mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-08 19:28:16 +00:00
Merge pull request #3617 from Infisical/ENG-2797
feat(audit-logs): Audit org updates, project create / update / delete
This commit is contained in:
@@ -1,3 +1,4 @@
|
|||||||
|
import { ProjectType } from "@app/db/schemas";
|
||||||
import {
|
import {
|
||||||
TCreateProjectTemplateDTO,
|
TCreateProjectTemplateDTO,
|
||||||
TUpdateProjectTemplateDTO
|
TUpdateProjectTemplateDTO
|
||||||
@@ -315,7 +316,6 @@ export enum EventType {
|
|||||||
CREATE_PROJECT_TEMPLATE = "create-project-template",
|
CREATE_PROJECT_TEMPLATE = "create-project-template",
|
||||||
UPDATE_PROJECT_TEMPLATE = "update-project-template",
|
UPDATE_PROJECT_TEMPLATE = "update-project-template",
|
||||||
DELETE_PROJECT_TEMPLATE = "delete-project-template",
|
DELETE_PROJECT_TEMPLATE = "delete-project-template",
|
||||||
APPLY_PROJECT_TEMPLATE = "apply-project-template",
|
|
||||||
GET_APP_CONNECTIONS = "get-app-connections",
|
GET_APP_CONNECTIONS = "get-app-connections",
|
||||||
GET_AVAILABLE_APP_CONNECTIONS_DETAILS = "get-available-app-connections-details",
|
GET_AVAILABLE_APP_CONNECTIONS_DETAILS = "get-available-app-connections-details",
|
||||||
GET_APP_CONNECTION = "get-app-connection",
|
GET_APP_CONNECTION = "get-app-connection",
|
||||||
@@ -375,7 +375,13 @@ export enum EventType {
|
|||||||
MICROSOFT_TEAMS_WORKFLOW_INTEGRATION_LIST = "microsoft-teams-workflow-integration-list",
|
MICROSOFT_TEAMS_WORKFLOW_INTEGRATION_LIST = "microsoft-teams-workflow-integration-list",
|
||||||
|
|
||||||
PROJECT_ASSUME_PRIVILEGE_SESSION_START = "project-assume-privileges-session-start",
|
PROJECT_ASSUME_PRIVILEGE_SESSION_START = "project-assume-privileges-session-start",
|
||||||
PROJECT_ASSUME_PRIVILEGE_SESSION_END = "project-assume-privileges-session-end"
|
PROJECT_ASSUME_PRIVILEGE_SESSION_END = "project-assume-privileges-session-end",
|
||||||
|
|
||||||
|
UPDATE_ORG = "update-org",
|
||||||
|
|
||||||
|
CREATE_PROJECT = "create-project",
|
||||||
|
UPDATE_PROJECT = "update-project",
|
||||||
|
DELETE_PROJECT = "delete-project"
|
||||||
}
|
}
|
||||||
|
|
||||||
export const filterableSecretEvents: EventType[] = [
|
export const filterableSecretEvents: EventType[] = [
|
||||||
@@ -2451,14 +2457,6 @@ interface DeleteProjectTemplateEvent {
|
|||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
interface ApplyProjectTemplateEvent {
|
|
||||||
type: EventType.APPLY_PROJECT_TEMPLATE;
|
|
||||||
metadata: {
|
|
||||||
template: string;
|
|
||||||
projectId: string;
|
|
||||||
};
|
|
||||||
}
|
|
||||||
|
|
||||||
interface GetAppConnectionsEvent {
|
interface GetAppConnectionsEvent {
|
||||||
type: EventType.GET_APP_CONNECTIONS;
|
type: EventType.GET_APP_CONNECTIONS;
|
||||||
metadata: {
|
metadata: {
|
||||||
@@ -2913,6 +2911,59 @@ interface MicrosoftTeamsWorkflowIntegrationUpdateEvent {
|
|||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
|
interface OrgUpdateEvent {
|
||||||
|
type: EventType.UPDATE_ORG;
|
||||||
|
metadata: {
|
||||||
|
name?: string;
|
||||||
|
slug?: string;
|
||||||
|
authEnforced?: boolean;
|
||||||
|
scimEnabled?: boolean;
|
||||||
|
defaultMembershipRoleSlug?: string;
|
||||||
|
enforceMfa?: boolean;
|
||||||
|
selectedMfaMethod?: string;
|
||||||
|
allowSecretSharingOutsideOrganization?: boolean;
|
||||||
|
bypassOrgAuthEnabled?: boolean;
|
||||||
|
userTokenExpiration?: string;
|
||||||
|
secretsProductEnabled?: boolean;
|
||||||
|
pkiProductEnabled?: boolean;
|
||||||
|
kmsProductEnabled?: boolean;
|
||||||
|
sshProductEnabled?: boolean;
|
||||||
|
scannerProductEnabled?: boolean;
