Record sign-ins, new accounts, automatic log trimming and what settings changed

A check of every write path found gaps in what the audit log captured:

- Sign-ins and sign-outs are now recorded with the IP they came from
  (sign-out is recorded first and can't block signing out).
- A new account is recorded when it's created on first sign-in, including
  when the very first user becomes admin - so the log shows who gained
  access, not only who changed things.
- The automatic log purge, which deletes audit entries, now records
  itself, attributed to "system". recordAudit() takes an optional actor
  for this. It only records when something was actually deleted.
- Settings updates record what changed (before and after) instead of only
  which sections were touched. The notification channels (Gotify, ntfy,
  SMTP, webhook) record field names only: they hold credentials, and
  webhook URLs and public ntfy topics act as secrets, while the audit log
  is readable by operators and Settings is admin-only.
- Integration edits record renames, enabling/disabling, whether
  credentials were replaced (never the credentials), and which settings
  fields changed (names only).

The Privacy page and README now say sign-ins store an IP in the audit log.

Verified through the real routes against a scratch database: user
creation, the logout route, the automatic purge, settings and
integration edits - including that a secret token and a webhook URL
appear nowhere in the stored entries. The sign-in callback itself needs
a real identity provider and wasn't run.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This commit is contained in:
bobbanandClaude Sonnet 5.5 committed 2026-10-02 22:40:46 +02:00
1 parent 22cfdbede0
commit 88d9c8e097
9 files changed
+129 -12

No files matched your search

+5 -2
View File
@@ -163,7 +163,10 @@ export default function Privacy() {
</tr>
<tr>
<td>Audit log</td>
<td>Who changed what: your name (or email) as it was at the time, the action, what it was done to, and details of the change.</td>
<td>
Who changed what: your name (or email) as it was at the time, the action, what it was done to, and details of the change.
Also each time you sign in or out — with the IP address you came from — and when your account was first created.
</td>
<td>
{retention?.enabled
? `Entries older than ${retention.retentionDays} days are deleted (checked every ${retention.intervalHours} h).`
@@ -288,7 +291,7 @@ export default function Privacy() {
<div className="card-body">
<ul className="mb-0">
<li className="mb-2">Everyone signed in: the inventory and status pages, including server, IP, domain and secret-name details.</li>
<li className="mb-2">Operators and admins: also the audit log — who did what.</li>
<li className="mb-2">Operators and admins: also the audit log — who did what, and who signed in from where.</li>
<li>Admins only: the user list, everyone's active sign-ins (with IP and browser), the diagnostic log and settings.</li>
</ul>
</div>