Revert "Merge pull request 'Complete Housekeeping migration and /ase cutover' (#52) from codex/housekeeping-complete into main"
This reverts commit488b6e57c4, reversing changes made tob506b4499a.
This commit is contained in:
1 parent
488b6e57c4
commit
b1ddda66ff
802 files changed
+61370
-76659
No files matched your search
@@ -1,28 +1,13 @@
|
||||
import { count, desc, inArray, like, or } from "drizzle-orm";
|
||||
import type { HousekeepingDomainId } from "@/features/housekeeping/migration/types";
|
||||
import { AdminAuditLog, type Db, db, User } from "@/lib/db";
|
||||
import { AdminAuditLog, db, User } from "@/lib/db";
|
||||
|
||||
export interface AuditEntry {
|
||||
interface AuditEntry {
|
||||
userId: number;
|
||||
action: string;
|
||||
target: string;
|
||||
targetId?: number;
|
||||
before?: Record<string, unknown>;
|
||||
after?: Record<string, unknown>;
|
||||
correlationId?: string;
|
||||
outcome?: "intent" | "success" | "failure" | "partial" | "denied";
|
||||
reason?: string;
|
||||
domain?: HousekeepingDomainId;
|
||||
ipAddress?: string;
|
||||
}
|
||||
|
||||
export type HousekeepingAuditTransaction = Pick<Db, "insert">;
|
||||
|
||||
export interface HousekeepingAuditWriter {
|
||||
write(
|
||||
entry: AuditEntry,
|
||||
transaction?: HousekeepingAuditTransaction,
|
||||
): Promise<void>;
|
||||
}
|
||||
|
||||
const SENSITIVE_KEY_RE =
|
||||
@@ -30,8 +15,7 @@ const SENSITIVE_KEY_RE =
|
||||
const REDACTED = "[Redacted]";
|
||||
|
||||
function sanitizeAuditPayload(value: unknown, depth = 0): unknown {
|
||||
if (depth > 6) return REDACTED;
|
||||
if (value == null) return value;
|
||||
if (depth > 6 || value == null) return value;
|
||||
if (Array.isArray(value))
|
||||
return value.map((v) => sanitizeAuditPayload(v, depth + 1));
|
||||
if (typeof value !== "object") return value;
|
||||
@@ -63,10 +47,7 @@ function computeDiff(
|
||||
return Object.keys(diff).length > 0 ? diff : null;
|
||||
}
|
||||
|
||||
export async function logAudit(
|
||||
entry: AuditEntry,
|
||||
transaction?: HousekeepingAuditTransaction,
|
||||
): Promise<void> {
|
||||
export async function logAudit(entry: AuditEntry): Promise<void> {
|
||||
const sanitizedBefore = entry.before
|
||||
? (sanitizeAuditPayload(entry.before) as Record<string, unknown>)
|
||||
: undefined;
|
||||
@@ -75,8 +56,7 @@ export async function logAudit(
|
||||
: undefined;
|
||||
const diff = computeDiff(sanitizedBefore, sanitizedAfter);
|
||||
|
||||
const auditWriter: HousekeepingAuditTransaction = transaction ?? db;
|
||||
await auditWriter.insert(AdminAuditLog).values({
|
||||
await db.insert(AdminAuditLog).values({
|
||||
userId: entry.userId,
|
||||
action: entry.action,
|
||||
target: entry.target,
|
||||
@@ -84,19 +64,10 @@ export async function logAudit(
|
||||
before: sanitizedBefore ? JSON.stringify(sanitizedBefore) : null,
|
||||
after: sanitizedAfter ? JSON.stringify(sanitizedAfter) : null,
|
||||
diff: diff ? JSON.stringify(diff) : null,
|
||||
correlationId: entry.correlationId,
|
||||
outcome: entry.outcome,
|
||||
reason: entry.reason,
|
||||
domain: entry.domain,
|
||||
ipAddress: entry.ipAddress,
|
||||
createdAt: new Date().toISOString(),
|
||||
});
|
||||
}
|
||||
|
||||
export const housekeepingAuditWriter: HousekeepingAuditWriter = {
|
||||
write: logAudit,
|
||||
};
|
||||
|
||||
interface GetLogsOptions {
|
||||
search?: string;
|
||||
page?: number;
|
||||
|
||||
Reference in new issue
Block a user