telemetry: synthetic:true on canary refusals (keyed, not a bare flag)
All checks were successful
check / gate (push) Successful in 25s
canary / probe (push) Successful in 7s

The canary deliberately sends forged tokens every 10 min; those refusal
rows read as attacks. It now sends X-Windy-Synthetic carrying a shared
secret (Gitea repo secret CANARY_SYNTHETIC_KEY = WINDYGIT_SYNTHETIC_KEY in
Veron .env); the API marks the row synthetic only on a constant-time
match, so an attacker cannot label their own refusals synthetic to hide.
synthetic is declared on forge.auth.failed (Telemetry Boss, UPDATE 3).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
2026-09-23 11:54:56 -04:00
parent 90643fe48e
commit 1c3b5b0638
6 changed files with 54 additions and 6 deletions

View File

@@ -14,7 +14,7 @@ from fastapi import Depends, FastAPI
from api.app import telemetry as tmod
from api.app.errors import RepairPointer
DECLARED_AUTH_KEYS = {"code", "http_status", "caller", "route", "upstream_status"}
DECLARED_AUTH_KEYS = {"code", "http_status", "caller", "route", "upstream_status", "synthetic"}
def _app(tel: tmod.Telemetry) -> FastAPI:
@@ -140,3 +140,26 @@ def test_caller_classes_are_the_declared_three():
tmod.caller_class({"authorization": "Bearer eyJhbGciOiJSUzI1NiJ9.e30.x"})
== "anonymous_human"
)
@pytest.mark.asyncio
async def test_canary_refusals_are_marked_synthetic_only_with_the_real_key():
from types import SimpleNamespace
async def refusal(headers):
tel = _tel()
app = _app(tel)
app.state.settings = SimpleNamespace(windygit_synthetic_key="k3y")
await _get(app, "/api/v1/repos/x/grants", headers)
return [e for e in tel.buffer if e["event_type"] == "forge.auth.failed"][0]["metadata"][
"synthetic"
]
assert await refusal({"X-Windy-Synthetic": "k3y"}) is True
assert await refusal({"X-Windy-Synthetic": "guess"}) is False # an attacker can't hide
assert await refusal({}) is False
def test_synthetic_needs_a_configured_key():
assert tmod.is_synthetic({"x-windy-synthetic": ""}, "") is False
assert tmod.is_synthetic({"x-windy-synthetic": "anything"}, "") is False