|
||||||
|
shareSecretsProductEnabled?: boolean;
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
interface ProjectCreateEvent {
|
||||||
|
type: EventType.CREATE_PROJECT;
|
||||||
|
metadata: {
|
||||||
|
name: string;
|
||||||
|
slug?: string;
|
||||||
|
type: ProjectType;
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
interface ProjectUpdateEvent {
|
||||||
|
type: EventType.UPDATE_PROJECT;
|
||||||
|
metadata: {
|
||||||
|
name?: string;
|
||||||
|
description?: string;
|
||||||
|
autoCapitalization?: boolean;
|
||||||
|
hasDeleteProtection?: boolean;
|
||||||
|
slug?: string;
|
||||||
|
secretSharing?: boolean;
|
||||||
|
pitVersionLimit?: number;
|
||||||
|
auditLogsRetentionDays?: number;
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
interface ProjectDeleteEvent {
|
||||||
|
type: EventType.DELETE_PROJECT;
|
||||||
|
metadata: {
|
||||||
|
id: string;
|
||||||
|
name: string;
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
export type Event =
|
export type Event =
|
||||||
| GetSecretsEvent
|
| GetSecretsEvent
|
||||||
| GetSecretEvent
|
| GetSecretEvent
|
||||||
@@ -3117,7 +3168,6 @@ export type Event =
|
|||||||
| CreateProjectTemplateEvent
|
| CreateProjectTemplateEvent
|
||||||
| UpdateProjectTemplateEvent
|
| UpdateProjectTemplateEvent
|
||||||
| DeleteProjectTemplateEvent
|
| DeleteProjectTemplateEvent
|
||||||
| ApplyProjectTemplateEvent
|
|
||||||
| GetAppConnectionsEvent
|
| GetAppConnectionsEvent
|
||||||
| GetAvailableAppConnectionsDetailsEvent
|
| GetAvailableAppConnectionsDetailsEvent
|
||||||
| GetAppConnectionEvent
|
| GetAppConnectionEvent
|
||||||
@@ -3179,4 +3229,8 @@ export type Event =
|
|||||||
| MicrosoftTeamsWorkflowIntegrationGetTeamsEvent
|
| MicrosoftTeamsWorkflowIntegrationGetTeamsEvent
|
||||||
| MicrosoftTeamsWorkflowIntegrationGetEvent
|
| MicrosoftTeamsWorkflowIntegrationGetEvent
|
||||||
| MicrosoftTeamsWorkflowIntegrationListEvent
|
| MicrosoftTeamsWorkflowIntegrationListEvent
|
||||||
| MicrosoftTeamsWorkflowIntegrationUpdateEvent;
|
| MicrosoftTeamsWorkflowIntegrationUpdateEvent
|
||||||
|
| OrgUpdateEvent
|
||||||
|
| ProjectCreateEvent
|
||||||
|
| ProjectUpdateEvent
|
||||||
|
| ProjectDeleteEvent;
|
||||||
|
|||||||
@@ -312,8 +312,17 @@ export const registerOrgRouter = async (server: FastifyZodProvider) => {
|
|||||||
data: req.body
|
data: req.body
|
||||||
});
|
});
|
||||||
|
|
||||||
|
await server.services.auditLog.createAuditLog({
|
||||||
|
...req.auditLogInfo,
|
||||||
|
orgId: req.permission.orgId,
|
||||||
|
event: {
|
||||||
|
type: EventType.UPDATE_ORG,
|
||||||
|
metadata: req.body
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
return {
|
return {
|
||||||
message: "Successfully changed organization name",
|
message: "Successfully updated organization",
|
||||||
organization
|
organization
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -263,6 +263,17 @@ export const registerProjectRouter = async (server: FastifyZodProvider) => {
|
|||||||
actor: req.permission.type,
|
actor: req.permission.type,
|
||||||
actorOrgId: req.permission.orgId
|
actorOrgId: req.permission.orgId
|
||||||
});
|
});
|
||||||
|
|
||||||
|
await server.services.auditLog.createAuditLog({
|
||||||
|
...req.auditLogInfo,
|
||||||
|
orgId: req.permission.orgId,
|
||||||
|
projectId: req.params.workspaceId,
|
||||||
|
event: {
|
||||||
|
type: EventType.DELETE_PROJECT,
|
||||||
|
metadata: workspace
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
return { workspace };
|
return { workspace };
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
