A bundle of small file-local fixes to the receiver path and
node-deletion flow.
Changes:
- F4 receiver audit log: applyIncomingSync now writes a system audit
entry on every applied push so mirrored security-rule changes show
up in the replica's audit panel with a clear control-side origin.
- F7 pilot-agent skip: pushResource explicitly excludes pilot-agent
nodes (they have no api_url for HTTP push) and warns once per node
id so the operator sees they will not receive replicated policies.
- B4 identity-drift notification: when targetIdentity differs from
the cached fleet_self_identity, dispatch a warning so the operator
can audit any identity-scoped policies that may need re-targeting.
- B6 stack_pattern ReDoS guard: reject patterns with 4+ consecutive
wildcards or more than 8 wildcards total. Both control-side
validators (POST/PUT scan policies) and the receiver-side row
validator share the helper.
- B9 deleteNode cascade: clear fleet_sync_status rows for the node
inside the existing transaction so the sync-status panel does not
render ghost entries after a node is removed.
- S6 last_error redaction: formatError strips Bearer tokens and
JWT-shaped values from error messages and caps at 500 chars before
storing in fleet_sync_status.last_error or logging.
Tests:
- 8 new vitest cases covering audit-log entry, identity-drift alert,
pilot-agent warn-once, formatError redaction (Bearer + JWT), ReDoS
validator rejection, and a backtracking-time smoke test.
- New database-fleet-sync-cascade.test.ts: deleteNode removes
fleet_sync_status rows for the deleted node and leaves siblings
untouched.
- Full backend suite: 1792 pass / 5 skipped.