Skip to content

Milestone 19: Audit log UI (/admin/audit-log) - #36

Merged
Exonical merged 1 commit into
mainfrom
devin/1779467704-milestone-19-audit-log-ui
May 22, 2026
Merged

Exonical merged 1 commit into
mainfrom
devin/1779467704-milestone-19-audit-log-ui

Conversation

@devin-ai-integration

@devin-ai-integration devin-ai-integration Bot commented May 22, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Surfaces the existing M17b audit log endpoint (GET /api/op/audit-log) in the SPA as a new admin page.

  • New page at /admin/audit-log, gated on stig-manager:op:read, registered in the AdminLayout tab strip and the primary admin nav.
  • Filter form: HTTP method (POST/PUT/PATCH/DELETE/Any), path substring, user ID, since/until (datetime-local inputs that are converted to RFC3339 UTC for the API), and a clamped limit (1..1000).
  • Results table: timestamp / method / path / status / duration / user, color-coded method + status pills, and a per-row View toggle that expands an inline panel showing the JSON payload and metadata recorded by the audit middleware plus the route, request ID, OIDC subject, and IP. Anonymous callers render with an anonymous label.
  • New fetchAuditLog() typed client + useAuditLog() TanStack Query hook (re-uses the same Bearer-token bearer helpers as the rest of api/index.ts because /op/audit-log is wired directly on the chi router and isn't in the OpenAPI surface).
  • 2 new Playwright tests (31 total): one covers the form/table render, one creates a fresh Collection (a real POST /api/collections) → opens the audit log → filters by POST + /api/collections → polls until the new row appears → expands it → asserts the payload viewer is visible.

Review & Testing Checklist for Human

  • Sign in as admin, open /admin/audit-log, confirm the table and filter form render. Try filtering by method + path and by date range; click View on a row to inspect the JSON payload.
  • Sign in as evaluator (no stig-manager:op:read) and confirm the Audit log tab is hidden in the sidebar/admin strip and that a direct hit on /admin/audit-log returns the standard "Insufficient permissions" screen.

Notes

  • The audit middleware writes inserts asynchronously (5s context timeout) so the M19 e2e test polls via Refresh to give the row time to land — flake risk is low but not zero on a heavily-loaded CI runner.
  • The audit log endpoint already enforces a hard 1000-row server-side cap; the page's Limit input is just a client-side hint for the same range.

Link to Devin session: https://app.devin.ai/sessions/022810763c4643c0848ba894c1512b92
Requested by: @Exonical


Open in Devin Review

- New /admin/audit-log page surfacing GET /api/op/audit-log
- Filters: HTTP method, path substring, user ID, since/until (RFC3339),
  limit (1..1000)
- Per-row expand to inspect the JSON payload + metadata recorded by the
  audit middleware, plus route / request-id / OIDC subject / IP fields
- New 'Audit log' admin tab + sidebar nav entry, gated on stig-manager:op:read
- Typed fetchAuditLog() + useAuditLog() TanStack Query hook
- 2 Playwright tests covering form layout + a create-collection round-trip
  that confirms the audit row lands and the payload viewer opens

Co-Authored-By: Bryce Anglin <brycemanglin@gmail.com>
@devin-ai-integration

Copy link
Copy Markdown
Contributor Author

🤖 Devin AI Engineer

I'll be helping with this pull request! Here's what you should know:

✅ I will automatically:

  • Address comments on this PR. Add '(aside)' to your comment to have me ignore it.
  • Look at CI failures and help fix them

Note: I can only respond to comments from users who have write access to this repository.

⚙️ Control Options:

  • Disable automatic comment and CI monitoring

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Devin Review: No Issues Found

Devin Review analyzed this PR and found no potential bugs to report.

View in Devin Review to see 3 additional findings.

Open in Devin Review

@Exonical
Exonical merged commit e596c98 into main May 22, 2026
7 checks passed
@Exonical
Exonical deleted the devin/1779467704-milestone-19-audit-log-ui branch May 22, 2026 16:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant