Skip to content

Auth metrics updates #63030

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 2 commits into from
Aug 7, 2025
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 4 additions & 4 deletions src/Http/Authentication.Core/src/AuthenticationMetrics.cs
Original file line number Diff line number Diff line change
Expand Up @@ -31,22 +31,22 @@ public AuthenticationMetrics(IMeterFactory meterFactory)

_challengeCount = _meter.CreateCounter<long>(
"aspnetcore.authentication.challenges",
unit: "{request}",
unit: "{challenge}",
description: "The total number of times a scheme is challenged.");

_forbidCount = _meter.CreateCounter<long>(
"aspnetcore.authentication.forbids",
unit: "{request}",
unit: "{forbid}",
description: "The total number of times an authenticated user attempts to access a resource they are not permitted to access.");

_signInCount = _meter.CreateCounter<long>(
"aspnetcore.authentication.sign_ins",
unit: "{request}",
unit: "{sign_in}",
description: "The total number of times a principal is signed in with a scheme.");

_signOutCount = _meter.CreateCounter<long>(
"aspnetcore.authentication.sign_outs",
unit: "{request}",
unit: "{sign_out}",
description: "The total number of times a principal is signed out with a scheme.");
}

Expand Down
20 changes: 10 additions & 10 deletions src/Security/Authorization/Core/src/AuthorizationMetrics.cs
Original file line number Diff line number Diff line change
Expand Up @@ -18,31 +18,31 @@ internal sealed class AuthorizationMetrics
public const string MeterName = "Microsoft.AspNetCore.Authorization";

private readonly Meter _meter;
private readonly Counter<long> _authorizedRequestCount;
private readonly Counter<long> _authorizedCount;

public AuthorizationMetrics(IMeterFactory meterFactory)
{
_meter = meterFactory.Create(MeterName);

_authorizedRequestCount = _meter.CreateCounter<long>(
_authorizedCount = _meter.CreateCounter<long>(
"aspnetcore.authorization.attempts",
unit: "{request}",
description: "The total number of requests for which authorization was attempted.");
unit: "{attempt}",
description: "The total number of authorization attempts.");
}

public void AuthorizedRequestCompleted(ClaimsPrincipal user, string? policyName, AuthorizationResult? result, Exception? exception)
public void AuthorizeAttemptCompleted(ClaimsPrincipal user, string? policyName, AuthorizationResult? result, Exception? exception)
{
if (_authorizedRequestCount.Enabled)
if (_authorizedCount.Enabled)
{
AuthorizedRequestCompletedCore(user, policyName, result, exception);
AuthorizeAttemptCore(user, policyName, result, exception);
}
}

[MethodImpl(MethodImplOptions.NoInlining)]
private void AuthorizedRequestCompletedCore(ClaimsPrincipal user, string? policyName, AuthorizationResult? result, Exception? exception)
private void AuthorizeAttemptCore(ClaimsPrincipal user, string? policyName, AuthorizationResult? result, Exception? exception)
{
var tags = new TagList([
new("user.is_authenticated", user.Identity?.IsAuthenticated ?? false)
new("aspnetcore.user.is_authenticated", user.Identity?.IsAuthenticated ?? false)
]);

if (policyName is not null)
Expand All @@ -61,6 +61,6 @@ private void AuthorizedRequestCompletedCore(ClaimsPrincipal user, string? policy
tags.Add("error.type", exception.GetType().FullName);
}

_authorizedRequestCount.Add(1, tags);
_authorizedCount.Add(1, tags);
}
}
Original file line number Diff line number Diff line change
Expand Up @@ -30,11 +30,11 @@ public override async Task<AuthorizationResult> AuthorizeAsync(ClaimsPrincipal u
}
catch (Exception ex)
{
metrics.AuthorizedRequestCompleted(user, policyName: null, result: null, ex);
metrics.AuthorizeAttemptCompleted(user, policyName: null, result: null, ex);
throw;
}

metrics.AuthorizedRequestCompleted(user, policyName: null, result, exception: null);
metrics.AuthorizeAttemptCompleted(user, policyName: null, result, exception: null);
return result;
}

