fix(housekeeping): preserve audit failure evidence
This commit is contained in:
1 parent
89dec9da05
commit
21cd88ccfd
4 files changed
+80
-5
No files matched your search
@@ -237,4 +237,21 @@ describe("getAuditLogs", () => {
|
||||
const result = await getAuditLogs();
|
||||
expect(result.rows[0].username).toBe("User #99");
|
||||
});
|
||||
it("fails closed beyond the redaction depth cap without mutating the input", async () => {
|
||||
const sentinel = "raw-depth-secret";
|
||||
const deep = {
|
||||
a: { b: { c: { d: { e: { f: { g: { secret: sentinel } } } } } } },
|
||||
};
|
||||
insertValues.mockResolvedValue({ id: 1 });
|
||||
await logAudit({
|
||||
userId: 1,
|
||||
action: "update",
|
||||
target: "user",
|
||||
before: { deep, state: "before" },
|
||||
after: { deep, state: "after" },
|
||||
});
|
||||
const data = insertValues.mock.calls[0][0];
|
||||
expect(`${data.before}${data.after}${data.diff}`).not.toContain(sentinel);
|
||||
expect(deep.a.b.c.d.e.f.g.secret).toBe(sentinel);
|
||||
});
|
||||
});
|
||||
@@ -30,7 +30,8 @@ const SENSITIVE_KEY_RE =
|
||||
const REDACTED = "[Redacted]";
|
||||
|
||||
function sanitizeAuditPayload(value: unknown, depth = 0): unknown {
|
||||
if (depth > 6 || value == null) return value;
|
||||
if (depth > 6) return REDACTED;
|
||||
if (value == null) return value;
|
||||
if (Array.isArray(value))
|
||||
return value.map((v) => sanitizeAuditPayload(v, depth + 1));
|
||||
if (typeof value !== "object") return value;
|
||||
@@ -108,8 +109,8 @@ export async function getAuditLogs(options: GetLogsOptions = {}) {
|
||||
|
||||
const where = search
|
||||
? or(
|
||||
like(AdminAuditLog.action, `%${search}%`),
|
||||
like(AdminAuditLog.target, `%${search}%`),
|
||||
like(AdminAuditLog.action, `%$search%`),
|
||||
like(AdminAuditLog.target, `%$search%`),
|
||||
)
|
||||
: undefined;
|
||||
|
||||
|
||||
Reference in new issue
Block a user