Dedupe auth.unauthorized floods from unauthenticated page loads.

Keep one 401 audit per IP+path window, and hide historical unauthorized noise from the default business view.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
oliver 2026-09-01 21:48:18 +08:00
parent ea3d45ddc2
commit d35d3992c2
5 changed files with 82 additions and 10 deletions

View file

@ -60,5 +60,33 @@ class AuditShouldPersistTests(unittest.TestCase):
self.assertFalse(audit_should_persist(action="ume.token.get", method="GET", status_code=200))
class UnauthorizedDedupeTests(unittest.TestCase):
def setUp(self) -> None:
from netx_api import audit_async as aa
with aa._unauth_lock:
aa._unauth_recent.clear()
def test_dedupes_same_ip_path(self) -> None:
from netx_api.audit_async import should_audit_unauthorized
self.assertTrue(
should_audit_unauthorized(client_ip="127.0.0.1", method="GET", path="/v1/topology")
)
self.assertFalse(
should_audit_unauthorized(client_ip="127.0.0.1", method="GET", path="/v1/topology")
)
# Different path still recorded once.
self.assertTrue(
should_audit_unauthorized(client_ip="127.0.0.1", method="GET", path="/v1/managed-ne")
)
def test_different_ip_not_deduped(self) -> None:
from netx_api.audit_async import should_audit_unauthorized
self.assertTrue(should_audit_unauthorized(client_ip="1.1.1.1", method="GET", path="/v1/x"))
self.assertTrue(should_audit_unauthorized(client_ip="2.2.2.2", method="GET", path="/v1/x"))
if __name__ == "__main__":
unittest.main()