A09: record security events in the audit log #16
Labels
No labels
adr
android
area/calendar
area/design-system
area/i18n
area/jobs
area/offline
area/server
area/testing
bug
ci
duplicate
enhancement
help wanted
invalid
notifications
question
reliability
security
severity/low
severity/medium
tracking
web
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
eagraiclainne/app#16
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The audit log (
internal/audit/audit.go) records only entity mutations through the svc seams. Failed logins, successful logins, permission denials, PIN lockouts, session revocations, and API-key usage never reach the admin-visibleAuditLogRPC. They exist only as slog lines and OTel counters (telemetry.go:134-163) — and with no OTLP backend wired, the only trace of a brute-force attempt is stdout.Fix: emit audit entries (a distinct
security.*action family) for failed and successful logins, interceptor and service permission denials, PIN lockouts, and session revocations. Keep the existing best-effort queue semantics.Source: OWASP Top 10 (2025) audit of
v1.1.0, 2026-08-13. File references point at thev1.1.0tree.