Stand vor Einführung des Nacht-Agenten
This commit is contained in:
commit
4763548bfb
168 changed files with 12726 additions and 0 deletions
27
apps/api/src/modules/audit/index.ts
Normal file
27
apps/api/src/modules/audit/index.ts
Normal file
|
|
@ -0,0 +1,27 @@
|
|||
import type { FastifyInstance } from 'fastify';
|
||||
import { z } from 'zod';
|
||||
import { query } from '../../core/db.js';
|
||||
import { verifyAuditChain } from '../../core/audit.js';
|
||||
import { requirePermission } from '../../core/auth.js';
|
||||
import type { KcModule } from '../../core/module.js';
|
||||
|
||||
export const auditModule: KcModule = {
|
||||
name: 'audit',
|
||||
register(app: FastifyInstance) {
|
||||
app.get('/admin/audit', async (req) => {
|
||||
requirePermission(req, 'audit.read');
|
||||
const q = z.object({ action: z.string().max(100).optional(), actor: z.string().uuid().optional(), org: z.string().uuid().optional(), limit: z.coerce.number().int().min(1).max(500).default(100) }).parse(req.query);
|
||||
const rows = await query(
|
||||
`SELECT id, ts, actor_type, actor_id, org_id, action, resource_type, resource_id, result, error_class, correlation_id, ip, before_json, after_json
|
||||
FROM audit_events WHERE (? IS NULL OR action LIKE CONCAT(?, '%')) AND (? IS NULL OR actor_id = ?) AND (? IS NULL OR org_id = ?)
|
||||
ORDER BY id DESC LIMIT ?`,
|
||||
[q.action ?? null, q.action ?? null, q.actor ?? null, q.actor ?? null, q.org ?? null, q.org ?? null, q.limit],
|
||||
);
|
||||
return rows.map((r) => ({ id: r.id, ts: r.ts, actorType: r.actor_type, actorId: r.actor_id, orgId: r.org_id, action: r.action, resourceType: r.resource_type, resourceId: r.resource_id, result: r.result, errorClass: r.error_class, correlationId: r.correlation_id, ip: r.ip, before: r.before_json, after: r.after_json }));
|
||||
});
|
||||
app.get('/admin/audit/verify', async (req) => {
|
||||
requirePermission(req, 'audit.read');
|
||||
return verifyAuditChain();
|
||||
});
|
||||
},
|
||||
};
|
||||
Loading…
Add table
Add a link
Reference in a new issue