mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-08 23:28:25 +00:00
feat(audit-logs): Audit org updates, project create / update / delete
This commit is contained in:
@@ -315,7 +315,6 @@ export enum EventType {
|
|||||||
CREATE_PROJECT_TEMPLATE = "create-project-template",
|
CREATE_PROJECT_TEMPLATE = "create-project-template",
|
||||||
UPDATE_PROJECT_TEMPLATE = "update-project-template",
|
UPDATE_PROJECT_TEMPLATE = "update-project-template",
|
||||||
DELETE_PROJECT_TEMPLATE = "delete-project-template",
|
DELETE_PROJECT_TEMPLATE = "delete-project-template",
|
||||||
APPLY_PROJECT_TEMPLATE = "apply-project-template",
|
|
||||||
GET_APP_CONNECTIONS = "get-app-connections",
|
GET_APP_CONNECTIONS = "get-app-connections",
|
||||||
GET_AVAILABLE_APP_CONNECTIONS_DETAILS = "get-available-app-connections-details",
|
GET_AVAILABLE_APP_CONNECTIONS_DETAILS = "get-available-app-connections-details",
|
||||||
GET_APP_CONNECTION = "get-app-connection",
|
GET_APP_CONNECTION = "get-app-connection",
|
||||||
@@ -375,7 +374,13 @@ export enum EventType {
|
|||||||
MICROSOFT_TEAMS_WORKFLOW_INTEGRATION_LIST = "microsoft-teams-workflow-integration-list",
|
MICROSOFT_TEAMS_WORKFLOW_INTEGRATION_LIST = "microsoft-teams-workflow-integration-list",
|
||||||
|
|
||||||
PROJECT_ASSUME_PRIVILEGE_SESSION_START = "project-assume-privileges-session-start",
|
PROJECT_ASSUME_PRIVILEGE_SESSION_START = "project-assume-privileges-session-start",
|
||||||
PROJECT_ASSUME_PRIVILEGE_SESSION_END = "project-assume-privileges-session-end"
|
PROJECT_ASSUME_PRIVILEGE_SESSION_END = "project-assume-privileges-session-end",
|
||||||
|
|
||||||
|
UPDATE_ORG = "update-org",
|
||||||
|
|
||||||
|
CREATE_PROJECT = "create-project",
|
||||||
|
UPDATE_PROJECT = "update-project",
|
||||||
|
DELETE_PROJECT = "delete-project"
|
||||||
}
|
}
|
||||||
|
|
||||||
export const filterableSecretEvents: EventType[] = [
|
export const filterableSecretEvents: EventType[] = [
|
||||||
@@ -2451,14 +2456,6 @@ interface DeleteProjectTemplateEvent {
|
|||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
interface ApplyProjectTemplateEvent {
|
|
||||||
type: EventType.APPLY_PROJECT_TEMPLATE;
|
|
||||||
metadata: {
|
|
||||||
template: string;
|
|
||||||
projectId: string;
|
|
||||||
};
|
|
||||||
}
|
|
||||||
|
|
||||||
interface GetAppConnectionsEvent {
|
interface GetAppConnectionsEvent {
|
||||||
type: EventType.GET_APP_CONNECTIONS;
|
type: EventType.GET_APP_CONNECTIONS;
|
||||||
metadata: {
|
metadata: {
|
||||||
@@ -2913,6 +2910,26 @@ interface MicrosoftTeamsWorkflowIntegrationUpdateEvent {
|
|||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
|
interface OrgUpdateEvent {
|
||||||
|
type: EventType.UPDATE_ORG;
|
||||||
|
metadata: Record<string, string | boolean | object | number>; // The update parameters
|
||||||
|
}
|
||||||
|
|
||||||
|
interface ProjectCreateEvent {
|
||||||
|
type: EventType.CREATE_PROJECT;
|
||||||
|
metadata: Record<string, string | boolean | object | number>; // The creation parameters
|
||||||
|
}
|
||||||
|
|
||||||
|
interface ProjectUpdateEvent {
|
||||||
|
type: EventType.UPDATE_PROJECT;
|
||||||
|
metadata: Record<string, string | boolean | object | number>; // The update parameters
|
||||||
|
}
|
||||||
|
|
||||||
|
interface ProjectDeleteEvent {
|
||||||
|
type: EventType.DELETE_PROJECT;
|
||||||
|
metadata: Record<string, string>;
|
||||||
|
}
|
||||||
|
|
||||||
export type Event =
|
export type Event =
|
||||||
