More audit log stuff

This commit is contained in:
Fang-Pen Lin
2025-12-11 14:38:01 -08:00
parent 8598b276f6
commit 12b245b641
2 changed files with 32 additions and 4 deletions
@@ -49,8 +49,8 @@ import { TWebhookPayloads } from "@app/services/webhook/webhook-types";
import { WorkflowIntegration } from "@app/services/workflow-integration/workflow-integration-types"; import { WorkflowIntegration } from "@app/services/workflow-integration/workflow-integration-types";
import { KmipPermission } from "../kmip/kmip-enum"; import { KmipPermission } from "../kmip/kmip-enum";
import { ApprovalStatus } from "../secret-approval-request/secret-approval-request-types";
import { AcmeIdentifierType } from "../pki-acme/pki-acme-schemas"; import { AcmeIdentifierType } from "../pki-acme/pki-acme-schemas";
import { ApprovalStatus } from "../secret-approval-request/secret-approval-request-types";
export type TListProjectAuditLogDTO = { export type TListProjectAuditLogDTO = {
filter: { filter: {
@@ -582,7 +582,8 @@ export enum EventType {
// PKI ACME // PKI ACME
CREATE_ACME_ACCOUNT = "create-acme-account", CREATE_ACME_ACCOUNT = "create-acme-account",
RETRIEVE_ACME_ACCOUNT = "retrieve-acme-account", RETRIEVE_ACME_ACCOUNT = "retrieve-acme-account",
CREATE_ACME_ORDER = "create-acme-order" CREATE_ACME_ORDER = "create-acme-order",
FINALIZE_ACME_ORDER = "finalize-acme-order"
} }
export const filterableSecretEvents: EventType[] = [ export const filterableSecretEvents: EventType[] = [
@@ -4430,6 +4431,14 @@ interface CreateAcmeOrderEvent {
}; };
} }
interface FinalizeAcmeOrderEvent {
type: EventType.FINALIZE_ACME_ORDER;
metadata: {
orderId: string;
csr: string;
};
}
export type Event = export type Event =
| CreateSubOrganizationEvent | CreateSubOrganizationEvent
| UpdateSubOrganizationEvent | UpdateSubOrganizationEvent
@@ -4833,4 +4842,5 @@ export type Event =
| ApprovalRequestGrantRevokeEvent | ApprovalRequestGrantRevokeEvent
| CreateAcmeAccountEvent | CreateAcmeAccountEvent
| RetrieveAcmeAccountEvent | RetrieveAcmeAccountEvent
| CreateAcmeOrderEvent; | CreateAcmeOrderEvent
| FinalizeAcmeOrderEvent;
@@ -613,6 +613,7 @@ export const pkiAcmeServiceFactory = ({
// if not, we may be able to reject it early with an unsupportedIdentifier error. // if not, we may be able to reject it early with an unsupportedIdentifier error.
// TODO: ideally, we should return an error with subproblems if we have multiple unsupported identifiers // TODO: ideally, we should return an error with subproblems if we have multiple unsupported identifiers
const profile = await validateAcmeProfile(profileId);
if (payload.identifiers.some((identifier) => identifier.type !== AcmeIdentifierType.DNS)) { if (payload.identifiers.some((identifier) => identifier.type !== AcmeIdentifierType.DNS)) {
throw new AcmeUnsupportedIdentifierError({ message: "Only DNS identifiers are supported" }); throw new AcmeUnsupportedIdentifierError({ message: "Only DNS identifiers are supported" });
} }
@@ -686,7 +687,7 @@ export const pkiAcmeServiceFactory = ({
tx tx
); );
await auditLogService.createAuditLog({ await auditLogService.createAuditLog({
projectId: account.profileId, projectId: profile.projectId,
actor: { actor: {
type: ActorType.ACME_ACCOUNT, type: ActorType.ACME_ACCOUNT,
metadata: { metadata: {
@@ -932,6 +933,23 @@ export const pkiAcmeServiceFactory = ({
throw error; throw error;
} }
order = updatedOrder; order = updatedOrder;
await auditLogService.createAuditLog({
projectId: profile.projectId,
actor: {
type: ActorType.ACME_ACCOUNT,
metadata: {
profileId,
accountId
}
},
event: {
type: EventType.FINALIZE_ACME_ORDER,
metadata: {
orderId: updatedOrder.id,
csr: updatedOrder.csr!
}
}
});
} else if (order.status !== AcmeOrderStatus.Valid) { } else if (order.status !== AcmeOrderStatus.Valid) {
throw new AcmeOrderNotReadyError({ message: "ACME order is not ready" }); throw new AcmeOrderNotReadyError({ message: "ACME order is not ready" });
} }