Expand All @@ -52,11 +52,11 @@ public override async Task<AuthorizationResult> AuthorizeAsync(ClaimsPrincipal u
}
catch (Exception ex)
{
metrics.AuthorizedRequestCompleted(user, policyName, result: null, ex);
metrics.AuthorizeAttemptCompleted(user, policyName, result: null, ex);
throw;
}

metrics.AuthorizedRequestCompleted(user, policyName, result, exception: null);
metrics.AuthorizeAttemptCompleted(user, policyName, result, exception: null);
return result;
}
}
12 changes: 6 additions & 6 deletions src/Security/Authorization/test/AuthorizationMetricsTest.cs
Original file line number Diff line number Diff line change
Expand Up @@ -32,7 +32,7 @@ public async Task Authorize_WithPolicyName_Success()
Assert.Equal(1, measurement.Value);
Assert.Equal("Basic", (string)measurement.Tags["aspnetcore.authorization.policy"]);
Assert.Equal("success", (string)measurement.Tags["aspnetcore.authorization.result"]);
Assert.True((bool)measurement.Tags["user.is_authenticated"]);
Assert.True((bool)measurement.Tags["aspnetcore.user.is_authenticated"]);
}

[Fact]
Expand All @@ -57,7 +57,7 @@ public async Task Authorize_WithPolicyName_Failure()
Assert.Equal(1, measurement.Value);
Assert.Equal("Basic", (string)measurement.Tags["aspnetcore.authorization.policy"]);
Assert.Equal("failure", (string)measurement.Tags["aspnetcore.authorization.result"]);
Assert.False((bool)measurement.Tags["user.is_authenticated"]);
Assert.False((bool)measurement.Tags["aspnetcore.user.is_authenticated"]);
}

[Fact]
Expand All @@ -82,7 +82,7 @@ public async Task Authorize_WithPolicyName_PolicyNotFound()
Assert.Equal(1, measurement.Value);
Assert.Equal("UnknownPolicy", (string)measurement.Tags["aspnetcore.authorization.policy"]);
Assert.Equal("System.InvalidOperationException", (string)measurement.Tags["error.type"]);
Assert.False((bool)measurement.Tags["user.is_authenticated"]);
Assert.False((bool)measurement.Tags["aspnetcore.user.is_authenticated"]);
Assert.False(measurement.Tags.ContainsKey("aspnetcore.authorization.result"));
}

Expand Down Expand Up @@ -110,7 +110,7 @@ public async Task Authorize_WithoutPolicyName_Success()
var measurement = Assert.Single(authorizedRequestsCollector.GetMeasurementSnapshot());
Assert.Equal(1, measurement.Value);
Assert.Equal("success", (string)measurement.Tags["aspnetcore.authorization.result"]);
Assert.False((bool)measurement.Tags["user.is_authenticated"]);
Assert.False((bool)measurement.Tags["aspnetcore.user.is_authenticated"]);
Assert.False(measurement.Tags.ContainsKey("aspnetcore.authorization.policy"));
}

Expand All @@ -135,7 +135,7 @@ public async Task Authorize_WithoutPolicyName_Failure()
var measurement = Assert.Single(authorizedRequestsCollector.GetMeasurementSnapshot());
Assert.Equal(1, measurement.Value);
Assert.Equal("failure", (string)measurement.Tags["aspnetcore.authorization.result"]);
Assert.False((bool)measurement.Tags["user.is_authenticated"]);
Assert.False((bool)measurement.Tags["aspnetcore.user.is_authenticated"]);
Assert.False(measurement.Tags.ContainsKey("aspnetcore.authorization.policy"));
}

Expand Down Expand Up @@ -164,7 +164,7 @@ public async Task Authorize_WithoutPolicyName_ExceptionThrownInHandler()
var measurement = Assert.Single(authorizedRequestsCollector.GetMeasurementSnapshot());
Assert.Equal(1, measurement.Value);
Assert.Equal("System.InvalidOperationException", (string)measurement.Tags["error.type"]);
Assert.False((bool)measurement.Tags["user.is_authenticated"]);
Assert.False((bool)measurement.Tags["aspnetcore.user.is_authenticated"]);
Assert.False(measurement.Tags.ContainsKey("aspnetcore.authorization.policy"));
Assert.False(measurement.Tags.ContainsKey("aspnetcore.authorization.result"));
}
Expand Down
Loading