| GetSecretsEvent
|
| GetSecretsEvent
|
||||||
| GetSecretEvent
|
| GetSecretEvent
|
||||||
@@ -3117,7 +3134,6 @@ export type Event =
|
|||||||
| CreateProjectTemplateEvent
|
| CreateProjectTemplateEvent
|
||||||
| UpdateProjectTemplateEvent
|
| UpdateProjectTemplateEvent
|
||||||
| DeleteProjectTemplateEvent
|
| DeleteProjectTemplateEvent
|
||||||
| ApplyProjectTemplateEvent
|
|
||||||
| GetAppConnectionsEvent
|
| GetAppConnectionsEvent
|
||||||
| GetAvailableAppConnectionsDetailsEvent
|
| GetAvailableAppConnectionsDetailsEvent
|
||||||
| GetAppConnectionEvent
|
| GetAppConnectionEvent
|
||||||
@@ -3179,4 +3195,8 @@ export type Event =
|
|||||||
| MicrosoftTeamsWorkflowIntegrationGetTeamsEvent
|
| MicrosoftTeamsWorkflowIntegrationGetTeamsEvent
|
||||||
| MicrosoftTeamsWorkflowIntegrationGetEvent
|
| MicrosoftTeamsWorkflowIntegrationGetEvent
|
||||||
| MicrosoftTeamsWorkflowIntegrationListEvent
|
| MicrosoftTeamsWorkflowIntegrationListEvent
|
||||||
| MicrosoftTeamsWorkflowIntegrationUpdateEvent;
|
| MicrosoftTeamsWorkflowIntegrationUpdateEvent
|
||||||
|
| OrgUpdateEvent
|
||||||
|
| ProjectCreateEvent
|
||||||
|
| ProjectUpdateEvent
|
||||||
|
| ProjectDeleteEvent;
|
||||||
|
|||||||
@@ -26,8 +26,8 @@ export const getDefaultOnPremFeatures = (): TFeatureSet => ({
|
|||||||
customRateLimits: false,
|
customRateLimits: false,
|
||||||
customAlerts: false,
|
customAlerts: false,
|
||||||
secretAccessInsights: false,
|
secretAccessInsights: false,
|
||||||
auditLogs: false,
|
auditLogs: true,
|
||||||
auditLogsRetentionDays: 0,
|
auditLogsRetentionDays: 2,
|
||||||
auditLogStreams: false,
|
auditLogStreams: false,
|
||||||
auditLogStreamLimit: 3,
|
auditLogStreamLimit: 3,
|
||||||
samlSSO: false,
|
samlSSO: false,
|
||||||
|
|||||||
@@ -301,8 +301,17 @@ export const registerOrgRouter = async (server: FastifyZodProvider) => {
|
|||||||
data: req.body
|
data: req.body
|
||||||
});
|
});
|
||||||
|
|
||||||
|
await server.services.auditLog.createAuditLog({
|
||||||
|
...req.auditLogInfo,
|
||||||
|
orgId: req.permission.orgId,
|
||||||
|
event: {
|
||||||
|
type: EventType.UPDATE_ORG,
|
||||||
|
metadata: req.body
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
return {
|
return {
|
||||||
message: "Successfully changed organization name",
|
message: "Successfully updated organization",
|
||||||
organization
|
organization
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -263,6 +263,17 @@ export const registerProjectRouter = async (server: FastifyZodProvider) => {
|
|||||||
actor: req.permission.type,
|
actor: req.permission.type,
|
||||||
actorOrgId: req.permission.orgId
|
actorOrgId: req.permission.orgId
|
||||||
});
|
});
|
||||||
|
|
||||||
|
await server.services.auditLog.createAuditLog({
|
||||||
|
...req.auditLogInfo,
|
||||||
|
orgId: req.permission.orgId,
|
||||||
|
projectId: req.params.workspaceId,
|
||||||
|
event: {
|
||||||
|
type: EventType.DELETE_PROJECT,
|
||||||
|
metadata: {}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
return { workspace };
|
return { workspace };
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
@@ -297,6 +308,19 @@ export const registerProjectRouter = async (server: FastifyZodProvider) => {
|
|||||||
projectId: req.params.workspaceId,
|
projectId: req.params.workspaceId,
|
||||||
name: req.body.name
|
name: req.body.name
|
||||||
});
|
});
|
||||||
|
|
||||||
|
await server.services.auditLog.createAuditLog({
|
||||||
|
...req.auditLogInfo,
|
||||||
|
