Files
meet/docker
briquet 81b0059946 ✨(backend) add structured audit logging facility
Add a core.audit package emitting one ECS-shaped JSON line per
security-relevant action on a dedicated "audit" logger.

The actor, auth method, tenant and network fields are read from the request
passed to audit.log. A person is identified by primary key, OIDC sub when
the account has one and email domains.

Actions are audit.Action specs carrying their ECS category and types, so
a call site only names what was attempted. The project declares the rest
in code, from an auditing module the audit app autodiscovers:
audit.register lists the fields describing a model as a target, and
audit.register_auth_method names the DRF authentication classes and the
login backends. A field that cannot be read is skipped, not the event.

AuditViewMixin audits every response of the CRUD actions a view maps in
audit_actions, and of the extra actions naming theirs with
@action(audit_action=...), from finalize_response: the outcome, reason
and status come from the response, so a refusal is recorded under the
action that was attempted. An exception DRF does not handle is recorded
as an internal error before it propagates. The core.audit app also
records Django login and logout signals.
2026-10-06 00:44:28 +02:00
..
2024-12-16 23:41:09 +01:00
2026-10-01 00:13:36 +02:00