Skip to content

Add error handling for unawaited auditLog calls #535

Description

@DeFiVC

Bug Description

Multiple service methods call auditLog() without await, meaning audit log failures are silently swallowed and don't block the main operation. While this is intentional for non-blocking behavior, it means audit logs can be lost without any indication.

Locations

Examples across the codebase:

  • src/modules/courses/course.service.ts - multiple calls
  • src/modules/quizzes/quiz.service.ts - multiple calls
  • src/modules/rewards/reward.service.ts - multiple calls
  • src/modules/admin/admin-users.service.ts - multiple calls

The Problem

// Current pattern (fire-and-forget):
auditLog("course.enrolled", { userId, courseId });

// If auditLog throws or the DB write fails, the error is lost

While making audit logging non-blocking is correct (audit failures shouldn't fail the main operation), the current implementation:

  1. Doesn't log audit failures at all
  2. Doesn't buffer failed writes for retry
  3. Could silently lose audit trail entries

Recommended Fix

Either:

  1. Add error handling in the auditLog function itself to log failures
  2. Use a buffered/async audit logger (as suggested in issue Make audit logging non-blocking with buffered writes #523)
  3. At minimum, wrap in .catch() to log the failure:
auditLog("course.enrolled", { userId, courseId }).catch((err) =>
    logger.warn({ err, userId, courseId }, "Failed to write audit log")
);

Acceptance Criteria

  • Audit log failures should be logged (not silently swallowed)
  • Consider implementing a buffered audit logger
  • Main operations should continue even if audit logging fails

Severity

low - Observability improvement. Audit logs are important for compliance but losing them shouldn't break the system.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions