telemetry: synthetic:true on canary refusals (keyed, not a bare flag)
All checks were successful
check / gate (push) Successful in 25s
canary / probe (push) Successful in 7s

The canary deliberately sends forged tokens every 10 min; those refusal
rows read as attacks. It now sends X-Windy-Synthetic carrying a shared
secret (Gitea repo secret CANARY_SYNTHETIC_KEY = WINDYGIT_SYNTHETIC_KEY in
Veron .env); the API marks the row synthetic only on a constant-time
match, so an attacker cannot label their own refusals synthetic to hide.
synthetic is declared on forge.auth.failed (Telemetry Boss, UPDATE 3).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
2026-09-23 11:54:56 -04:00
parent 90643fe48e
commit 1c3b5b0638
6 changed files with 54 additions and 6 deletions

View File

@@ -73,6 +73,10 @@ class Check:
def _probe(c: Check) -> Result:
data = json.dumps(c.body).encode() if c.body else None
headers = {"User-Agent": "windy-git-canary/1.0", **c.headers}
# Mark our own probes so the ledger can tell a canary forgery from an attack.
# A shared secret, not a flag: a bare header would let an attacker hide.
if os.environ.get("CANARY_SYNTHETIC_KEY"):
headers["X-Windy-Synthetic"] = os.environ["CANARY_SYNTHETIC_KEY"]
if data:
headers["Content-Type"] = "application/json"
req = urllib.request.Request(c.url, data=data, method=c.method, headers=headers)