mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-10 05:28:29 +00:00
Merge pull request #4865 from Infisical/feat/addLoginAuditLogs
Add user login and select organization audit logs
This commit is contained in:
@@ -365,6 +365,8 @@ export enum EventType {
|
|||||||
LOAD_PROJECT_KMS_BACKUP = "load-project-kms-backup",
|
LOAD_PROJECT_KMS_BACKUP = "load-project-kms-backup",
|
||||||
ORG_ADMIN_ACCESS_PROJECT = "org-admin-accessed-project",
|
ORG_ADMIN_ACCESS_PROJECT = "org-admin-accessed-project",
|
||||||
ORG_ADMIN_BYPASS_SSO = "org-admin-bypassed-sso",
|
ORG_ADMIN_BYPASS_SSO = "org-admin-bypassed-sso",
|
||||||
|
USER_LOGIN = "user-login",
|
||||||
|
SELECT_ORGANIZATION = "select-organization",
|
||||||
CREATE_CERTIFICATE_TEMPLATE = "create-certificate-template",
|
CREATE_CERTIFICATE_TEMPLATE = "create-certificate-template",
|
||||||
UPDATE_CERTIFICATE_TEMPLATE = "update-certificate-template",
|
UPDATE_CERTIFICATE_TEMPLATE = "update-certificate-template",
|
||||||
DELETE_CERTIFICATE_TEMPLATE = "delete-certificate-template",
|
DELETE_CERTIFICATE_TEMPLATE = "delete-certificate-template",
|
||||||
@@ -570,6 +572,7 @@ interface UserActorMetadata {
|
|||||||
email?: string | null;
|
email?: string | null;
|
||||||
username: string;
|
username: string;
|
||||||
permission?: Record<string, unknown>;
|
permission?: Record<string, unknown>;
|
||||||
|
authMethod?: string;
|
||||||
}
|
}
|
||||||
|
|
||||||
interface ServiceActorMetadata {
|
interface ServiceActorMetadata {
|
||||||
@@ -2657,6 +2660,22 @@ interface OrgAdminBypassSSOEvent {
|
|||||||
metadata: Record<string, string>; // no metadata yet
|
metadata: Record<string, string>; // no metadata yet
|
||||||
}
|
}
|
||||||
|
|
||||||
|
interface UserLoginEvent {
|
||||||
|
type: EventType.USER_LOGIN;
|
||||||
|
metadata: {
|
||||||
|
organizationId?: string;
|
||||||
|
authProvider?: string;
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
interface SelectOrganizationEvent {
|
||||||
|
type: EventType.SELECT_ORGANIZATION;
|
||||||
|
metadata: {
|
||||||
|
organizationId: string;
|
||||||
|
organizationName: string;
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
interface CreateCertificateTemplateEstConfig {
|
interface CreateCertificateTemplateEstConfig {
|
||||||
type: EventType.CREATE_CERTIFICATE_TEMPLATE_EST_CONFIG;
|
type: EventType.CREATE_CERTIFICATE_TEMPLATE_EST_CONFIG;
|
||||||
metadata: {
|
metadata: {
|
||||||
@@ -4535,4 +4554,6 @@ export type Event =
|
|||||||
| UpdateCertificateRenewalConfigEvent
|
| UpdateCertificateRenewalConfigEvent
|
||||||
| DisableCertificateRenewalConfigEvent
|
| DisableCertificateRenewalConfigEvent
|
||||||
| AutomatedRenewCertificate
|
| AutomatedRenewCertificate
|
||||||
| AutomatedRenewCertificateFailed;
|
| AutomatedRenewCertificateFailed
|
||||||
|
| UserLoginEvent
|
||||||
|
| SelectOrganizationEvent;
|
||||||
|
|||||||
@@ -454,6 +454,30 @@ export const authLoginServiceFactory = ({
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if (organizationId) {
|
||||||
|
await auditLogService.createAuditLog({
|
||||||
|
orgId: organizationId,
|
||||||
|
ipAddress: ip,
|
||||||
|
userAgent,
|
||||||
|
userAgentType: getUserAgentType(userAgent),
|
||||||
|
actor: {
|
||||||
|
type: ActorType.USER,
|
||||||
|
metadata: {
|
||||||
|
email: userEnc.email,
|
||||||
|
userId: userEnc.userId,
|
||||||
|
username: userEnc.username,
|
||||||
|
authMethod
|
||||||
|
}
|
||||||
|
},
|
||||||
|
event: {
|
||||||
|
type: EventType.USER_LOGIN,
|
||||||
|
metadata: {
|
||||||
|
organizationId
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
return {
|
return {
|
||||||
tokens: {
|
tokens: {
|
||||||
accessToken: token.access,
|
accessToken: token.access,
|
||||||
@@ -646,6 +670,29 @@ export const authLoginServiceFactory = ({
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
await auditLogService.createAuditLog({
|
||||||
|
orgId: organizationId,
|
||||||
|
ipAddress,
|
||||||
|
userAgent,
|
||||||
|
userAgentType: getUserAgentType(userAgent),
|
||||||
|
actor: {
|
||||||
|
type: ActorType.USER,
|
||||||
|
metadata: {
|
||||||
|
email: user.email,
|
||||||
|
userId: user.id,
|
||||||
|
username: user.username,
|
||||||
|
authMethod: decodedToken.authMethod
|
||||||
|
}
|
||||||
|
},
|
||||||
|
event: {
|
||||||
|
type: EventType.SELECT_ORGANIZATION,
|
||||||
|
metadata: {
|
||||||
|
organizationId,
|
||||||
|
organizationName: selectedOrg.name
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
return {
|
return {
|
||||||
...tokens,
|
...tokens,
|
||||||
user,
|
user,
|
||||||
@@ -1039,6 +1086,33 @@ export const authLoginServiceFactory = ({
|
|||||||
organizationId
|
organizationId
|
||||||
});
|
});
|
||||||
|
|
||||||
|
if (organizationId) {
|
||||||
|
await auditLogService.createAuditLog({
|
||||||
|
orgId: organizationId,
|
||||||
|
ipAddress: ip,
|
||||||
|
userAgent,
|
||||||
|
userAgentType: getUserAgentType(userAgent),
|
||||||
|
actor: {
|
||||||
|
type: ActorType.USER,
|
||||||
|
metadata: {
|
||||||
|
email: userEnc.email,
|
||||||
|
userId: userEnc.userId,
|
||||||
|
username: userEnc.username,
|
||||||
|
authMethod: decodedProviderToken.authMethod
|
||||||
|
}
|
||||||
|
},
|
||||||
|
event: {
|
||||||
|
type: EventType.USER_LOGIN,
|
||||||
|
metadata: {
|
||||||
|
organizationId,
|
||||||
|
...(isAuthMethodSaml(decodedProviderToken.authMethod) && {
|
||||||
|
authProvider: decodedProviderToken.authMethod
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
return { token, isMfaEnabled: false, user: userEnc, decodedProviderToken } as const;
|
return { token, isMfaEnabled: false, user: userEnc, decodedProviderToken } as const;
|
||||||
};
|
};
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user