orgId: req.permission.orgId,
|
||||||
|
projectId: req.params.workspaceId,
|
||||||
|
event: {
|
||||||
|
type: EventType.UPDATE_PROJECT,
|
||||||
|
metadata: {
|
||||||
|
name: req.body.name
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
return {
|
return {
|
||||||
message: "Successfully changed workspace name",
|
message: "Successfully changed workspace name",
|
||||||
workspace
|
workspace
|
||||||
@@ -375,6 +399,17 @@ export const registerProjectRouter = async (server: FastifyZodProvider) => {
|
|||||||
actor: req.permission.type,
|
actor: req.permission.type,
|
||||||
actorOrgId: req.permission.orgId
|
actorOrgId: req.permission.orgId
|
||||||
});
|
});
|
||||||
|
|
||||||
|
await server.services.auditLog.createAuditLog({
|
||||||
|
...req.auditLogInfo,
|
||||||
|
orgId: req.permission.orgId,
|
||||||
|
projectId: req.params.workspaceId,
|
||||||
|
event: {
|
||||||
|
type: EventType.UPDATE_PROJECT,
|
||||||
|
metadata: req.body
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
return {
|
return {
|
||||||
workspace
|
workspace
|
||||||
};
|
};
|
||||||
@@ -411,6 +446,17 @@ export const registerProjectRouter = async (server: FastifyZodProvider) => {
|
|||||||
projectId: req.params.workspaceId,
|
projectId: req.params.workspaceId,
|
||||||
autoCapitalization: req.body.autoCapitalization
|
autoCapitalization: req.body.autoCapitalization
|
||||||
});
|
});
|
||||||
|
|
||||||
|
await server.services.auditLog.createAuditLog({
|
||||||
|
...req.auditLogInfo,
|
||||||
|
orgId: req.permission.orgId,
|
||||||
|
projectId: req.params.workspaceId,
|
||||||
|
event: {
|
||||||
|
type: EventType.UPDATE_PROJECT,
|
||||||
|
metadata: req.body
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
return {
|
return {
|
||||||
message: "Successfully changed workspace settings",
|
message: "Successfully changed workspace settings",
|
||||||
workspace
|
workspace
|
||||||
@@ -448,6 +494,17 @@ export const registerProjectRouter = async (server: FastifyZodProvider) => {
|
|||||||
projectId: req.params.workspaceId,
|
projectId: req.params.workspaceId,
|
||||||
hasDeleteProtection: req.body.hasDeleteProtection
|
hasDeleteProtection: req.body.hasDeleteProtection
|
||||||
});
|
});
|
||||||
|
|
||||||
|
await server.services.auditLog.createAuditLog({
|
||||||
|
...req.auditLogInfo,
|
||||||
|
orgId: req.permission.orgId,
|
||||||
|
projectId: req.params.workspaceId,
|
||||||
|
event: {
|
||||||
|
type: EventType.UPDATE_PROJECT,
|
||||||
|
metadata: req.body
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
return {
|
return {
|
||||||
message: "Successfully changed workspace settings",
|
message: "Successfully changed workspace settings",
|
||||||
workspace
|
workspace
|
||||||
@@ -486,6 +543,16 @@ export const registerProjectRouter = async (server: FastifyZodProvider) => {
|
|||||||
workspaceSlug: req.params.workspaceSlug
|
workspaceSlug: req.params.workspaceSlug
|
||||||
});
|
});
|
||||||
|
|
||||||
|
await server.services.auditLog.createAuditLog({
|
||||||
|
...req.auditLogInfo,
|
||||||
|
orgId: req.permission.orgId,
|
||||||
|
projectId: workspace.id,
|
||||||
|
event: {
|
||||||
|
type: EventType.UPDATE_PROJECT,
|
||||||
|
metadata: req.body
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
return {
|
return {
|
||||||
message: "Successfully changed workspace version limit",
|
message: "Successfully changed workspace version limit",
|
||||||
workspace
|
workspace
|
||||||
