Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .secrets.baseline

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

97 changes: 97 additions & 0 deletions api/openapi.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -118,6 +118,16 @@ paths:
content:
application/json:
schema: {$ref: '#/components/schemas/ErrorEnvelope'}
'503':
description: >-
server.error. retryable true: sign-in did not complete and nothing was
issued, including when the per-user lock was not acquired in time.
retryable false: the outcome is unknown; sign in again rather than
assuming either result.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorEnvelope'

/api/v1/auth/logout:
post:
Expand All @@ -126,6 +136,36 @@ paths:
responses:
'204':
description: Session revoked
'403':
description: >-
authz.csrf_invalid. A credential cookie selects what to revoke and the
double-submit token is missing or does not match. Nothing was revoked and
no cookie was changed.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorEnvelope'
'500':
description: >-
auth.logout_incomplete, retryable. The revocation failed and rolled back,
so nothing was revoked. Both cookies are cleared; the session may stay
valid until it expires.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorEnvelope'
'503':
description: >-
server.error, not retryable, and both cookies are cleared. Two outcomes,
told apart by the message. The account lock was not acquired in time:
this attempt revoked nothing. The commit outcome is unknown: revocation
could not be confirmed. Neither invites an automatic retry, because
with the cookies cleared a repeated request may name no family, or a
different one.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorEnvelope'

/api/v1/auth/refresh:
post:
Expand All @@ -148,6 +188,15 @@ paths:
content:
application/json:
schema: {$ref: '#/components/schemas/ErrorEnvelope'}
'503':
description: >-
server.error. retryable true: nothing was rotated, including when the
per-user lock was not acquired in time. retryable false: the rotation
outcome is unknown; sign in again rather than presenting the same token.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorEnvelope'

/api/v1/auth/refresh-cookie:
post:
Expand All @@ -171,6 +220,15 @@ paths:
content:
application/json:
schema: {$ref: '#/components/schemas/ErrorEnvelope'}
'503':
description: >-
server.error. retryable true: nothing was rotated and no cookie was
set, including when the per-user lock was not acquired in time.
retryable false: the rotation outcome is unknown.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorEnvelope'

/api/v1/auth/me:
get:
Expand Down Expand Up @@ -747,6 +805,15 @@ paths:
content:
application/json:
schema: {$ref: '#/components/schemas/ErrorEnvelope'}
'503':
description: >-
server.error. retryable true: a lock wait exceeded its limit and the
transaction rolled back, so the user was not deleted. retryable false:
the commit outcome is unknown.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorEnvelope'

/api/v1/users/{id}/roles:assign:
post:
Expand Down Expand Up @@ -821,6 +888,16 @@ paths:
content:
application/json:
schema: {$ref: '#/components/schemas/ErrorEnvelope'}
'503':
description: >-
server.error. retryable true: a lock wait exceeded its limit and the
transaction rolled back, so the change was not applied. retryable
false: the commit outcome is unknown, and the change may or may not
have been applied.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorEnvelope'

/api/v1/users/{id}:disable:
post:
Expand Down Expand Up @@ -856,6 +933,16 @@ paths:
content:
application/json:
schema: {$ref: '#/components/schemas/ErrorEnvelope'}
'503':
description: >-
server.error. retryable true: a lock wait exceeded its limit and the
transaction rolled back, so the change was not applied. retryable
false: the commit outcome is unknown, and the change may or may not
have been applied.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorEnvelope'

/api/v1/users/{id}:enable:
post:
Expand Down Expand Up @@ -885,6 +972,16 @@ paths:
content:
application/json:
schema: {$ref: '#/components/schemas/ErrorEnvelope'}
'503':
description: >-
server.error. retryable true: a lock wait exceeded its limit and the
transaction rolled back, so the change was not applied. retryable
false: the commit outcome is unknown, and the change may or may not
have been applied.
content:
application/json:
schema:
$ref: '#/components/schemas/ErrorEnvelope'

/api/v1/roles:create:
post:
Expand Down
39 changes: 37 additions & 2 deletions audit/events.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -65,13 +65,48 @@ events:

- code: auth.login.failure
severity: warning
description: Authentication attempt failed
description: >-
Authentication attempt failed, or a presented credential was refused.
reason names why. Password login records wrong_password,
unknown_user, account_disabled, mfa_required, mfa_invalid,
mfa_required_during_login or password_changed_during_login. The
binders record the session, access-token and account-state reasons.
SSO records the sso_ reasons, and sso_account_disabled or
sso_account_deleted when the local account may not sign in; the
sign-in page stays generic. account_state_unavailable,
session_lookup_failed and role_lookup_unavailable mean the server
could not tell, and the request answered 503, not 401. invalid_credentials, account_locked,
mfa_failed and sso_failed are legacy values that nothing records
now; older rows may carry them. username is the submitted name,
clipped. remote_addr and user_agent are recorded by the binders,
the user agent clipped.
actor_types: [user]
detail_schema:
type: object
properties:
reason: {type: string, enum: [invalid_credentials, account_locked, mfa_required, mfa_failed, sso_failed]}
reason:
type: string
enum: [
wrong_password, unknown_user, account_disabled, account_deleted,
account_missing, account_state_unknown, account_state_unavailable,
mfa_required, mfa_invalid, mfa_required_during_login,
password_changed_during_login,
invalid_session_token, session_expired, session_revoked,
session_lookup_failed, session_user_lookup_failed,
invalid_api_token, invalid_jwt, jwt_expired, jwt_verify_failed,
invalid_jwt_subject, invalid_jwt_session,
role_lookup_unavailable,
sid_absent, session_absent, session_owner_mismatch,
session_absolute_expired, session_binding_unknown,
sso_login_init_failed, sso_idp_error, sso_state_expired,
sso_state_invalid, sso_token_invalid, sso_discovery_failed,
sso_account_disabled, sso_account_deleted, sso_account_not_active,
sso_signin_failed,
invalid_credentials, account_locked, mfa_failed, sso_failed]
auth_method: {type: string}
username: {type: string}
remote_addr: {type: string}
user_agent: {type: string}

