feat(audit): tamper-evident logging, alerting, retention and compliance reports (#396) - #1000
Open
sandrawillow001-afk wants to merge 1 commit into
Conversation
…ce reports (Smartdevs17#396) Audit evidence was only half-covered: the HTTP audit path had a hash chain and query API, but nothing alerted on critical events in real time, nothing enforced an archival policy, no compliance view existed, and untrusted detail values went into the log verbatim. - event-schema: canonical actor/action/resource/timestamp schema with zod validation, plus sanitisers that strip CR/LF, control characters and ANSI escapes and neutralise CSV formula injection on export. - alerting: declarative critical-event rules with severity thresholds, sliding window de-duplication and pluggable sinks (log + optional webhook). - retention: three-tier policy (hot/archive/purge) writing append-only NDJSON archives with manifests and payload hashes; a chain anchor keeps verifyIntegrity() valid after eviction. - compliance-report: SOC2 TSC and PCI-DSS v4 requirement 10 control mapping with per-control evidence and PCI-DSS 10.3 field completeness. - routes: GET /audit/alerts, /audit/compliance/report (JSON or CSV), /audit/retention/tiers, /audit/archives, POST /audit/retention/archive, and schema validation on POST /audit/log. 🤖 Generated with Codebuff Co-Authored-By: Codebuff <noreply@codebuff.com>
|
@sandrawillow001-afk is attempting to deploy a commit to the smartdevs17's projects Team on Vercel. A member of the Team first needs to authorize it. |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #396.
What already existed
The HTTP audit path (
services/auditService.ts,routes/audit.ts,middleware/sensitiveAudit.ts) already had a hash chain, query/export endpoints and a retention policy object, andsrc/audit/*had an immutable logger plus a chain verifier. Re-checking #396's acceptance criteria against that code left four genuine gaps.Gaps closed
audit/alerting.ts— declarative rules, severity thresholds, sliding-window de-duplication, log + optional webhook sinksaudit/retention.ts— hot/archive/purge tiers, append-only NDJSON archives with manifests and payload hashesaudit/compliance-report.ts— SOC2 TSC + PCI-DSS v4 req. 10 control mapping, per-control evidence, 10.3 field completenessverifyIntegrity()audit/event-schema.tssanitises CR/LF, control characters and ANSI escapes; CSV export neutralises formulas; a chain anchor keeps verification valid after evictionsrc/audit/event-schema.tsalso adds the canonical validated event schema (actor, action, resource, timestamp, outcome, origin) that the issue asks for.API
GET /api/v1/audit/alerts— recent alerts + counts by severityGET /api/v1/audit/compliance/report—?framework=SOC2|PCI-DSS,?from=,?to=,?format=csvGET /api/v1/audit/retention/tiers,GET /api/v1/audit/archivesPOST /api/v1/audit/retention/archive?confirm=truePOST /api/v1/audit/lognow validates against the canonical schema (400 with issue details)Verification
package.jsonfix (separate PR) to install dependencies at all.🤖 Generated with Codebuff