From e2d77360eb588b2fd4c5f8670b3b18f5e96aaf6d Mon Sep 17 00:00:00 2001 From: Kit OC5 Date: Wed, 23 Sep 2026 12:52:32 -0400 Subject: [PATCH] push velocity: key humans on windy_identity_id (SSO link); no id -> system + caller Telemetry UPDATE 2 actor rule: agent/human rows without actor_id are quarantined. Forge humans sign in only via Windy SSO, so Gitea's external_login_user.external_id is their windy_identity_id. Co-Authored-By: Claude Opus 5.5 --- api/tests/test_push_velocity.py | 23 ++++++++++++++--------- scripts/telemetry_emit.py | 16 ++++++++++++---- 2 files changed, 26 insertions(+), 13 deletions(-) diff --git a/api/tests/test_push_velocity.py b/api/tests/test_push_velocity.py index eb56c17..4fe2342 100644 --- a/api/tests/test_push_velocity.py +++ b/api/tests/test_push_velocity.py @@ -18,8 +18,8 @@ _spec.loader.exec_module(te) NOW = 1_800_000_000.0 -def row(login="agent-et26abcd1234", uid=7, p1h=0, p24h=0, d24h=0, repos=1): - return {"uid": uid, "login": login, "p1h": p1h, "p24h": p24h, "d24h": d24h, "repos": repos} +def row(login="agent-et26abcd1234", uid=7, p1h=0, p24h=0, d24h=0, repos=1, wid=None): + return {"uid": uid, "login": login, "wid": wid, "p1h": p1h, "p24h": p24h, "d24h": d24h, "repos": repos} def test_under_every_threshold_emits_nothing(): @@ -61,15 +61,20 @@ def test_the_sync_account_is_exempt(): assert ev == [] -def test_human_rows_carry_no_invented_actor_id(): - ev, _ = te.push_velocity_events([row(login="u-5e1b9569abc", d24h=11)], NOW, {}) - assert [(e["actor_type"], e["metadata"]["rule"]) for e in ev] == [("human", "ref_deletes_24h")] - assert "actor_id" not in ev[0] +def test_sso_human_is_keyed_on_windy_identity_id(): + ev, _ = te.push_velocity_events([row(login="u-5e1b9569abc", wid="5e1b9569-full-id", d24h=11)], NOW, {}) + assert [(e["actor_type"], e["actor_id"], e["metadata"]["rule"]) for e in ev] == [ + ("human", "5e1b9569-full-id", "ref_deletes_24h") + ] + assert "caller" not in ev[0]["metadata"] -def test_unparseable_agent_login_keeps_agent_type_without_actor_id(): - ev, _ = te.push_velocity_events([row(login="agent-weird", p24h=501)], NOW, {}) - assert ev[0]["actor_type"] == "agent" and "actor_id" not in ev[0] +def test_no_provable_id_is_system_plus_caller_never_an_invented_id(): + # UPDATE 2 actor rule: agent/human rows without an actor_id are quarantined. + for login in ("u-nolink", "agent-weird"): + ev, _ = te.push_velocity_events([row(login=login, p24h=501)], NOW, {}) + assert ev[0]["actor_type"] == "system" and "actor_id" not in ev[0] + assert ev[0]["metadata"]["caller"] == "unknown" def test_passport_round_trip(): diff --git a/scripts/telemetry_emit.py b/scripts/telemetry_emit.py index c37d153..c7998a9 100644 --- a/scripts/telemetry_emit.py +++ b/scripts/telemetry_emit.py @@ -95,6 +95,8 @@ PV_EXEMPT = {"windyadmin"} # keeps exactly the actor's own copy. PV_QUERY = """ select a.act_user_id as uid, u.lower_name as login, + (select el.external_id from external_login_user el + where el.user_id = u.id order by el.external_id limit 1) as wid, count(*) filter (where a.op_type in (5, 9) and a.created_unix > {h1}) as p1h, count(*) filter (where a.op_type in (5, 9)) as p24h, count(*) filter (where a.op_type in (16, 17)) as d24h, @@ -139,7 +141,6 @@ def push_velocity_events(rows: list[dict], now: float, alerted: dict) -> tuple[l "platform": PLATFORM, "service": "forge", "event_type": "forge.push_velocity", - "actor_type": "agent" if agent else "human", "metadata": { "rule": rule, "window_s": window, @@ -149,9 +150,16 @@ def push_velocity_events(rows: list[dict], now: float, alerted: dict) -> tuple[l "gitea_user_id": int(r["uid"]), }, } - passport = passport_from_login(login) if agent else None - if passport: # unknown is absent, never invented (I-12) - ev["actor_id"] = passport + # Actor rule (telemetry UPDATE 2): agent/human rows MUST carry an + # actor_id. Humans sign in to the forge only via Windy SSO, so the + # external login id IS their windy_identity_id. No id we can prove + # -> actor_type system + metadata.caller, never an invented id (I-12). + actor_id = passport_from_login(login) if agent else (r.get("wid") or None) + if actor_id: + ev["actor_type"], ev["actor_id"] = ("agent" if agent else "human"), str(actor_id) + else: + ev["actor_type"] = "system" + ev["metadata"]["caller"] = "unknown" events.append(ev) return events, keep