Add audit log feature for recording all actions
Adds audit logging that records all authorized actions performed by users and API keys. The audit log is automatically populated whenever the authorizer approves an action, and is queryable via GraphQL, MCP, and CLI interfaces. Permission checks are excluded via a dry-run flag to avoid phantom entries on page loads. Signed-off-by: Bryan Frimin <bryan@getprobo.com>
This commit is contained in:
@@ -524,6 +524,34 @@ enum WebhookSubscriptionOrderField
|
||||
)
|
||||
}
|
||||
|
||||
enum AuditLogActorType
|
||||
@goModel(
|
||||
model: "go.probo.inc/probo/pkg/coredata.AuditLogActorType"
|
||||
) {
|
||||
USER
|
||||
@goEnum(
|
||||
value: "go.probo.inc/probo/pkg/coredata.AuditLogActorTypeUser"
|
||||
)
|
||||
API_KEY
|
||||
@goEnum(
|
||||
value: "go.probo.inc/probo/pkg/coredata.AuditLogActorTypeAPIKey"
|
||||
)
|
||||
SYSTEM
|
||||
@goEnum(
|
||||
value: "go.probo.inc/probo/pkg/coredata.AuditLogActorTypeSystem"
|
||||
)
|
||||
}
|
||||
|
||||
enum AuditLogEntryOrderField
|
||||
@goModel(
|
||||
model: "go.probo.inc/probo/pkg/coredata.AuditLogEntryOrderField"
|
||||
) {
|
||||
CREATED_AT
|
||||
@goEnum(
|
||||
value: "go.probo.inc/probo/pkg/coredata.AuditLogEntryOrderFieldCreatedAt"
|
||||
)
|
||||
}
|
||||
|
||||
enum RiskOrderField
|
||||
@goModel(model: "go.probo.inc/probo/pkg/coredata.RiskOrderField") {
|
||||
CREATED_AT
|
||||
@@ -2018,6 +2046,15 @@ type Organization implements Node {
|
||||
orderBy: WebhookSubscriptionOrder
|
||||
): WebhookSubscriptionConnection! @goField(forceResolver: true)
|
||||
|
||||
auditLogEntries(
|
||||
first: Int
|
||||
after: CursorKey
|
||||
last: Int
|
||||
before: CursorKey
|
||||
orderBy: AuditLogEntryOrder
|
||||
filter: AuditLogEntryFilter
|
||||
): AuditLogEntryConnection! @goField(forceResolver: true)
|
||||
|
||||
createdAt: Datetime!
|
||||
updatedAt: Datetime!
|
||||
|
||||
@@ -5956,3 +5993,48 @@ type ElectronicSignatureEvent {
|
||||
occurredAt: Datetime!
|
||||
createdAt: Datetime!
|
||||
}
|
||||
|
||||
# Audit Log
|
||||
|
||||
input AuditLogEntryOrder
|
||||
@goModel(
|
||||
model: "go.probo.inc/probo/pkg/server/api/console/v1/types.AuditLogEntryOrderBy"
|
||||
) {
|
||||
field: AuditLogEntryOrderField!
|
||||
direction: OrderDirection!
|
||||
}
|
||||
|
||||
input AuditLogEntryFilter {
|
||||
action: String
|
||||
actorId: ID
|
||||
resourceType: String
|
||||
resourceId: ID
|
||||
}
|
||||
|
||||
type AuditLogEntry implements Node {
|
||||
id: ID!
|
||||
organization: Organization @goField(forceResolver: true)
|
||||
actorId: ID!
|
||||
actorType: AuditLogActorType!
|
||||
action: String!
|
||||
resourceType: String!
|
||||
resourceId: ID!
|
||||
metadata: String
|
||||
createdAt: Datetime!
|
||||
|
||||
permission(action: String!): Boolean! @goField(forceResolver: true)
|
||||
}
|
||||
|
||||
type AuditLogEntryConnection
|
||||
@goModel(
|
||||
model: "go.probo.inc/probo/pkg/server/api/console/v1/types.AuditLogEntryConnection"
|
||||
) {
|
||||
edges: [AuditLogEntryEdge!]!
|
||||
pageInfo: PageInfo!
|
||||
totalCount: Int! @goField(forceResolver: true)
|
||||
}
|
||||
|
||||
type AuditLogEntryEdge {
|
||||
cursor: CursorKey!
|
||||
node: AuditLogEntry!
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user