mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-03 17:26:07 +00:00
More audit logs
This commit is contained in:
@@ -50,6 +50,7 @@ import { WorkflowIntegration } from "@app/services/workflow-integration/workflow
|
|||||||
|
|
||||||
import { KmipPermission } from "../kmip/kmip-enum";
|
import { KmipPermission } from "../kmip/kmip-enum";
|
||||||
import { ApprovalStatus } from "../secret-approval-request/secret-approval-request-types";
|
import { ApprovalStatus } from "../secret-approval-request/secret-approval-request-types";
|
||||||
|
import { AcmeIdentifierType } from "../pki-acme/pki-acme-schemas";
|
||||||
|
|
||||||
export type TListProjectAuditLogDTO = {
|
export type TListProjectAuditLogDTO = {
|
||||||
filter: {
|
filter: {
|
||||||
@@ -79,7 +80,8 @@ export type TCreateAuditLogDTO = {
|
|||||||
| PlatformActor
|
| PlatformActor
|
||||||
| UnknownUserActor
|
| UnknownUserActor
|
||||||
| KmipClientActor
|
| KmipClientActor
|
||||||
| AcmeProfileActor;
|
| AcmeProfileActor
|
||||||
|
| AcmeAccountActor;
|
||||||
orgId?: string;
|
orgId?: string;
|
||||||
projectId?: string;
|
projectId?: string;
|
||||||
} & BaseAuthData;
|
} & BaseAuthData;
|
||||||
@@ -579,7 +581,8 @@ export enum EventType {
|
|||||||
|
|
||||||
// PKI ACME
|
// PKI ACME
|
||||||
CREATE_ACME_ACCOUNT = "create-acme-account",
|
CREATE_ACME_ACCOUNT = "create-acme-account",
|
||||||
RETRIEVE_ACME_ACCOUNT = "retrieve-acme-account"
|
RETRIEVE_ACME_ACCOUNT = "retrieve-acme-account",
|
||||||
|
CREATE_ACME_ORDER = "create-acme-order"
|
||||||
}
|
}
|
||||||
|
|
||||||
export const filterableSecretEvents: EventType[] = [
|
export const filterableSecretEvents: EventType[] = [
|
||||||
@@ -624,6 +627,11 @@ interface AcmeProfileActorMetadata {
|
|||||||
profileId: string;
|
profileId: string;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
interface AcmeAccountActorMetadata {
|
||||||
|
profileId: string;
|
||||||
|
accountId: string;
|
||||||
|
}
|
||||||
|
|
||||||
interface UnknownUserActorMetadata {}
|
interface UnknownUserActorMetadata {}
|
||||||
|
|
||||||
export interface UserActor {
|
export interface UserActor {
|
||||||
@@ -666,6 +674,11 @@ export interface AcmeProfileActor {
|
|||||||
metadata: AcmeProfileActorMetadata;
|
metadata: AcmeProfileActorMetadata;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
export interface AcmeAccountActor {
|
||||||
|
type: ActorType.ACME_ACCOUNT;
|
||||||
|
metadata: AcmeAccountActorMetadata;
|
||||||
|
}
|
||||||
|
|
||||||
export type Actor =
|
export type Actor =
|
||||||
| UserActor
|
| UserActor
|
||||||
| ServiceActor
|
| ServiceActor
|
||||||
@@ -4406,6 +4419,17 @@ interface RetrieveAcmeAccountEvent {
|
|||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
|
interface CreateAcmeOrderEvent {
|
||||||
|
type: EventType.CREATE_ACME_ORDER;
|
||||||
|
metadata: {
|
||||||
|
orderId: string;
|
||||||
|
identifiers: Array<{
|
||||||
|
type: AcmeIdentifierType;
|
||||||
|
value: string;
|
||||||
|
}>;
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
export type Event =
|
export type Event =
|
||||||
| CreateSubOrganizationEvent
|
| CreateSubOrganizationEvent
|
||||||
| UpdateSubOrganizationEvent
|
| UpdateSubOrganizationEvent
|
||||||
@@ -4808,4 +4832,5 @@ export type Event =
|
|||||||
| ApprovalRequestGrantGetEvent
|
| ApprovalRequestGrantGetEvent
|
||||||
| ApprovalRequestGrantRevokeEvent
|
| ApprovalRequestGrantRevokeEvent
|
||||||
| CreateAcmeAccountEvent
|
| CreateAcmeAccountEvent
|
||||||
| RetrieveAcmeAccountEvent;
|
| RetrieveAcmeAccountEvent
|
||||||
|
| CreateAcmeOrderEvent;
|
||||||
|
|||||||
@@ -685,7 +685,26 @@ export const pkiAcmeServiceFactory = ({
|
|||||||
})),
|
})),
|
||||||
tx
|
tx
|
||||||
);
|
);
|
||||||
// TODO: create audit log here
|
await auditLogService.createAuditLog({
|
||||||
|
projectId: account.profileId,
|
||||||
|
actor: {
|
||||||
|
type: ActorType.ACME_ACCOUNT,
|
||||||
|
metadata: {
|
||||||
|
profileId: account.profileId,
|
||||||
|
accountId: account.id
|
||||||
|
}
|
||||||
|
},
|
||||||
|
event: {
|
||||||
|
type: EventType.CREATE_ACME_ORDER,
|
||||||
|
metadata: {
|
||||||
|
orderId: createdOrder.id,
|
||||||
|
identifiers: authorizations.map((auth) => ({
|
||||||
|
type: auth.identifierType as AcmeIdentifierType,
|
||||||
|
value: auth.identifierValue
|
||||||
|
}))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
return { ...createdOrder, authorizations, account };
|
return { ...createdOrder, authorizations, account };
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user