Skip to content

feat: add centralized audit log service for sensitive admin and contract operations - #958

Merged
Chucks1093 merged 5 commits into
accesslayerorg:mainfrom
gospeltout:Add-audit-log-service-for-sensitive-admin-and-contract-operations
Sep 27, 2026
Merged

Chucks1093 merged 5 commits into
accesslayerorg:mainfrom
gospeltout:Add-audit-log-service-for-sensitive-admin-and-contract-operations

Conversation

@gospeltout

Copy link
Copy Markdown
Contributor

Summary

  • Implemented centralized audit log service (AuditLog) to record sensitive admin and contract operations (actorWallet, actionType, targetId, payload, createdAt).
  • Added GET /admin/audit-log endpoint protected with adminGuard authentication.
  • Added query parameter filtering by actionType and date range (fromDate, toDate, from, to, startDate, endDate).
  • Implemented cursor-based pagination (default 50, capped at 100) sorted by createdAt descending.
  • Enforced record immutability by exposing only the GET route with no update or delete endpoints.
  • Updated bigint-serializer.utils.ts to properly serialize Date objects in API responses and updated jest.setup.ts to support dynamic Prisma model mocking.

Testing

  • pnpm lint
  • pnpm build
  • pnpm exec prisma generate when schema or generated types changed
  • Ran integration test suites:
    • pnpm test src/modules/admin/audit-log.integration.test.ts
    • pnpm test src/modules/admin/audit-log-endpoint.integration.test.ts

Checklist

  • Linked issue or backlog item
  • No secrets or live credentials added
  • Docs updated if setup or env changed
  • Change is scoped to one problem

Closes #898

@Chucks1093
Chucks1093 merged commit f9f3f8e into accesslayerorg:main Sep 27, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Add audit log service for sensitive admin and contract operations

2 participants