fix(audit): 审计按账号 id 归属并记录来源 IP/UA,登录失败与限速入审计和指标,写入失败计数告警

This commit is contained in:
Lemon-miaow committed 2026-09-24 16:02:44 +08:00
1 parent c4e4953f3d
commit 857c73a66a
39 files changed
+794 -161

No files matched your search

+29
View File
@@ -81,6 +81,32 @@ var (
Name: "rate_limited_total",
Help: "Requests refused by a volumetric rate limit, by scope.",
}, []string{"scope"})
// AuthFailuresTotal counts refused sign-in attempts by door (login_email,
// op_login, passkey, passkey_discoverable, setup_redeem, bind_redeem) and
// reason (bad_code, no_account, staff_account, bad_credential, ...). A few a
// day is people mistyping; a steady stream is guessing or enumeration.
AuthFailuresTotal = prometheus.NewCounterVec(prometheus.CounterOpts{
Namespace: namespace,
Name: "auth_failures_total",
Help: "Refused sign-in attempts, by door and reason.",
}, []string{"door", "reason"})
// SessionsRevokedTotal counts sessions ended before expiry, by who ended
// them: logout (the holder) or admin (the owner revoking a user's sessions).
SessionsRevokedTotal = prometheus.NewCounterVec(prometheus.CounterOpts{
Namespace: namespace,
Name: "sessions_revoked_total",
Help: "Sessions revoked before expiry, by who revoked them.",
}, []string{"by"})
// AuditWriteFailuresTotal counts audit rows the API failed to write. The
// action went through; only its record was lost.
AuditWriteFailuresTotal = prometheus.NewCounter(prometheus.CounterOpts{
Namespace: namespace,
Name: "audit_write_failures_total",
Help: "Audit rows the API failed to write.",
})
)
// OTPPurposes are the email-code doors OTPLockoutsTotal is labelled by.
@@ -135,6 +161,9 @@ func Collectors() []prometheus.Collector {
OTPLockoutsTotal,
MailTotal,
RateLimitedTotal,
AuthFailuresTotal,
SessionsRevokedTotal,
AuditWriteFailuresTotal,
}
}