@@ -297,6 +308,17 @@ export const registerProjectRouter = async (server: FastifyZodProvider) => {
|
|||||||
projectId: req.params.workspaceId,
|
projectId: req.params.workspaceId,
|
||||||
name: req.body.name
|
name: req.body.name
|
||||||
});
|
});
|
||||||
|
|
||||||
|
await server.services.auditLog.createAuditLog({
|
||||||
|
...req.auditLogInfo,
|
||||||
|
orgId: req.permission.orgId,
|
||||||
|
projectId: req.params.workspaceId,
|
||||||
|
event: {
|
||||||
|
type: EventType.UPDATE_PROJECT,
|
||||||
|
metadata: req.body
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
return {
|
return {
|
||||||
message: "Successfully changed workspace name",
|
message: "Successfully changed workspace name",
|
||||||
workspace
|
workspace
|
||||||
@@ -375,6 +397,17 @@ export const registerProjectRouter = async (server: FastifyZodProvider) => {
|
|||||||
actor: req.permission.type,
|
actor: req.permission.type,
|
||||||
actorOrgId: req.permission.orgId
|
actorOrgId: req.permission.orgId
|
||||||
});
|
});
|
||||||
|
|
||||||
|
await server.services.auditLog.createAuditLog({
|
||||||
|
...req.auditLogInfo,
|
||||||
|
orgId: req.permission.orgId,
|
||||||
|
projectId: req.params.workspaceId,
|
||||||
|
event: {
|
||||||
|
type: EventType.UPDATE_PROJECT,
|
||||||
|
metadata: req.body
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
return {
|
return {
|
||||||
workspace
|
workspace
|
||||||
};
|
};
|
||||||
@@ -411,6 +444,17 @@ export const registerProjectRouter = async (server: FastifyZodProvider) => {
|
|||||||
projectId: req.params.workspaceId,
|
projectId: req.params.workspaceId,
|
||||||
autoCapitalization: req.body.autoCapitalization
|
autoCapitalization: req.body.autoCapitalization
|
||||||
});
|
});
|
||||||
|
|
||||||
|
await server.services.auditLog.createAuditLog({
|
||||||
|
...req.auditLogInfo,
|
||||||
|
orgId: req.permission.orgId,
|
||||||
|
projectId: req.params.workspaceId,
|
||||||
|
event: {
|
||||||
|
type: EventType.UPDATE_PROJECT,
|
||||||
|
metadata: req.body
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
return {
|
return {
|
||||||
message: "Successfully changed workspace settings",
|
message: "Successfully changed workspace settings",
|
||||||
workspace
|
workspace
|
||||||
@@ -448,6 +492,17 @@ export const registerProjectRouter = async (server: FastifyZodProvider) => {
|
|||||||
projectId: req.params.workspaceId,
|
projectId: req.params.workspaceId,
|
||||||
hasDeleteProtection: req.body.hasDeleteProtection
|
hasDeleteProtection: req.body.hasDeleteProtection
|
||||||
});
|
});
|
||||||
|
|
||||||
|
await server.services.auditLog.createAuditLog({
|
||||||
|
...req.auditLogInfo,
|
||||||
|
orgId: req.permission.orgId,
|
||||||
|
projectId: req.params.workspaceId,
|
||||||
|
event: {
|
||||||
|
type: EventType.UPDATE_PROJECT,
|
||||||
|
metadata: req.body
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
return {
|
return {
|
||||||
message: "Successfully changed workspace settings",
|
message: "Successfully changed workspace settings",
|
||||||
workspace
|
workspace
|
||||||
@@ -486,6 +541,16 @@ export const registerProjectRouter = async (server: FastifyZodProvider) => {
|
|||||||
workspaceSlug: req.params.workspaceSlug
|
workspaceSlug: req.params.workspaceSlug
|
||||||
});
|
});
|
||||||
|
|
||||||
|
await server.services.auditLog.createAuditLog({
|
||||||
|
...req.auditLogInfo,
|
||||||
|
orgId: req.permission.orgId,
|
||||||
|
projectId: workspace.id,
|
||||||
|
event: {
|
||||||
|
type: EventType.UPDATE_PROJECT,
|
||||||
|
metadata: req.body
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
