fix: B6 复审收口——测试 Redis 隔离/网关审计口径 platform/死常量清理/回归断言补强

- P2: test_risk_api env 注入 FakePublisher,aml 推送不触真 Redis
- P3: deny/_authz_audit 增 agent_type 参数,simulate 越权审计传 platform
  (与网关放行审计同口径);删 HANDLE_RESULTS 死常量(Literal 单处定义)
- P3: 补 start_date/end_date 过滤+分页 422 边界+suitability api 层审计断言;
  补 app/service/risk/__init__.py
- 挂账: B7 行新增④项(启动期拒绝/引擎工厂覆盖三实例化点/handle 原子性/
  input_guard_log);B9b 行核查单(disclaimer/scan 幂等/Swagger 手测/analyst);
  TODO.md T-30/T-31/T-32 进度同步
This commit is contained in:
2026-09-06 19:21:15 +08:00
parent 3e40a2bb49
commit a78e9d4d31
8 changed files with 61 additions and 12 deletions
+9 -3
View File
@@ -54,13 +54,18 @@ def _authz_audit(
auth: AuthContext | None,
customer_id: str | None,
code: str,
agent_type: str = "risk",
) -> None:
"""鉴权失败审计(event_type='authz';手册 P-05,B6 评审 P1-1)。"""
"""鉴权失败审计(event_type='authz';手册 P-05,B6 评审 P1-1)。
agent_type 按路由归属传入(网关路由传 'platform',复审 P3:与放行审计
同口径,避免按模块检索审计时漏网关越权事件)。
"""
risk_repo.insert_audit_log(
{
"trace_id": current_trace() or new_trace(),
"event_type": "authz",
"agent_type": "risk",
"agent_type": agent_type,
"actor_id": auth.actor_id if auth else "anonymous",
"customer_id": customer_id,
"rule_id": None,
@@ -80,9 +85,10 @@ def deny(
risk_repo: RiskRepository,
customer_id: str | None = None,
message: str | None = None,
agent_type: str = "risk",
) -> None:
"""越权出口:审计 + 403(全部 403 必经此函数,保证留痕与错误码)。"""
_authz_audit(risk_repo, auth, customer_id, code)
_authz_audit(risk_repo, auth, customer_id, code, agent_type)
raise PermissionDenied(code, message or f"forbidden: {code}")
-2
View File
@@ -32,8 +32,6 @@ from app.utils.trace import current_trace, new_trace
router = APIRouter(prefix="/api/risk", tags=["risk"])
HANDLE_RESULTS = ("confirmed_normal", "confirmed_suspicious", "reported")
def _repo() -> RiskRepository:
"""仓储入口(测试 monkeypatch 点)。"""
+1
View File
@@ -42,6 +42,7 @@ def submit_trade_api(req: TradeRequest, auth: AuthContext = Depends(get_auth_con
deny(
auth, "AUTH_403_ROLE", _repo(),
customer_id=req.customer_id, message="risk_demo or owner customer only",
agent_type="platform", # 网关越权与放行审计同口径(复审 P3)
)
try:
return submit_trade(req.model_dump())