Audit only intentional auth actions, not automatic 401/403 gates.

Stop recording unauthorized/forbidden/password-gate and silent refresh; keep login, logout, and failed-login style events.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
oliver 2026-09-01 21:51:59 +08:00
parent d35d3992c2
commit 61531e524f
5 changed files with 35 additions and 127 deletions

View file

@ -153,19 +153,7 @@ def api_refresh(
detail={},
)
raise
user = out.get("user") or {}
write_audit(
db,
action="auth.refresh",
actor_user_id=str(user.get("id") or ""),
actor_username=str(user.get("username") or ""),
method="POST",
path="/v1/auth/refresh",
status_code=200,
client_ip=ip,
user_agent=ua,
detail={},
)
# Successful silent token refresh is not an operator action — skip audit.
return _token_response(response, request, out)