telemetry: synthetic:true on canary refusals (keyed, not a bare flag)
The canary deliberately sends forged tokens every 10 min; those refusal rows read as attacks. It now sends X-Windy-Synthetic carrying a shared secret (Gitea repo secret CANARY_SYNTHETIC_KEY = WINDYGIT_SYNTHETIC_KEY in Veron .env); the API marks the row synthetic only on a constant-time match, so an attacker cannot label their own refusals synthetic to hide. synthetic is declared on forge.auth.failed (Telemetry Boss, UPDATE 3). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -71,6 +71,9 @@ class Settings(BaseSettings):
|
||||
# root-only /etc/windygit/telemetry.env on Veron, never in the repo.
|
||||
windygit_telemetry_token: str = ""
|
||||
telemetry_ingest_url: str = "https://admin.windyword.ai/v1/events"
|
||||
# Shared with our canary (Gitea repo secret CANARY_SYNTHETIC_KEY). A request
|
||||
# carrying it in X-Windy-Synthetic is our own tooling -> synthetic:true.
|
||||
windygit_synthetic_key: str = ""
|
||||
|
||||
# Internal callers (the Cloud portal calling /internal/*). A first-class
|
||||
# caller class, not a bypass: unset means service calls are REFUSED.
|
||||
|
||||
Reference in New Issue
Block a user