return {
|
return {
|
||||||
message: "Successfully changed workspace version limit",
|
message: "Successfully changed workspace version limit",
|
||||||
workspace
|
workspace
|
||||||
@@ -524,6 +589,16 @@ export const registerProjectRouter = async (server: FastifyZodProvider) => {
|
|||||||
auditLogsRetentionDays: req.body.auditLogsRetentionDays
|
auditLogsRetentionDays: req.body.auditLogsRetentionDays
|
||||||
});
|
});
|
||||||
|
|
||||||
|
await server.services.auditLog.createAuditLog({
|
||||||
|
...req.auditLogInfo,
|
||||||
|
orgId: req.permission.orgId,
|
||||||
|
projectId: workspace.id,
|
||||||
|
event: {
|
||||||
|
type: EventType.UPDATE_PROJECT,
|
||||||
|
metadata: req.body
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
return {
|
return {
|
||||||
message: "Successfully updated project's audit logs retention period",
|
message: "Successfully updated project's audit logs retention period",
|
||||||
workspace
|
workspace
|
||||||
|
|||||||
@@ -206,19 +206,18 @@ export const registerProjectRouter = async (server: FastifyZodProvider) => {
|
|||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
if (req.body.template) {
|
await server.services.auditLog.createAuditLog({
|
||||||
await server.services.auditLog.createAuditLog({
|
...req.auditLogInfo,
|
||||||
...req.auditLogInfo,
|
orgId: req.permission.orgId,
|
||||||
orgId: req.permission.orgId,
|
projectId: project.id,
|
||||||
event: {
|
event: {
|
||||||
type: EventType.APPLY_PROJECT_TEMPLATE,
|
type: EventType.CREATE_PROJECT,
|
||||||
metadata: {
|
metadata: {
|
||||||
template: req.body.template,
|
...req.body,
|
||||||
projectId: project.id
|
name: req.body.projectName
|
||||||
}
|
|
||||||
}
|
}
|
||||||
});
|
}
|
||||||
}
|
});
|
||||||
|
|
||||||
return { project };
|
return { project };
|
||||||
}
|
}
|
||||||
@@ -262,6 +261,16 @@ export const registerProjectRouter = async (server: FastifyZodProvider) => {
|
|||||||
actor: req.permission.type
|
actor: req.permission.type
|
||||||
});
|
});
|
||||||
|
|
||||||
|
await server.services.auditLog.createAuditLog({
|
||||||
|
...req.auditLogInfo,
|
||||||
|
orgId: req.permission.orgId,
|
||||||
|
projectId: project.id,
|
||||||
|
event: {
|
||||||
|
type: EventType.DELETE_PROJECT,
|
||||||
|
metadata: project
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
return project;
|
return project;
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
@@ -341,6 +350,16 @@ export const registerProjectRouter = async (server: FastifyZodProvider) => {
|
|||||||
actorOrgId: req.permission.orgId
|
actorOrgId: req.permission.orgId
|
||||||
});
|
});
|
||||||
|
|
||||||
|
await server.services.auditLog.createAuditLog({
|
||||||
|
...req.auditLogInfo,
|
||||||
|
orgId: req.permission.orgId,
|
||||||
|
projectId: project.id,
|
||||||
|
event: {
|
||||||
|
type: EventType.UPDATE_PROJECT,
|
||||||
|
metadata: req.body
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
return project;
|
return project;
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|||||||
@@ -123,7 +123,6 @@ export const eventToNameMap: { [K in EventType]: string } = {
|
|||||||
[EventType.CREATE_PROJECT_TEMPLATE]: "Create project template",
|
[EventType.CREATE_PROJECT_TEMPLATE]: "Create project template",
|
||||||
[EventType.UPDATE_PROJECT_TEMPLATE]: "Update project template",
|
[EventType.UPDATE_PROJECT_TEMPLATE]: "Update project template",
|
||||||
[EventType.DELETE_PROJECT_TEMPLATE]: "Delete project template",
|
[EventType.DELETE_PROJECT_TEMPLATE]: "Delete project template",
|
||||||
[EventType.APPLY_PROJECT_TEMPLATE]: "Apply project template",
