feat(housekeeping): correlate command audit evidence

This commit is contained in:
Simo committed 2026-08-26 21:56:51 +02:00
1 parent 7c93d3e766
commit 89dec9da05
4 files changed
+226 -4

No files matched your search

+51
View File
@@ -87,6 +87,57 @@ describe("logAudit", () => {
expect(JSON.parse(data.diff).username).toEqual({ from: "foo", to: "bar" });
});
it("redacts sensitive keys recursively in nested objects and arrays", async () => {
insertValues.mockResolvedValue({ id: 1 });
await logAudit({
userId: 1,
action: "update",
target: "user",
before: {
profile: { authTicket: "private-ticket" },
integrations: [{ api_key: "private-key" }],
},
});
const before = JSON.parse(insertValues.mock.calls[0][0].before);
expect(before.profile.authTicket).toBe("[Redacted]");
expect(before.integrations[0].api_key).toBe("[Redacted]");
});
it("persists correlation, domain, outcome, reason, and IP evidence", async () => {
insertValues.mockResolvedValue({ id: 1 });
await logAudit({
userId: 1,
action: "ban",
target: "user",
correlationId: "corr-123",
domain: "people",
outcome: "denied",
reason: "Policy requirement was not met",
ipAddress: "127.0.0.1",
});
expect(insertValues.mock.calls[0][0]).toMatchObject({
correlationId: "corr-123",
domain: "people",
outcome: "denied",
reason: "Policy requirement was not met",
ipAddress: "127.0.0.1",
});
});
it("writes through the injected transaction when one is supplied", async () => {
const transactionValues = vi.fn().mockResolvedValue({ id: 1 });
const transactionInsert = vi.fn(() => ({ values: transactionValues }));
await logAudit({ userId: 1, action: "update", target: "settings" }, {
insert: transactionInsert,
} as never);
expect(transactionInsert).toHaveBeenCalledOnce();
expect(transactionValues).toHaveBeenCalledOnce();
expect(insertValues).not.toHaveBeenCalled();
});
it("omits diff when only before or after is missing", async () => {
insertValues.mockResolvedValue({ id: 1 });
await logAudit({