feat: add privacy-safe server diagnostics

This commit is contained in:
inman committed 2026-08-30 16:01:42 +08:00
1 parent 2360506607
commit a3963ad0f6
27 files changed
+1305 -112

No files matched your search

+26 -1
View File
@@ -2,6 +2,11 @@ import argon2 from 'argon2';
import type { AppConfig } from './config.js';
import { getPool, withTransaction } from './db.js';
import { hashToken, randomToken, sameTokenHash } from './crypto.js';
import {
diagnosticMetadataKeys,
noopDiagnosticLogger,
type DiagnosticLogger
} from './diagnostics.js';
export interface AuthUser {
id: string;
@@ -55,7 +60,18 @@ export class AuthService {
parallelism: 1
});
constructor(private readonly config: AppConfig) {}
constructor(
private readonly config: AppConfig,
private readonly logger: DiagnosticLogger = noopDiagnosticLogger
) {}
private log(metadata: Record<string, unknown>, message: string): void {
try {
this.logger.info(metadata, message);
} catch {
// Authentication state and audit persistence never depend on logging.
}
}
async ensureOrganization(): Promise<{ id: string; slug: string; name: string }> {
const result = await getPool(this.config).query(
@@ -255,5 +271,14 @@ export class AuthService {
VALUES ($1, $2, 'auth.' || $3, 'session', $4, $5, $6)`,
[organizationId, userId, eventType, userId || '', requestId, metadata]
);
this.log({
diagnostic_event: 'audit.event.staged',
diagnostic_stage: 'auth_audit',
request_id: requestId,
domain_event: `auth.${eventType}`,
entity_type: 'session',
actor_present: Boolean(userId),
metadata_keys: diagnosticMetadataKeys(metadata)
}, 'authentication audit event persisted');
}
}