@@ -524,6 +591,16 @@ export const registerProjectRouter = async (server: FastifyZodProvider) => {
|
|||||||
auditLogsRetentionDays: req.body.auditLogsRetentionDays
|
auditLogsRetentionDays: req.body.auditLogsRetentionDays
|
||||||
});
|
});
|
||||||
|
|
||||||
|
await server.services.auditLog.createAuditLog({
|
||||||
|
...req.auditLogInfo,
|
||||||
|
orgId: req.permission.orgId,
|
||||||
|
projectId: workspace.id,
|
||||||
|
event: {
|
||||||
|
type: EventType.UPDATE_PROJECT,
|
||||||
|
metadata: req.body
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
return {
|
return {
|
||||||
message: "Successfully updated project's audit logs retention period",
|
message: "Successfully updated project's audit logs retention period",
|
||||||
workspace
|
workspace
|
||||||
|
|||||||
@@ -206,19 +206,15 @@ export const registerProjectRouter = async (server: FastifyZodProvider) => {
|
|||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
if (req.body.template) {
|
await server.services.auditLog.createAuditLog({
|
||||||
await server.services.auditLog.createAuditLog({
|
...req.auditLogInfo,
|
||||||
...req.auditLogInfo,
|
orgId: req.permission.orgId,
|
||||||
orgId: req.permission.orgId,
|
projectId: project.id,
|
||||||
event: {
|
event: {
|
||||||
type: EventType.APPLY_PROJECT_TEMPLATE,
|
type: EventType.CREATE_PROJECT,
|
||||||
metadata: {
|
metadata: req.body
|
||||||
template: req.body.template,
|
}
|
||||||
projectId: project.id
|
});
|
||||||
}
|
|
||||||
}
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
return { project };
|
return { project };
|
||||||
}
|
}
|
||||||
@@ -262,6 +258,16 @@ export const registerProjectRouter = async (server: FastifyZodProvider) => {
|
|||||||
actor: req.permission.type
|
actor: req.permission.type
|
||||||
});
|
});
|
||||||
|
|
||||||
|
await server.services.auditLog.createAuditLog({
|
||||||
|
...req.auditLogInfo,
|
||||||
|
orgId: req.permission.orgId,
|
||||||
|
projectId: project.id,
|
||||||
|
event: {
|
||||||
|
type: EventType.DELETE_PROJECT,
|
||||||
|
metadata: {}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
return project;
|
return project;
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
@@ -341,6 +347,16 @@ export const registerProjectRouter = async (server: FastifyZodProvider) => {
|
|||||||
actorOrgId: req.permission.orgId
|
actorOrgId: req.permission.orgId
|
||||||
});
|
});
|
||||||
|
|
||||||
|
await server.services.auditLog.createAuditLog({
|
||||||
|
...req.auditLogInfo,
|
||||||
|
orgId: req.permission.orgId,
|
||||||
|
projectId: project.id,
|
||||||
|
event: {
|
||||||
|
type: EventType.UPDATE_PROJECT,
|
||||||
|
metadata: req.body
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
return project;
|
return project;
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|||||||
@@ -123,7 +123,6 @@ export const eventToNameMap: { [K in EventType]: string } = {
|
|||||||
[EventType.CREATE_PROJECT_TEMPLATE]: "Create project template",
|
[EventType.CREATE_PROJECT_TEMPLATE]: "Create project template",
|
||||||
[EventType.UPDATE_PROJECT_TEMPLATE]: "Update project template",
|
[EventType.UPDATE_PROJECT_TEMPLATE]: "Update project template",
|
||||||
[EventType.DELETE_PROJECT_TEMPLATE]: "Delete project template",
|
[EventType.DELETE_PROJECT_TEMPLATE]: "Delete project template",
|
||||||
[EventType.APPLY_PROJECT_TEMPLATE]: "Apply project template",
|
|
||||||
[EventType.GET_APP_CONNECTIONS]: "List App Connections",
|
[EventType.GET_APP_CONNECTIONS]: "List App Connections",