- code: auth.logout
severity: info
Expand Down
90 changes: 90 additions & 0 deletions frontend/src/api/schema.d.ts
Original file line number Diff line number Diff line change
Expand Up @@ -5036,6 +5036,15 @@ export interface operations {
"application/json": components["schemas"]["ErrorEnvelope"];
};
};
/** @description server.error. retryable true: sign-in did not complete and nothing was issued, including when the per-user lock was not acquired in time. retryable false: the outcome is unknown; sign in again rather than assuming either result. */
503: {
headers: {
[name: string]: unknown;
};
content: {
"application/json": components["schemas"]["ErrorEnvelope"];
};
};
};
};
postAuthLogout: {
Expand All @@ -5054,6 +5063,33 @@ export interface operations {
};
content?: never;
};
/** @description authz.csrf_invalid. A credential cookie selects what to revoke and the double-submit token is missing or does not match. Nothing was revoked and no cookie was changed. */
403: {
headers: {
[name: string]: unknown;
};
content: {
"application/json": components["schemas"]["ErrorEnvelope"];
};
};
/** @description auth.logout_incomplete, retryable. The revocation failed and rolled back, so nothing was revoked. Both cookies are cleared; the session may stay valid until it expires. */
500: {
headers: {
[name: string]: unknown;
};
content: {
"application/json": components["schemas"]["ErrorEnvelope"];
};
};
/** @description server.error, not retryable, and both cookies are cleared. Two outcomes, told apart by the message. The account lock was not acquired in time: this attempt revoked nothing. The commit outcome is unknown: revocation could not be confirmed. Neither invites an automatic retry, because with the cookies cleared a repeated request may name no family, or a different one. */
503: {
headers: {
[name: string]: unknown;
};
content: {
"application/json": components["schemas"]["ErrorEnvelope"];
};
};
};
};
postAuthRefresh: {
Expand Down Expand Up @@ -5087,6 +5123,15 @@ export interface operations {
"application/json": components["schemas"]["ErrorEnvelope"];
};
};
/** @description server.error. retryable true: nothing was rotated, including when the per-user lock was not acquired in time. retryable false: the rotation outcome is unknown; sign in again rather than presenting the same token. */
503: {
headers: {
[name: string]: unknown;
};
content: {
"application/json": components["schemas"]["ErrorEnvelope"];
};
};
};
};
postAuthRefreshCookie: {
Expand Down Expand Up @@ -5116,6 +5161,15 @@ export interface operations {
"application/json": components["schemas"]["ErrorEnvelope"];
};
};
/** @description server.error. retryable true: nothing was rotated and no cookie was set, including when the per-user lock was not acquired in time. retryable false: the rotation outcome is unknown. */
503: {
headers: {
[name: string]: unknown;
};
content: {
"application/json": components["schemas"]["ErrorEnvelope"];
};
};
};
};
getAuthMe: {
Expand Down Expand Up @@ -5956,6 +6010,15 @@ export interface operations {
"application/json": components["schemas"]["ErrorEnvelope"];
};
};
/** @description server.error. retryable true: a lock wait exceeded its limit and the transaction rolled back, so the user was not deleted. retryable false: the commit outcome is unknown. */
503: {
headers: {
[name: string]: unknown;
};
content: {
"application/json": components["schemas"]["ErrorEnvelope"];
};
};
};
};
postUserRolesAssign: {
Expand Down Expand Up @@ -6064,6 +6127,15 @@ export interface operations {
"application/json": components["schemas"]["ErrorEnvelope"];
};
};
/** @description server.error. retryable true: a lock wait exceeded its limit and the transaction rolled back, so the change was not applied. retryable false: the commit outcome is unknown, and the change may or may not have been applied. */
503: {
headers: {
[name: string]: unknown;
};
content: {
"application/json": components["schemas"]["ErrorEnvelope"];
};
};
};
};
postUserDisable: {
Expand Down Expand Up @@ -6113,6 +6185,15 @@ export interface operations {
"application/json": components["schemas"]["ErrorEnvelope"];
};
};
/** @description server.error. retryable true: a lock wait exceeded its limit and the transaction rolled back, so the change was not applied. retryable false: the commit outcome is unknown, and the change may or may not have been applied. */
503: {
headers: {
[name: string]: unknown;
};
content: {
"application/json": components["schemas"]["ErrorEnvelope"];
};
};
};
};
postUserEnable: {
Expand Down Expand Up @@ -6153,6 +6234,15 @@ export interface operations {
"application/json": components["schemas"]["ErrorEnvelope"];
};
};
/** @description server.error. retryable true: a lock wait exceeded its limit and the transaction rolled back, so the change was not applied. retryable false: the commit outcome is unknown, and the change may or may not have been applied. */
503: {
headers: {
[name: string]: unknown;
};
content: {
"application/json": components["schemas"]["ErrorEnvelope"];
};
};
};
};
postRolesCreate: {
Expand Down
6 changes: 3 additions & 3 deletions internal/audit/events.gen.go

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

Loading
Loading