Record sign-ins, new accounts, automatic log trimming and what settings changed
A check of every write path found gaps in what the audit log captured: - Sign-ins and sign-outs are now recorded with the IP they came from (sign-out is recorded first and can't block signing out). - A new account is recorded when it's created on first sign-in, including when the very first user becomes admin - so the log shows who gained access, not only who changed things. - The automatic log purge, which deletes audit entries, now records itself, attributed to "system". recordAudit() takes an optional actor for this. It only records when something was actually deleted. - Settings updates record what changed (before and after) instead of only which sections were touched. The notification channels (Gotify, ntfy, SMTP, webhook) record field names only: they hold credentials, and webhook URLs and public ntfy topics act as secrets, while the audit log is readable by operators and Settings is admin-only. - Integration edits record renames, enabling/disabling, whether credentials were replaced (never the credentials), and which settings fields changed (names only). The Privacy page and README now say sign-ins store an IP in the audit log. Verified through the real routes against a scratch database: user creation, the logout route, the automatic purge, settings and integration edits - including that a secret token and a webhook URL appear nowhere in the stored entries. The sign-in callback itself needs a real identity provider and wasn't run. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This commit is contained in:
1 parent
22cfdbede0
commit
88d9c8e097
9 files changed
+129
-12
No files matched your search
@@ -163,7 +163,10 @@ export default function Privacy() {
|
||||
</tr>
|
||||
<tr>
|
||||
<td>Audit log</td>
|
||||
<td>Who changed what: your name (or email) as it was at the time, the action, what it was done to, and details of the change.</td>
|
||||
<td>
|
||||
Who changed what: your name (or email) as it was at the time, the action, what it was done to, and details of the change.
|
||||
Also each time you sign in or out — with the IP address you came from — and when your account was first created.
|
||||
</td>
|
||||
<td>
|
||||
{retention?.enabled
|
||||
? `Entries older than ${retention.retentionDays} days are deleted (checked every ${retention.intervalHours} h).`
|
||||
@@ -288,7 +291,7 @@ export default function Privacy() {
|
||||
<div className="card-body">
|
||||
<ul className="mb-0">
|
||||
<li className="mb-2">Everyone signed in: the inventory and status pages, including server, IP, domain and secret-name details.</li>
|
||||
<li className="mb-2">Operators and admins: also the audit log — who did what.</li>
|
||||
<li className="mb-2">Operators and admins: also the audit log — who did what, and who signed in from where.</li>
|
||||
<li>Admins only: the user list, everyone's active sign-ins (with IP and browser), the diagnostic log and settings.</li>
|
||||
</ul>
|
||||
</div>
|
||||
|
||||
Reference in new issue
Block a user