fix(housekeeping): preserve audit failure evidence

This commit is contained in:
Simo committed 2026-08-26 22:03:02 +02:00
1 parent 89dec9da05
commit 21cd88ccfd
4 files changed
+80 -5

No files matched your search

@@ -96,4 +96,37 @@ describe("audit command envelope", () => {
undefined,
);
});
it("preserves the original operation error when failure evidence rejects", async () => {
const original = new Error("operation failed");
const auditFailure = new Error("audit failure");
const writer: HousekeepingAuditWriter = {
write: vi
.fn()
.mockResolvedValueOnce(undefined)
.mockRejectedValueOnce(auditFailure),
};
await expect(
runWithAuditIntent(writer, auditEntry, () => Promise.reject(original)),
).rejects.toBe(original);
expect(
(original as Error & { auditOutcomeError?: unknown }).auditOutcomeError,
).toBe(auditFailure);
});
it("throws a completed-operation error when success evidence rejects", async () => {
const auditFailure = new Error("audit failure");
const writer: HousekeepingAuditWriter = {
write: vi
.fn()
.mockResolvedValueOnce(undefined)
.mockRejectedValueOnce(auditFailure),
};
await expect(
runWithAuditIntent(writer, auditEntry, () => Promise.resolve("done")),
).rejects.toMatchObject({
operationCompleted: true,
operationResult: "done",
auditOutcomeError: auditFailure,
});
});
});
@@ -5,6 +5,17 @@ import type {
} from "@/lib/services/audit";
type AuditOutcome = Exclude<NonNullable<AuditEntry["outcome"]>, "intent">;
export class AuditOutcomePersistenceError<T> extends Error {
readonly operationCompleted = true;
constructor(
readonly operationResult: T,
readonly auditOutcomeError: unknown,
) {
super("Operation completed but audit outcome could not be persisted");
this.name = "AuditOutcomePersistenceError";
}
}
export async function writeIntent(
writer: HousekeepingAuditWriter,
@@ -35,10 +46,23 @@ export async function runWithAuditIntent<T>(
try {
result = await operation();
} catch (error) {
await writeOutcome(writer, entry, "failure", transaction);
try {
await writeOutcome(writer, entry, "failure", transaction);
} catch (auditOutcomeError) {
if (error instanceof Error) {
Object.defineProperty(error, "auditOutcomeError", {
value: auditOutcomeError,
configurable: true,
});
}
}
throw error;
}
await writeOutcome(writer, entry, "success", transaction);
try {
await writeOutcome(writer, entry, "success", transaction);
} catch (auditOutcomeError) {
throw new AuditOutcomePersistenceError(result, auditOutcomeError);
}
return result;
}
+17
View File
@@ -237,4 +237,21 @@ describe("getAuditLogs", () => {
const result = await getAuditLogs();
expect(result.rows[0].username).toBe("User #99");
});
it("fails closed beyond the redaction depth cap without mutating the input", async () => {
const sentinel = "raw-depth-secret";
const deep = {
a: { b: { c: { d: { e: { f: { g: { secret: sentinel } } } } } } },
};
insertValues.mockResolvedValue({ id: 1 });
await logAudit({
userId: 1,
action: "update",
target: "user",
before: { deep, state: "before" },
after: { deep, state: "after" },
});
const data = insertValues.mock.calls[0][0];
expect(`${data.before}${data.after}${data.diff}`).not.toContain(sentinel);
expect(deep.a.b.c.d.e.f.g.secret).toBe(sentinel);
});
});
+4 -3
View File
@@ -30,7 +30,8 @@ const SENSITIVE_KEY_RE =
const REDACTED = "[Redacted]";
function sanitizeAuditPayload(value: unknown, depth = 0): unknown {
if (depth > 6 || value == null) return value;
if (depth > 6) return REDACTED;
if (value == null) return value;
if (Array.isArray(value))
return value.map((v) => sanitizeAuditPayload(v, depth + 1));
if (typeof value !== "object") return value;
@@ -108,8 +109,8 @@ export async function getAuditLogs(options: GetLogsOptions = {}) {
const where = search
? or(
like(AdminAuditLog.action, `%${search}%`),
like(AdminAuditLog.target, `%${search}%`),
like(AdminAuditLog.action, `%$search%`),
like(AdminAuditLog.target, `%$search%`),
)
: undefined;