Skip to content
Snippets Groups Projects
Commit a0a93185 authored by ale's avatar ale
Browse files

improve logging of auth events

parent 9f2bc780
No related branches found
No related tags found
No related merge requests found
...@@ -31,18 +31,22 @@ def api_auth(): ...@@ -31,18 +31,22 @@ def api_auth():
check_ratelimit(request, username, source_ip) check_ratelimit(request, username, source_ip)
try: try:
result, errmsg, unused_shard = do_auth( auth_status, errmsg, unused_shard = do_auth(
username, service, shard, password, otp_token, source_ip) username, service, shard, password, otp_token, source_ip)
except Exception, e: except Exception, e:
app.logger.exception('Unexpected exception in authenticate()') app.logger.exception('Unexpected exception in authenticate()')
abort(500) abort(500)
app.logger.info( # Build a nice log message.
'AUTH %s %s %s otp=%s%s', log_parts = [username, service, auth_status]
username, service, result, otp_token and 'y' or 'n', log_parts.append('otp=%s' % (otp_token and 'y' or 'n'))
(' err=%s' % errmsg) if errmsg else '') if shard:
log_parts.append('shard=%s' % shard)
if errmsg:
log_parts.append('err=%s' % errmsg)
app.logger.info('AUTH %s', ' '.join(log_parts))
response = make_response(result) response = make_response(auth_status)
response.headers['Cache-Control'] = 'no-cache' response.headers['Cache-Control'] = 'no-cache'
response.headers['Content-Type'] = 'text/plain' response.headers['Content-Type'] = 'text/plain'
response.headers['Expires'] = '-1' response.headers['Expires'] = '-1'
......
...@@ -40,10 +40,12 @@ def do_nginx_http_auth(): ...@@ -40,10 +40,12 @@ def do_nginx_http_auth():
app.logger.exception('Unexpected exception in authenticate()') app.logger.exception('Unexpected exception in authenticate()')
abort(500) abort(500)
app.logger.info( log_parts = [username, service, auth_status]
'NGINX_AUTH %s %s %s shard=%s%s', if shard:
username, service, auth_status, shard, log_parts.append('-> shard=%s' % shard)
(' err=%s' % errmsg) if errmsg else '') if errmsg:
log_parts.append('err=%s' % errmsg)
app.logger.info('NGINX_AUTH %s', ' '.join(log_parts))
response = make_response('') response = make_response('')
if auth_status == 'OK': if auth_status == 'OK':
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment