fix(audit): 审计按账号 id 归属并记录来源 IP/UA,登录失败与限速入审计和指标,写入失败计数告警

This commit is contained in:
Lemon-miaow committed 2026-09-24 16:02:44 +08:00
1 parent c4e4953f3d
commit 857c73a66a
39 files changed
+794 -161

No files matched your search

+1 -6
View File
@@ -61,12 +61,7 @@ func (a *API) noteOTPLock(r *http.Request, err error, userID, purpose string) {
payload, _ := json.Marshal(map[string]any{
"user_id": userID, "purpose": purpose, "until": lock.Until.UTC(), "failures": otpFailureBudget,
})
if aerr := a.Repo.Audit(ctx, AuditEntry{
Actor: actor, Source: "external", Action: "auth.otp.locked",
RequestID: requestIDFromContext(ctx), Payload: payload,
}); aerr != nil {
log.Printf("auth: audit of otp lock for user %s failed: %v", userID, aerr)
}
a.auditEntry(r, AuditEntry{Actor: actor, ActorUserID: userID, Action: "auth.otp.locked", Payload: payload})
door, notify := otpDoorName[purpose]
if !notify || uerr != nil || u.Email == "" {