fix(housekeeping): preserve audit failure evidence

This commit is contained in:
Simo committed 2026-08-26 22:03:02 +02:00
1 parent 89dec9da05
commit 21cd88ccfd
4 files changed
+80 -5

No files matched your search

+17
View File
@@ -237,4 +237,21 @@ describe("getAuditLogs", () => {
const result = await getAuditLogs();
expect(result.rows[0].username).toBe("User #99");
});
it("fails closed beyond the redaction depth cap without mutating the input", async () => {
const sentinel = "raw-depth-secret";
const deep = {
a: { b: { c: { d: { e: { f: { g: { secret: sentinel } } } } } } },
};
insertValues.mockResolvedValue({ id: 1 });
await logAudit({
userId: 1,
action: "update",
target: "user",
before: { deep, state: "before" },
after: { deep, state: "after" },
});
const data = insertValues.mock.calls[0][0];
expect(`${data.before}${data.after}${data.diff}`).not.toContain(sentinel);
expect(deep.a.b.c.d.e.f.g.secret).toBe(sentinel);
});
});
+4 -3
View File
@@ -30,7 +30,8 @@ const SENSITIVE_KEY_RE =
const REDACTED = "[Redacted]";
function sanitizeAuditPayload(value: unknown, depth = 0): unknown {
if (depth > 6 || value == null) return value;
if (depth > 6) return REDACTED;
if (value == null) return value;
if (Array.isArray(value))
return value.map((v) => sanitizeAuditPayload(v, depth + 1));
if (typeof value !== "object") return value;
@@ -108,8 +109,8 @@ export async function getAuditLogs(options: GetLogsOptions = {}) {
const where = search
? or(
like(AdminAuditLog.action, `%${search}%`),
like(AdminAuditLog.target, `%${search}%`),
like(AdminAuditLog.action, `%$search%`),
like(AdminAuditLog.target, `%$search%`),
)
: undefined;