A09: record security events in the audit log #16

Closed
opened 2026-08-13 09:35:04 +00:00 by nalum · 0 comments
Owner

The audit log (internal/audit/audit.go) records only entity mutations through the svc seams. Failed logins, successful logins, permission denials, PIN lockouts, session revocations, and API-key usage never reach the admin-visible AuditLog RPC. They exist only as slog lines and OTel counters (telemetry.go:134-163) — and with no OTLP backend wired, the only trace of a brute-force attempt is stdout.

Fix: emit audit entries (a distinct security.* action family) for failed and successful logins, interceptor and service permission denials, PIN lockouts, and session revocations. Keep the existing best-effort queue semantics.


Source: OWASP Top 10 (2025) audit of v1.1.0, 2026-08-13. File references point at the v1.1.0 tree.

The audit log (`internal/audit/audit.go`) records only entity mutations through the svc seams. Failed logins, successful logins, permission denials, PIN lockouts, session revocations, and API-key usage never reach the admin-visible `AuditLog` RPC. They exist only as slog lines and OTel counters (`telemetry.go:134-163`) — and with no OTLP backend wired, the only trace of a brute-force attempt is stdout. **Fix**: emit audit entries (a distinct `security.*` action family) for failed and successful logins, interceptor and service permission denials, PIN lockouts, and session revocations. Keep the existing best-effort queue semantics. --- Source: OWASP Top 10 (2025) audit of `v1.1.0`, 2026-08-13. File references point at the `v1.1.0` tree.
nalum added reference refs/tags/v1.1.0 2026-08-13 09:37:47 +00:00
nalum closed this issue 2026-08-13 11:40:24 +00:00
Sign in to join this conversation.
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
eagraiclainne/app#16
No description provided.