diff --git a/backend/src/ee/services/audit-log-stream/audit-log-stream-service.ts b/backend/src/ee/services/audit-log-stream/audit-log-stream-service.ts index cff4ed49a..fd6e10a28 100644 --- a/backend/src/ee/services/audit-log-stream/audit-log-stream-service.ts +++ b/backend/src/ee/services/audit-log-stream/audit-log-stream-service.ts @@ -1,10 +1,13 @@ import { ForbiddenError } from "@casl/ability"; +import { RawAxiosRequestHeaders } from "axios"; import { SecretKeyEncoding } from "@app/db/schemas"; +import { request } from "@app/lib/config/request"; import { infisicalSymmetricDecrypt, infisicalSymmetricEncypt } from "@app/lib/crypto/encryption"; import { BadRequestError } from "@app/lib/errors"; import { validateLocalIps } from "@app/lib/validator"; +import { AUDIT_LOG_STREAM_TIMEOUT } from "../audit-log/audit-log-queue"; import { TLicenseServiceFactory } from "../license/license-service"; import { OrgPermissionActions, OrgPermissionSubjects } from "../permission/org-permission"; import { TPermissionServiceFactory } from "../permission/permission-service"; @@ -57,6 +60,21 @@ export const auditLogStreamServiceFactory = ({ "Failed to create audit log streams due to plan limit reached. Kindly contact Infisical to add more streams." }); } + + // testing connection first + const headers: RawAxiosRequestHeaders = { "Content-Type": "application/json" }; + if (token) headers.Authorization = `Bearer ${token}`; + await request.post( + url, + { ping: "ok" }, + { + headers, + // request timeout + timeout: AUDIT_LOG_STREAM_TIMEOUT, + // connection timeout + signal: AbortSignal.timeout(AUDIT_LOG_STREAM_TIMEOUT) + } + ); const encryptedToken = token ? infisicalSymmetricEncypt(token) : undefined; const logStream = await auditLogStreamDAL.create({ orgId: actorOrgId, @@ -99,6 +117,22 @@ export const auditLogStreamServiceFactory = ({ ForbiddenError.from(permission).throwUnlessCan(OrgPermissionActions.Edit, OrgPermissionSubjects.Settings); if (url) validateLocalIps(url); + + // testing connection first + const headers: RawAxiosRequestHeaders = { "Content-Type": "application/json" }; + if (token) headers.Authorization = `Bearer ${token}`; + await request.post( + url || logStream.url, + { ping: "ok" }, + { + headers, + // request timeout + timeout: AUDIT_LOG_STREAM_TIMEOUT, + // connection timeout + signal: AbortSignal.timeout(AUDIT_LOG_STREAM_TIMEOUT) + } + ); + const encryptedToken = token ? infisicalSymmetricEncypt(token) : undefined; const updatedLogStream = await auditLogStreamDAL.updateById(id, { url, diff --git a/backend/src/ee/services/audit-log/audit-log-queue.ts b/backend/src/ee/services/audit-log/audit-log-queue.ts index bf03d7548..a4d504d35 100644 --- a/backend/src/ee/services/audit-log/audit-log-queue.ts +++ b/backend/src/ee/services/audit-log/audit-log-queue.ts @@ -24,7 +24,7 @@ export type TAuditLogQueueServiceFactory = ReturnType ({ rbac: false, customRateLimits: false, customAlerts: false, - auditLogs: false, - auditLogsRetentionDays: 0, - auditLogStreams: false, + auditLogs: true, + auditLogsRetentionDays: 3, + auditLogStreams: true, auditLogStreamLimit: 3, samlSSO: false, scim: false, diff --git a/backend/src/lib/api-docs/constants.ts b/backend/src/lib/api-docs/constants.ts index 40043c900..b4c0c2a5c 100644 --- a/backend/src/lib/api-docs/constants.ts +++ b/backend/src/lib/api-docs/constants.ts @@ -617,12 +617,12 @@ export const INTEGRATION = { export const AUDIT_LOG_STREAMS = { CREATE: { - url: "The socket URL to push logs to.", - token: "Authentication token from the logging provider" + url: "The HTTP URL to push logs to.", + token: "Authentication token for the external provider used for identification." }, UPDATE: { id: "The ID of the audit log stream to update.", - url: "The socket URL to push logs to.", + url: "The HTTP URL to push logs to.", token: "Authentication token for the external provider used for identification." }, DELETE: { diff --git a/frontend/src/views/Settings/OrgSettingsPage/components/AuditLogStreamTab/AuditLogStreamForm.tsx b/frontend/src/views/Settings/OrgSettingsPage/components/AuditLogStreamTab/AuditLogStreamForm.tsx index 7f0ec24e8..66acea296 100644 --- a/frontend/src/views/Settings/OrgSettingsPage/components/AuditLogStreamTab/AuditLogStreamForm.tsx +++ b/frontend/src/views/Settings/OrgSettingsPage/components/AuditLogStreamTab/AuditLogStreamForm.tsx @@ -64,7 +64,7 @@ export const AuditLogStreamForm = ({ id = "", onClose }: Props) => { const handleFormSubmit = async ({ token, url }: TForm) => { if (isSubmitting) return; if (isEdit) { - handleAuditLogStreamEdit({ token, url }); + await handleAuditLogStreamEdit({ token, url }); return; } try { @@ -102,7 +102,7 @@ export const AuditLogStreamForm = ({ id = "", onClose }: Props) => { control={control} name="url" render={({ field, fieldState: { error } }) => ( - + )} @@ -118,7 +118,7 @@ export const AuditLogStreamForm = ({ id = "", onClose }: Props) => { errorText={error?.message} helperText="The bearer token used to authenticate with the logging provider endpoint" > - + )} />