mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 09:28:06 +00:00
feat: more expendable audit logs
This commit is contained in:
@@ -6,6 +6,9 @@ import { DatabaseError } from "@app/lib/errors";
|
|||||||
import { ormify, selectAllTableCols, stripUndefinedInWhere } from "@app/lib/knex";
|
import { ormify, selectAllTableCols, stripUndefinedInWhere } from "@app/lib/knex";
|
||||||
import { logger } from "@app/lib/logger";
|
import { logger } from "@app/lib/logger";
|
||||||
import { QueueName } from "@app/queue";
|
import { QueueName } from "@app/queue";
|
||||||
|
import { ActorType } from "@app/services/auth/auth-type";
|
||||||
|
|
||||||
|
import { EventType } from "./audit-log-types";
|
||||||
|
|
||||||
export type TAuditLogDALFactory = ReturnType<typeof auditLogDALFactory>;
|
export type TAuditLogDALFactory = ReturnType<typeof auditLogDALFactory>;
|
||||||
|
|
||||||
@@ -25,7 +28,24 @@ export const auditLogDALFactory = (db: TDbClient) => {
|
|||||||
const auditLogOrm = ormify(db, TableName.AuditLog);
|
const auditLogOrm = ormify(db, TableName.AuditLog);
|
||||||
|
|
||||||
const find = async (
|
const find = async (
|
||||||
{ orgId, projectId, userAgentType, startDate, endDate, limit = 20, offset = 0, actor, eventType }: TFindQuery,
|
{
|
||||||
|
orgId,
|
||||||
|
projectId,
|
||||||
|
userAgentType,
|
||||||
|
startDate,
|
||||||
|
endDate,
|
||||||
|
limit = 20,
|
||||||
|
offset = 0,
|
||||||
|
actorId,
|
||||||
|
actorType,
|
||||||
|
eventType,
|
||||||
|
eventMetadata
|
||||||
|
}: Omit<TFindQuery, "actor" | "eventType"> & {
|
||||||
|
actorId?: string;
|
||||||
|
actorType?: ActorType;
|
||||||
|
eventType?: EventType[];
|
||||||
|
eventMetadata?: Record<string, string>;
|
||||||
|
},
|
||||||
tx?: Knex
|
tx?: Knex
|
||||||
) => {
|
) => {
|
||||||
try {
|
try {
|
||||||
@@ -34,7 +54,6 @@ export const auditLogDALFactory = (db: TDbClient) => {
|
|||||||
stripUndefinedInWhere({
|
stripUndefinedInWhere({
|
||||||
projectId,
|
projectId,
|
||||||
[`${TableName.AuditLog}.orgId`]: orgId,
|
[`${TableName.AuditLog}.orgId`]: orgId,
|
||||||
eventType,
|
|
||||||
userAgentType
|
userAgentType
|
||||||
})
|
})
|
||||||
)
|
)
|
||||||
@@ -52,8 +71,22 @@ export const auditLogDALFactory = (db: TDbClient) => {
|
|||||||
.offset(offset)
|
.offset(offset)
|
||||||
.orderBy(`${TableName.AuditLog}.createdAt`, "desc");
|
.orderBy(`${TableName.AuditLog}.createdAt`, "desc");
|
||||||
|
|
||||||
if (actor) {
|
if (actorId) {
|
||||||
void sqlQuery.whereRaw(`"actorMetadata"->>'userId' = ?`, [actor]);
|
void sqlQuery.whereRaw(`"actorMetadata"->>'userId' = ?`, [actorId]);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (eventMetadata && Object.keys(eventMetadata).length) {
|
||||||
|
Object.entries(eventMetadata).forEach(([key, value]) => {
|
||||||
|
void sqlQuery.whereRaw(`"eventMetadata"->>'${key}' = ?`, [value]);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
if (actorType) {
|
||||||
|
void sqlQuery.where("actor", actorType);
|
||||||
|
}
|
||||||
|
|
||||||
|
if (eventType?.length) {
|
||||||
|
void sqlQuery.whereIn("eventType", eventType);
|
||||||
}
|
}
|
||||||
|
|
||||||
if (startDate) {
|
if (startDate) {
|
||||||
|
|||||||
@@ -23,25 +23,12 @@ export const auditLogServiceFactory = ({
|
|||||||
auditLogQueue,
|
auditLogQueue,
|
||||||
permissionService
|
permissionService
|
||||||
}: TAuditLogServiceFactoryDep) => {
|
}: TAuditLogServiceFactoryDep) => {
|
||||||
const listAuditLogs = async ({
|
const listAuditLogs = async ({ actorAuthMethod, actorId, actorOrgId, actor, filter }: TListProjectAuditLogDTO) => {
|
||||||
userAgentType,
|
if (filter.projectId) {
|
||||||
eventType,
|
|
||||||
offset,
|
|
||||||
limit,
|
|
||||||
endDate,
|
|
||||||
startDate,
|
|
||||||
actor,
|
|
||||||
actorId,
|
|
||||||
actorOrgId,
|
|
||||||
actorAuthMethod,
|
|
||||||
projectId,
|
|
||||||
auditLogActor
|
|
||||||
}: TListProjectAuditLogDTO) => {
|
|
||||||
if (projectId) {
|
|
||||||
const { permission } = await permissionService.getProjectPermission(
|
const { permission } = await permissionService.getProjectPermission(
|
||||||
actor,
|
actor,
|
||||||
actorId,
|
actorId,
|
||||||
projectId,
|
filter.projectId,
|
||||||
actorAuthMethod,
|
actorAuthMethod,
|
||||||
actorOrgId
|
actorOrgId
|
||||||
);
|
);
|
||||||
@@ -65,14 +52,16 @@ export const auditLogServiceFactory = ({
|
|||||||
// If project ID is not provided, then we need to return all the audit logs for the organization itself.
|
// If project ID is not provided, then we need to return all the audit logs for the organization itself.
|
||||||
|
|
||||||
const auditLogs = await auditLogDAL.find({
|
const auditLogs = await auditLogDAL.find({
|
||||||
startDate,
|
startDate: filter.startDate,
|
||||||
endDate,
|
endDate: filter.endDate,
|
||||||
limit,
|
limit: filter.limit,
|
||||||
offset,
|
offset: filter.offset,
|
||||||
eventType,
|
eventType: filter.eventType,
|
||||||
userAgentType,
|
userAgentType: filter.userAgentType,
|
||||||
actor: auditLogActor,
|
actorId: filter.auditLogActorId,
|
||||||
...(projectId ? { projectId } : { orgId: actorOrgId })
|
actorType: filter.actorType,
|
||||||
|
eventMetadata: filter.eventMetadata,
|
||||||
|
...(filter.projectId ? { projectId: filter.projectId } : { orgId: actorOrgId })
|
||||||
});
|
});
|
||||||
|
|
||||||
return auditLogs.map(({ eventType: logEventType, actor: eActor, actorMetadata, eventMetadata, ...el }) => ({
|
return auditLogs.map(({ eventType: logEventType, actor: eActor, actorMetadata, eventMetadata, ...el }) => ({
|
||||||
|
|||||||
@@ -15,6 +15,7 @@ export type TListProjectAuditLogDTO = {
|
|||||||
projectId?: string;
|
projectId?: string;
|
||||||
auditLogActorId?: string;
|
auditLogActorId?: string;
|
||||||
actorType?: ActorType;
|
actorType?: ActorType;
|
||||||
|
eventMetadata?: Record<string, string>;
|
||||||
};
|
};
|
||||||
} & Omit<TProjectPermission, "projectId">;
|
} & Omit<TProjectPermission, "projectId">;
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user