fix(audit): store plugin entries with no acting user as a null user_id (#1556)

Plugin audit entries written outside a request used the literal "system"
as user_id. That column references users.id, so the insert was refused
(Postgres logs it as an FK violation) and the entry was silently dropped.
Write null instead and keep "system" / plugin:<id> in username.
This commit is contained in:
ZacharyZcR authored and GitHub committed 2026-10-04 18:40:13 +08:00
1 parent 4c9e12f3b7
commit abbfca2e94
7 files changed
+40 -9

No files matched your search

+4 -4
View File
@@ -156,7 +156,7 @@ async function writeAudit(
const { logAudit } = await import("../utils/audit-logger.js");
await logAudit({
// Attribution comes from the runtime, never from the plugin.
userId: getActor() ?? "system",
userId: getActor() ?? null,
username: `plugin:${manifest.id}`,
action: `plugin_${options.action}`,
resourceType: "plugin",
@@ -965,12 +965,12 @@ export function createPluginContext(
record: async (entry) => {
try {
const { logAudit } = await import("../utils/audit-logger.js");
const actor = getActor() ?? "system";
const actor = getActor();
const meta = requestMeta(entry.request);
await logAudit({
...meta,
userId: actor,
username: actor,
userId: actor ?? null,
username: actor ?? "system",
action: entry.action,
resourceType: entry.resourceType ?? "plugin",
resourceId: entry.resourceId ?? pluginId,
+1 -1
View File
@@ -351,7 +351,7 @@ async function writePublicRouteAudit(
try {
const { logAudit } = await import("../utils/audit-logger.js");
await logAudit({
userId: "system",
userId: null,
username: `plugin:${manifest.id}`,
action: "plugin_http_public_routes",
resourceType: "plugin",
+1 -1
View File
@@ -111,7 +111,7 @@ async function auditRefusal(
const { logAudit } = await import("../utils/audit-logger.js");
await logAudit({
// Attribution comes from the runtime, never from the plugin.
userId: getActor() ?? "system",
userId: getActor() ?? null,
username: `plugin:${pluginId}`,
action: `plugin_${action}`,
resourceType: "plugin",
+1 -1
View File
@@ -382,7 +382,7 @@ function auditPublicSocket(pluginId: string, path: string): void {
void import("../utils/audit-logger.js")
.then(({ logAudit }) =>
logAudit({
userId: "system",
userId: null,
username: `plugin:${pluginId}`,
action: "plugin_ws_public_route",
resourceType: "plugin",
@@ -77,6 +77,34 @@ describe("AuditLogRepository", () => {
]);
});
it("stores entries with no acting user, and refuses ids that are not users", async () => {
const repo = await createRepository();
await repo.create({
userId: null,
username: "plugin:example",
action: "plugin_http_public_routes",
resourceType: "plugin",
success: true,
});
await expect(
repo.create({
userId: "system",
username: "system",
action: "cleanup",
resourceType: "plugin",
success: true,
}),
).rejects.toThrow();
const page = await repo.listPage({ filters: {}, limit: 10, offset: 0 });
expect(page.logs).toHaveLength(1);
expect(page.logs[0]).toMatchObject({
userId: null,
username: "plugin:example",
});
});
it("deletes logs by user id and only runs write hook for deleted rows", async () => {
let writeCount = 0;
const repo = await createRepository(() => {
+2 -1
View File
@@ -73,7 +73,8 @@ describe("ctx.audit.record", () => {
const ctx = contextFor("audit-fixture");
await ctx.audit.record({ action: "cleanup", success: false });
expect(auditEntries[0]).toMatchObject({
userId: "system",
userId: null,
username: "system",
resourceType: "plugin",
resourceId: "audit-fixture",
resourceName: "Audit Fixture",
+3 -1
View File
@@ -20,7 +20,9 @@ export async function getAuditUsername(userId: string): Promise<string> {
}
export interface AuditLogParams {
userId: string;
// Null when no user acted (a plugin starting up, background work): the
// column references users.id, so anything else would be refused.
userId: string | null;
username: string;
action: string;
resourceType: string;