Commit f6ea17ed authored by Stan Hu's avatar Stan Hu

Merge branch '62756-include-user-info-in-access-logs' into 'master'

Include username in auth log

Closes #62756

See merge request gitlab-org/gitlab-ce!29821
parents 851d19c2 fc85b07a
...@@ -4,12 +4,22 @@ ...@@ -4,12 +4,22 @@
ActiveSupport::Notifications.subscribe('rack.attack') do |name, start, finish, request_id, req| ActiveSupport::Notifications.subscribe('rack.attack') do |name, start, finish, request_id, req|
if [:throttle, :blacklist].include? req.env['rack.attack.match_type'] if [:throttle, :blacklist].include? req.env['rack.attack.match_type']
Gitlab::AuthLogger.error( rack_attack_info = {
message: 'Rack_Attack', message: 'Rack_Attack',
env: req.env['rack.attack.match_type'], env: req.env['rack.attack.match_type'],
ip: req.ip, ip: req.ip,
request_method: req.request_method, request_method: req.request_method,
fullpath: req.fullpath fullpath: req.fullpath
) }
if req.env['rack.attack.matched'] != 'throttle_unauthenticated'
user_id = req.env['rack.attack.match_discriminator']
user = User.find_by(id: user_id)
rack_attack_info[:user_id] = user_id
rack_attack_info[:username] = user.username unless user.nil?
end
Gitlab::AuthLogger.error(rack_attack_info)
end end
end end
...@@ -102,6 +102,27 @@ describe 'Rack Attack global throttles' do ...@@ -102,6 +102,27 @@ describe 'Rack Attack global throttles' do
expect_rejection { get(*get_args) } expect_rejection { get(*get_args) }
end end
it 'logs RackAttack info into structured logs' do
requests_per_period.times do
get(*get_args)
expect(response).to have_http_status 200
end
arguments = {
message: 'Rack_Attack',
env: :throttle,
ip: '127.0.0.1',
request_method: 'GET',
fullpath: get_args.first,
user_id: user.id,
username: user.username
}
expect(Gitlab::AuthLogger).to receive(:error).with(arguments).once
expect_rejection { get(*get_args) }
end
end end
context 'when the throttle is disabled' do context 'when the throttle is disabled' do
...@@ -189,7 +210,15 @@ describe 'Rack Attack global throttles' do ...@@ -189,7 +210,15 @@ describe 'Rack Attack global throttles' do
expect(response).to have_http_status 200 expect(response).to have_http_status 200
end end
expect(Gitlab::AuthLogger).to receive(:error).once arguments = {
message: 'Rack_Attack',
env: :throttle,
ip: '127.0.0.1',
request_method: 'GET',
fullpath: '/users/sign_in'
}
expect(Gitlab::AuthLogger).to receive(:error).with(arguments)
get url_that_does_not_require_authentication get url_that_does_not_require_authentication
end end
...@@ -345,7 +374,17 @@ describe 'Rack Attack global throttles' do ...@@ -345,7 +374,17 @@ describe 'Rack Attack global throttles' do
expect(response).to have_http_status 200 expect(response).to have_http_status 200
end end
expect(Gitlab::AuthLogger).to receive(:error).once arguments = {
message: 'Rack_Attack',
env: :throttle,
ip: '127.0.0.1',
request_method: 'GET',
fullpath: '/dashboard/snippets',
user_id: user.id,
username: user.username
}
expect(Gitlab::AuthLogger).to receive(:error).with(arguments).once
get url_that_requires_authentication get url_that_requires_authentication
end end
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment