1773ed5f95
Mirror to GitHub / mirror (push) Successful in 26s
Test and Lint / backend-test (push) Successful in 1m11s
continuous-integration/drone/push Build is passing
Test and Lint / frontend-test (push) Successful in 2m28s
Version and Release / version-bump (push) Successful in 32s
Version and Release / trigger-drone (push) Has been skipped
Original: feat: enhance security logging and ensure rate limit blocks are properly tracked - Add comprehensive logging for rate limit blocks with full request details - IP address (with proper proxy detection), user agent, headers, timestamps - Rate limit info (current count, limit, remaining, reset time) - Separate tracking for auth vs general endpoints - Enhance authentication failure logging - JWT validation failures with detailed error info - Admin auth attempts without token - Failed token validation with user context - All events include IP, path, method, user agent - Improve Winston logger configuration for production - Add automatic log rotation (10MB errors, 50MB combined) - Create separate security.log for auth/rate limit events - Ensure logs directory exists automatically - Add structured JSON format for log aggregation - Support container logging with LOG_TO_CONSOLE env var - Create comprehensive documentation - Security logging guide with examples - Monitoring recommendations - Configuration reference - Add test script to verify logging functionality All rate limit settings remain configurable via admin panel: - Window duration, max requests, auth limits - Skip authenticated requests option - Public endpoints only option 🤖 Generated with [Claude Code](https://claude.ai/code) Co-Authored-By: Claude <noreply@anthropic.com>
95 lines
2.5 KiB
JavaScript
95 lines
2.5 KiB
JavaScript
#!/usr/bin/env node
|
|
|
|
/**
|
|
* Test script to verify security logging is working correctly
|
|
* Run with: node scripts/test-security-logging.js
|
|
*/
|
|
|
|
require('dotenv').config({ path: '../.env' });
|
|
const logger = require('../src/utils/logger');
|
|
|
|
console.log('Testing Security Logging...\n');
|
|
|
|
// Test 1: Basic logging
|
|
console.log('1. Testing basic logging levels:');
|
|
logger.info('Test info message', { test: true });
|
|
logger.warn('Test warning message', { test: true });
|
|
logger.error('Test error message', { test: true });
|
|
|
|
// Test 2: Security event logging
|
|
console.log('\n2. Testing security event logging:');
|
|
|
|
// Rate limit exceeded
|
|
logger.warn('Rate limit exceeded', {
|
|
ip: '192.168.1.100',
|
|
path: '/api/admin/login',
|
|
method: 'POST',
|
|
authenticated: false,
|
|
userAgent: 'Mozilla/5.0 Test',
|
|
timestamp: new Date().toISOString(),
|
|
rateLimitInfo: {
|
|
limit: 5,
|
|
current: 6,
|
|
remaining: 0,
|
|
resetTime: new Date(Date.now() + 900000).toISOString()
|
|
}
|
|
});
|
|
|
|
// Auth rate limit
|
|
logger.warn('Auth rate limit exceeded', {
|
|
ip: '192.168.1.101',
|
|
path: '/api/auth/admin/login',
|
|
method: 'POST',
|
|
userAgent: 'Mozilla/5.0 Test',
|
|
authType: 'admin',
|
|
timestamp: new Date().toISOString()
|
|
});
|
|
|
|
// Failed login
|
|
logger.warn('Failed login attempt', {
|
|
username: 'testuser',
|
|
ip: '192.168.1.102',
|
|
userAgent: 'Mozilla/5.0 Test',
|
|
reason: 'invalid_credentials',
|
|
timestamp: new Date().toISOString()
|
|
});
|
|
|
|
// JWT validation failure
|
|
logger.warn('JWT validation failed', {
|
|
ip: '192.168.1.103',
|
|
path: '/api/admin/events',
|
|
method: 'GET',
|
|
userAgent: 'Mozilla/5.0 Test',
|
|
error: 'TokenExpiredError',
|
|
message: 'jwt expired',
|
|
timestamp: new Date().toISOString()
|
|
});
|
|
|
|
// Account lockout
|
|
logger.warn('Login attempt on locked account', {
|
|
username: 'lockeduser',
|
|
ip: '192.168.1.104',
|
|
remainingLockTime: 1200,
|
|
timestamp: new Date().toISOString()
|
|
});
|
|
|
|
// Suspicious activity
|
|
logger.warn('Suspicious login activity detected', {
|
|
username: 'suspicioususer',
|
|
ips: ['192.168.1.105', '192.168.1.106', '192.168.1.107'],
|
|
timeWindow: '15 minutes',
|
|
timestamp: new Date().toISOString()
|
|
});
|
|
|
|
console.log('\n3. Check log files:');
|
|
console.log('- logs/security.log - Should contain all security warnings');
|
|
console.log('- logs/error.log - Should contain error messages');
|
|
console.log('- logs/combined.log - Should contain all messages');
|
|
|
|
console.log('\n✅ Security logging test complete!');
|
|
console.log('Review the log files to ensure all events are properly captured.');
|
|
|
|
// Give logger time to flush
|
|
setTimeout(() => {
|
|
process.exit(0);
|
|
}, 1000); |