Revert "Merge pull request 'Complete Housekeeping migration and /ase cutover' (#52) from codex/housekeeping-complete into main"
This reverts commit488b6e57c4, reversing changes made tob506b4499a.
This commit is contained in:
1 parent
488b6e57c4
commit
b1ddda66ff
802 files changed
+61370
-76659
No files matched your search
@@ -87,61 +87,6 @@ describe("logAudit", () => {
|
||||
expect(JSON.parse(data.diff).username).toEqual({ from: "foo", to: "bar" });
|
||||
});
|
||||
|
||||
it("redacts sensitive keys recursively in nested objects and arrays", async () => {
|
||||
insertValues.mockResolvedValue({ id: 1 });
|
||||
await logAudit({
|
||||
userId: 1,
|
||||
action: "update",
|
||||
target: "user",
|
||||
before: {
|
||||
profile: {
|
||||
authTicket: "private-ticket",
|
||||
credentials: { newPassword: "one-time-password" },
|
||||
},
|
||||
integrations: [{ api_key: "private-key" }],
|
||||
},
|
||||
});
|
||||
|
||||
const before = JSON.parse(insertValues.mock.calls[0][0].before);
|
||||
expect(before.profile.authTicket).toBe("[Redacted]");
|
||||
expect(before.profile.credentials.newPassword).toBe("[Redacted]");
|
||||
expect(before.integrations[0].api_key).toBe("[Redacted]");
|
||||
});
|
||||
|
||||
it("persists correlation, domain, outcome, reason, and IP evidence", async () => {
|
||||
insertValues.mockResolvedValue({ id: 1 });
|
||||
await logAudit({
|
||||
userId: 1,
|
||||
action: "ban",
|
||||
target: "user",
|
||||
correlationId: "corr-123",
|
||||
domain: "people",
|
||||
outcome: "denied",
|
||||
reason: "Policy requirement was not met",
|
||||
ipAddress: "127.0.0.1",
|
||||
});
|
||||
|
||||
expect(insertValues.mock.calls[0][0]).toMatchObject({
|
||||
correlationId: "corr-123",
|
||||
domain: "people",
|
||||
outcome: "denied",
|
||||
reason: "Policy requirement was not met",
|
||||
ipAddress: "127.0.0.1",
|
||||
});
|
||||
});
|
||||
|
||||
it("writes through the injected transaction when one is supplied", async () => {
|
||||
const transactionValues = vi.fn().mockResolvedValue({ id: 1 });
|
||||
const transactionInsert = vi.fn(() => ({ values: transactionValues }));
|
||||
|
||||
await logAudit({ userId: 1, action: "update", target: "settings" }, {
|
||||
insert: transactionInsert,
|
||||
} as never);
|
||||
|
||||
expect(transactionInsert).toHaveBeenCalledOnce();
|
||||
expect(transactionValues).toHaveBeenCalledOnce();
|
||||
expect(insertValues).not.toHaveBeenCalled();
|
||||
});
|
||||
it("omits diff when only before or after is missing", async () => {
|
||||
insertValues.mockResolvedValue({ id: 1 });
|
||||
await logAudit({
|
||||
@@ -241,21 +186,4 @@ describe("getAuditLogs", () => {
|
||||
const result = await getAuditLogs();
|
||||
expect(result.rows[0].username).toBe("User #99");
|
||||
});
|
||||
it("fails closed beyond the redaction depth cap without mutating the input", async () => {
|
||||
const sentinel = "raw-depth-secret";
|
||||
const deep = {
|
||||
a: { b: { c: { d: { e: { f: { g: { secret: sentinel } } } } } } },
|
||||
};
|
||||
insertValues.mockResolvedValue({ id: 1 });
|
||||
await logAudit({
|
||||
userId: 1,
|
||||
action: "update",
|
||||
target: "user",
|
||||
before: { deep, state: "before" },
|
||||
after: { deep, state: "after" },
|
||||
});
|
||||
const data = insertValues.mock.calls[0][0];
|
||||
expect(`${data.before}${data.after}${data.diff}`).not.toContain(sentinel);
|
||||
expect(deep.a.b.c.d.e.f.g.secret).toBe(sentinel);
|
||||
});
|
||||
});
|
||||
Reference in new issue
Block a user