is affected
A project that reads DwSessionKeyInfo.lastUsedAt — from ctx.sessionKey, listKeys, or a
DwSessionKeyInfo it sends to its own app — or builds a DwSessionKeyInfo itself. The field is now
DateTime?: null until the key's first use, which is always recorded. The framework migration
20261009_000003_dw_auth_key_last_used sets it to NULL on every key whose last_used_at still
equals its created_at, so a key used only within its first keyTouchInterval before the upgrade
reads as never used.
What to change
-
Where the code compares
lastUsedAtwithcreatedAtto tell an unused key, ask the field:- final lastUsed = key.lastUsedAt.isAtSameMomentAs(key.createdAt) ? null : key.lastUsedAt;+ final lastUsed = key.lastUsedAt; // or key.isUsed -
Every other read of
lastUsedAthandlesnull— the compiler names each one. -
A query of the project's own on
dw_auth_key.last_used_atexpectsNULLfor a key never used.
How to check
The project compiles; a key issued and not yet used shows lastUsedAt == null, and after one call
with it a value.