|
|
||||||
[EventType.GET_APP_CONNECTIONS]: "List App Connections",
|
[EventType.GET_APP_CONNECTIONS]: "List App Connections",
|
||||||
[EventType.GET_AVAILABLE_APP_CONNECTIONS_DETAILS]: "List App Connections Details",
|
[EventType.GET_AVAILABLE_APP_CONNECTIONS_DETAILS]: "List App Connections Details",
|
||||||
[EventType.GET_APP_CONNECTION]: "Get App Connection",
|
[EventType.GET_APP_CONNECTION]: "Get App Connection",
|
||||||
@@ -189,7 +188,13 @@ export const eventToNameMap: { [K in EventType]: string } = {
|
|||||||
[EventType.ADD_IDENTITY_LDAP_AUTH]: "Attached LDAP Auth to identity",
|
[EventType.ADD_IDENTITY_LDAP_AUTH]: "Attached LDAP Auth to identity",
|
||||||
[EventType.UPDATE_IDENTITY_LDAP_AUTH]: "Updated LDAP Auth for identity",
|
[EventType.UPDATE_IDENTITY_LDAP_AUTH]: "Updated LDAP Auth for identity",
|
||||||
[EventType.GET_IDENTITY_LDAP_AUTH]: "Retrieved LDAP Auth for identity",
|
[EventType.GET_IDENTITY_LDAP_AUTH]: "Retrieved LDAP Auth for identity",
|
||||||
[EventType.REVOKE_IDENTITY_LDAP_AUTH]: "Revoked LDAP Auth for identity"
|
[EventType.REVOKE_IDENTITY_LDAP_AUTH]: "Revoked LDAP Auth for identity",
|
||||||
|
|
||||||
|
[EventType.UPDATE_ORG]: "Update Organization",
|
||||||
|
|
||||||
|
[EventType.CREATE_PROJECT]: "Create Project",
|
||||||
|
[EventType.UPDATE_PROJECT]: "Update Project",
|
||||||
|
[EventType.DELETE_PROJECT]: "Delete Project"
|
||||||
};
|
};
|
||||||
|
|
||||||
export const userAgentTypeToNameMap: { [K in UserAgentType]: string } = {
|
export const userAgentTypeToNameMap: { [K in UserAgentType]: string } = {
|
||||||
|
|||||||
@@ -131,7 +131,6 @@ export enum EventType {
|
|||||||
CREATE_PROJECT_TEMPLATE = "create-project-template",
|
CREATE_PROJECT_TEMPLATE = "create-project-template",
|
||||||
UPDATE_PROJECT_TEMPLATE = "update-project-template",
|
UPDATE_PROJECT_TEMPLATE = "update-project-template",
|
||||||
DELETE_PROJECT_TEMPLATE = "delete-project-template",
|
DELETE_PROJECT_TEMPLATE = "delete-project-template",
|
||||||
APPLY_PROJECT_TEMPLATE = "apply-project-template",
|
|
||||||
GET_APP_CONNECTIONS = "get-app-connections",
|
GET_APP_CONNECTIONS = "get-app-connections",
|
||||||
GET_AVAILABLE_APP_CONNECTIONS_DETAILS = "get-available-app-connections-details",
|
GET_AVAILABLE_APP_CONNECTIONS_DETAILS = "get-available-app-connections-details",
|
||||||
GET_APP_CONNECTION = "get-app-connection",
|
GET_APP_CONNECTION = "get-app-connection",
|
||||||
@@ -183,5 +182,11 @@ export enum EventType {
|
|||||||
MICROSOFT_TEAMS_WORKFLOW_INTEGRATION_CHECK_INSTALLATION_STATUS = "microsoft-teams-workflow-integration-check-installation-status",
|
MICROSOFT_TEAMS_WORKFLOW_INTEGRATION_CHECK_INSTALLATION_STATUS = "microsoft-teams-workflow-integration-check-installation-status",
|
||||||
MICROSOFT_TEAMS_WORKFLOW_INTEGRATION_GET_TEAMS = "microsoft-teams-workflow-integration-get-teams",
|
MICROSOFT_TEAMS_WORKFLOW_INTEGRATION_GET_TEAMS = "microsoft-teams-workflow-integration-get-teams",
|
||||||
MICROSOFT_TEAMS_WORKFLOW_INTEGRATION_GET = "microsoft-teams-workflow-integration-get",
|
MICROSOFT_TEAMS_WORKFLOW_INTEGRATION_GET = "microsoft-teams-workflow-integration-get",
|
||||||
MICROSOFT_TEAMS_WORKFLOW_INTEGRATION_LIST = "microsoft-teams-workflow-integration-list"
|
MICROSOFT_TEAMS_WORKFLOW_INTEGRATION_LIST = "microsoft-teams-workflow-integration-list",
|
||||||
|
|
||||||
|
UPDATE_ORG = "update-org",
|
||||||
|
|
||||||
|
CREATE_PROJECT = "create-project",
|
||||||
|
UPDATE_PROJECT = "update-project",
|
||||||
|
DELETE_PROJECT = "delete-project"
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user