feat(audit): record security events in the audit log #34
No reviewers
Labels
No labels
adr
android
area/calendar
area/design-system
area/i18n
area/jobs
area/offline
area/server
area/testing
bug
ci
duplicate
enhancement
help wanted
invalid
notifications
question
reliability
security
severity/low
severity/medium
tracking
web
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
eagraiclainne/app!34
Loading…
Reference in a new issue
No description provided.
Delete branch "feat/audit-security-events"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Stacked on #32 (
fix/login-timing-oracle).Auth events existed only as slog lines + OTel counters — invisible to the admin AuditLog view. New
audit.RecordSecurityseam rides the existing best-effort queue/sink (no proto change: thesecurity.*action name travels in entity_type, so SearchAudit filters work as-is).Recorded: failed logins (target = account uid; an attacker-submitted unknown email is NEVER stored — log injection into the admin UI), successful logins, password lock transitions (emitted after the commit, so the log never claims a rolled-back lock), PIN lock transitions, matrix denials (via a new
auth.Config.OnDeniedhook — audit imports auth, so auth cannot import audit back), and svc resource-guard denials.Skipped, recorded in the report: session revocations (mid-transaction, no clean after-commit seam; 5 of 6 call sites are routine housekeeping) and per-service denial scatter sites (the shared guards cover the seam paths).
Admin UI renders the new rows via its existing raw-fallback path; full entry in the expanded JSON.
Fixes #16
🤖 Generated with Claude Code
f83523cee43d941607e0