fix: 独立审计日志并补齐令牌身份与失败记录
This commit is contained in:
@@ -40,12 +40,12 @@ func (h *Handler) handleRegistrationPut(w http.ResponseWriter, r *http.Request)
|
||||
Generate bool `json:"generate"`
|
||||
}
|
||||
if err := httpx.DecodeJSON(r, &req); err != nil {
|
||||
h.audit(actorString(p), "registration_update", "", "bad_request", ip)
|
||||
h.auditP(p, "registration_update", "", "bad_request", ip)
|
||||
httpx.WriteError(w, http.StatusBadRequest, "bad_request", "请求体无效")
|
||||
return
|
||||
}
|
||||
if req.Enabled == nil && req.Code == nil && !req.Generate {
|
||||
h.audit(actorString(p), "registration_update", "", "bad_request", ip)
|
||||
h.auditP(p, "registration_update", "", "bad_request", ip)
|
||||
httpx.WriteError(w, http.StatusBadRequest, "bad_request", "至少提供一项更新")
|
||||
return
|
||||
}
|
||||
@@ -108,23 +108,33 @@ func (h *Handler) handleRegistrationPut(w http.ResponseWriter, r *http.Request)
|
||||
if err != nil {
|
||||
var br badRequestError
|
||||
if errors.As(err, &br) {
|
||||
h.audit(actorString(p), "registration_update", "", "bad_request", ip)
|
||||
h.auditP(p, "registration_update", "", "bad_request", ip)
|
||||
httpx.WriteError(w, http.StatusBadRequest, "bad_request", string(br))
|
||||
return
|
||||
}
|
||||
h.audit(actorString(p), "registration_update", "", "error", ip)
|
||||
h.auditP(p, "registration_update", "", "error", ip)
|
||||
httpx.WriteError(w, http.StatusInternalServerError, "internal", "内部错误")
|
||||
return
|
||||
}
|
||||
|
||||
data, err := h.loadRegistration(r.Context())
|
||||
if err != nil {
|
||||
h.audit(actorString(p), "registration_update", "", "error", ip)
|
||||
h.auditP(p, "registration_update", "", "error", ip)
|
||||
httpx.WriteError(w, http.StatusInternalServerError, "internal", "内部错误")
|
||||
return
|
||||
}
|
||||
// 审计不写安全码明文
|
||||
h.audit(actorString(p), "registration_update", "", "ok", ip)
|
||||
detail := map[string]any{}
|
||||
if req.Enabled != nil {
|
||||
detail["enabled"] = *req.Enabled
|
||||
}
|
||||
if req.Generate {
|
||||
detail["generated"] = true
|
||||
}
|
||||
if req.Code != nil {
|
||||
detail["code_changed"] = true
|
||||
}
|
||||
h.auditPD(p, "registration_update", "", "ok", ip, detail)
|
||||
httpx.WriteOK(w, data)
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user