feat(housekeeping): correlate command audit evidence
This commit is contained in:
1 parent
7c93d3e766
commit
89dec9da05
4 files changed
+226
-4
No files matched your search
@@ -87,6 +87,57 @@ describe("logAudit", () => {
|
||||
expect(JSON.parse(data.diff).username).toEqual({ from: "foo", to: "bar" });
|
||||
});
|
||||
|
||||
it("redacts sensitive keys recursively in nested objects and arrays", async () => {
|
||||
insertValues.mockResolvedValue({ id: 1 });
|
||||
await logAudit({
|
||||
userId: 1,
|
||||
action: "update",
|
||||
target: "user",
|
||||
before: {
|
||||
profile: { authTicket: "private-ticket" },
|
||||
integrations: [{ api_key: "private-key" }],
|
||||
},
|
||||
});
|
||||
|
||||
const before = JSON.parse(insertValues.mock.calls[0][0].before);
|
||||
expect(before.profile.authTicket).toBe("[Redacted]");
|
||||
expect(before.integrations[0].api_key).toBe("[Redacted]");
|
||||
});
|
||||
|
||||
it("persists correlation, domain, outcome, reason, and IP evidence", async () => {
|
||||
insertValues.mockResolvedValue({ id: 1 });
|
||||
await logAudit({
|
||||
userId: 1,
|
||||
action: "ban",
|
||||
target: "user",
|
||||
correlationId: "corr-123",
|
||||
domain: "people",
|
||||
outcome: "denied",
|
||||
reason: "Policy requirement was not met",
|
||||
ipAddress: "127.0.0.1",
|
||||
});
|
||||
|
||||
expect(insertValues.mock.calls[0][0]).toMatchObject({
|
||||
correlationId: "corr-123",
|
||||
domain: "people",
|
||||
outcome: "denied",
|
||||
reason: "Policy requirement was not met",
|
||||
ipAddress: "127.0.0.1",
|
||||
});
|
||||
});
|
||||
|
||||
it("writes through the injected transaction when one is supplied", async () => {
|
||||
const transactionValues = vi.fn().mockResolvedValue({ id: 1 });
|
||||
const transactionInsert = vi.fn(() => ({ values: transactionValues }));
|
||||
|
||||
await logAudit({ userId: 1, action: "update", target: "settings" }, {
|
||||
insert: transactionInsert,
|
||||
} as never);
|
||||
|
||||
expect(transactionInsert).toHaveBeenCalledOnce();
|
||||
expect(transactionValues).toHaveBeenCalledOnce();
|
||||
expect(insertValues).not.toHaveBeenCalled();
|
||||
});
|
||||
it("omits diff when only before or after is missing", async () => {
|
||||
insertValues.mockResolvedValue({ id: 1 });
|
||||
await logAudit({
|
||||
|
||||
Reference in new issue
Block a user