|
||||||
[EventType.GET_AVAILABLE_APP_CONNECTIONS_DETAILS]: "List App Connections Details",
|
[EventType.GET_AVAILABLE_APP_CONNECTIONS_DETAILS]: "List App Connections Details",
|
||||||
[EventType.GET_APP_CONNECTION]: "Get App Connection",
|
[EventType.GET_APP_CONNECTION]: "Get App Connection",
|
||||||
@@ -189,7 +188,13 @@ export const eventToNameMap: { [K in EventType]: string } = {
|
|||||||
[EventType.ADD_IDENTITY_LDAP_AUTH]: "Attached LDAP Auth to identity",
|
[EventType.ADD_IDENTITY_LDAP_AUTH]: "Attached LDAP Auth to identity",
|
||||||
[EventType.UPDATE_IDENTITY_LDAP_AUTH]: "Updated LDAP Auth for identity",
|
[EventType.UPDATE_IDENTITY_LDAP_AUTH]: "Updated LDAP Auth for identity",
|
||||||
[EventType.GET_IDENTITY_LDAP_AUTH]: "Retrieved LDAP Auth for identity",
|
[EventType.GET_IDENTITY_LDAP_AUTH]: "Retrieved LDAP Auth for identity",
|
||||||
[EventType.REVOKE_IDENTITY_LDAP_AUTH]: "Revoked LDAP Auth for identity"
|
[EventType.REVOKE_IDENTITY_LDAP_AUTH]: "Revoked LDAP Auth for identity",
|
||||||
|
|
||||||
|
[EventType.UPDATE_ORG]: "Update Organization",
|
||||||
|
|
||||||
|
[EventType.CREATE_PROJECT]: "Create Project",
|
||||||
|
[EventType.UPDATE_PROJECT]: "Update Project",
|
||||||
|
[EventType.DELETE_PROJECT]: "Delete Project"
|
||||||
};
|
};
|
||||||
|
|
||||||
export const userAgentTypeToNameMap: { [K in UserAgentType]: string } = {
|
export const userAgentTypeToNameMap: { [K in UserAgentType]: string } = {
|
||||||
|
|||||||
@@ -131,7 +131,6 @@ export enum EventType {
|
|||||||
CREATE_PROJECT_TEMPLATE = "create-project-template",
|
CREATE_PROJECT_TEMPLATE = "create-project-template",
|
||||||
UPDATE_PROJECT_TEMPLATE = "update-project-template",
|
UPDATE_PROJECT_TEMPLATE = "update-project-template",
|
||||||
DELETE_PROJECT_TEMPLATE = "delete-project-template",
|
DELETE_PROJECT_TEMPLATE = "delete-project-template",
|
||||||
APPLY_PROJECT_TEMPLATE = "apply-project-template",
|
|
||||||
GET_APP_CONNECTIONS = "get-app-connections",
|
GET_APP_CONNECTIONS = "get-app-connections",
|
||||||
GET_AVAILABLE_APP_CONNECTIONS_DETAILS = "get-available-app-connections-details",
|
GET_AVAILABLE_APP_CONNECTIONS_DETAILS = "get-available-app-connections-details",
|
||||||
GET_APP_CONNECTION = "get-app-connection",
|
GET_APP_CONNECTION = "get-app-connection",
|
||||||
@@ -183,5 +182,11 @@ export enum EventType {
|
|||||||
MICROSOFT_TEAMS_WORKFLOW_INTEGRATION_CHECK_INSTALLATION_STATUS = "microsoft-teams-workflow-integration-check-installation-status",
|
MICROSOFT_TEAMS_WORKFLOW_INTEGRATION_CHECK_INSTALLATION_STATUS = "microsoft-teams-workflow-integration-check-installation-status",
|
||||||
MICROSOFT_TEAMS_WORKFLOW_INTEGRATION_GET_TEAMS = "microsoft-teams-workflow-integration-get-teams",
|
MICROSOFT_TEAMS_WORKFLOW_INTEGRATION_GET_TEAMS = "microsoft-teams-workflow-integration-get-teams",
|
||||||
MICROSOFT_TEAMS_WORKFLOW_INTEGRATION_GET = "microsoft-teams-workflow-integration-get",
|
MICROSOFT_TEAMS_WORKFLOW_INTEGRATION_GET = "microsoft-teams-workflow-integration-get",
|
||||||
MICROSOFT_TEAMS_WORKFLOW_INTEGRATION_LIST = "microsoft-teams-workflow-integration-list"
|
MICROSOFT_TEAMS_WORKFLOW_INTEGRATION_LIST = "microsoft-teams-workflow-integration-list",
|
||||||
|
|
||||||
|
UPDATE_ORG = "update-org",
|
||||||
|
|
||||||
|
CREATE_PROJECT = "create-project",
|
||||||
|
UPDATE_PROJECT = "update-project",
|
||||||
|
DELETE_PROJECT = "delete-project"
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user