Commit graph

4 commits

Author SHA1 Message Date
61531e524f Audit only intentional auth actions, not automatic 401/403 gates.
Stop recording unauthorized/forbidden/password-gate and silent refresh; keep login, logout, and failed-login style events.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-01 21:51:59 +08:00
d35d3992c2 Dedupe auth.unauthorized floods from unauthenticated page loads.
Keep one 401 audit per IP+path window, and hide historical unauthorized noise from the default business view.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-01 21:48:18 +08:00
ea3d45ddc2 Stop auditing successful auth.me and auth.sessions polls.
These are UI session checks that flooded the business audit view; keep failures only.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-01 21:44:52 +08:00
c181158209 Drop HTTP polling noise from operation audit by default.
Persist only business events and mutating/failed HTTP calls, and default the audit UI to a business view with an explicit HTTP filter.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-09-01 21:41:05 +08:00