Milestone 19: Audit log UI (/admin/audit-log) - #36
Merged
Merged
Conversation
- New /admin/audit-log page surfacing GET /api/op/audit-log - Filters: HTTP method, path substring, user ID, since/until (RFC3339), limit (1..1000) - Per-row expand to inspect the JSON payload + metadata recorded by the audit middleware, plus route / request-id / OIDC subject / IP fields - New 'Audit log' admin tab + sidebar nav entry, gated on stig-manager:op:read - Typed fetchAuditLog() + useAuditLog() TanStack Query hook - 2 Playwright tests covering form layout + a create-collection round-trip that confirms the audit row lands and the payload viewer opens Co-Authored-By: Bryce Anglin <brycemanglin@gmail.com>
Contributor
Author
🤖 Devin AI EngineerI'll be helping with this pull request! Here's what you should know: ✅ I will automatically:
Note: I can only respond to comments from users who have write access to this repository. ⚙️ Control Options:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Surfaces the existing M17b audit log endpoint (
GET /api/op/audit-log) in the SPA as a new admin page./admin/audit-log, gated onstig-manager:op:read, registered in the AdminLayout tab strip and the primary admin nav.anonymouslabel.fetchAuditLog()typed client +useAuditLog()TanStack Query hook (re-uses the same Bearer-token bearer helpers as the rest ofapi/index.tsbecause/op/audit-logis wired directly on the chi router and isn't in the OpenAPI surface).POST /api/collections) → opens the audit log → filters byPOST+/api/collections→ polls until the new row appears → expands it → asserts the payload viewer is visible.Review & Testing Checklist for Human
admin, open/admin/audit-log, confirm the table and filter form render. Try filtering by method + path and by date range; click View on a row to inspect the JSON payload.evaluator(nostig-manager:op:read) and confirm the Audit log tab is hidden in the sidebar/admin strip and that a direct hit on/admin/audit-logreturns the standard "Insufficient permissions" screen.Notes
Link to Devin session: https://app.devin.ai/sessions/022810763c4643c0848ba894c1512b92
Requested by: @Exonical