feat: add privacy-safe server diagnostics
This commit is contained in:
1 parent
2360506607
commit
a3963ad0f6
27 files changed
+1305
-112
No files matched your search
@@ -2,6 +2,11 @@ import argon2 from 'argon2';
|
||||
import type { AppConfig } from './config.js';
|
||||
import { getPool, withTransaction } from './db.js';
|
||||
import { hashToken, randomToken, sameTokenHash } from './crypto.js';
|
||||
import {
|
||||
diagnosticMetadataKeys,
|
||||
noopDiagnosticLogger,
|
||||
type DiagnosticLogger
|
||||
} from './diagnostics.js';
|
||||
|
||||
export interface AuthUser {
|
||||
id: string;
|
||||
@@ -55,7 +60,18 @@ export class AuthService {
|
||||
parallelism: 1
|
||||
});
|
||||
|
||||
constructor(private readonly config: AppConfig) {}
|
||||
constructor(
|
||||
private readonly config: AppConfig,
|
||||
private readonly logger: DiagnosticLogger = noopDiagnosticLogger
|
||||
) {}
|
||||
|
||||
private log(metadata: Record<string, unknown>, message: string): void {
|
||||
try {
|
||||
this.logger.info(metadata, message);
|
||||
} catch {
|
||||
// Authentication state and audit persistence never depend on logging.
|
||||
}
|
||||
}
|
||||
|
||||
async ensureOrganization(): Promise<{ id: string; slug: string; name: string }> {
|
||||
const result = await getPool(this.config).query(
|
||||
@@ -255,5 +271,14 @@ export class AuthService {
|
||||
VALUES ($1, $2, 'auth.' || $3, 'session', $4, $5, $6)`,
|
||||
[organizationId, userId, eventType, userId || '', requestId, metadata]
|
||||
);
|
||||
this.log({
|
||||
diagnostic_event: 'audit.event.staged',
|
||||
diagnostic_stage: 'auth_audit',
|
||||
request_id: requestId,
|
||||
domain_event: `auth.${eventType}`,
|
||||
entity_type: 'session',
|
||||
actor_present: Boolean(userId),
|
||||
metadata_keys: diagnosticMetadataKeys(metadata)
|
||||
}, 'authentication audit event persisted');
|
||||
}
|
||||
}
|
||||
Reference in new issue
Block a user