Files
buzz-sheet/lib/audit-log.ts
T
gunshiz 8ddb5896b6
CI / Verify (push) Successful in 1m28s
CI / Build immutable images and deploy (push) Successful in 2m40s
feat : add audit logs
2026-09-27 16:03:53 +07:00

213 lines
6.0 KiB
TypeScript

import "server-only";
import { and, count, desc, eq } from "drizzle-orm";
import { getDb, type Database } from "@/db";
import { auditLogs } from "@/db/schema";
import { securityLog } from "@/lib/security/http";
export const AUDIT_ACTIONS = [
"guide.created",
"guide.overview.saved",
"guide.weapon.saved",
"guide.artifact.saved",
"guide.constellations.saved",
"guide.team.saved",
"guide.extra.created",
"guide.extra.saved",
"guide.extra.deleted",
"guide.extra.reordered",
"guide.trashed",
"guide.restored",
"guide.published",
"guide.unpublished",
"guide.permanently_deleted",
"glossary_alias.created",
"glossary_alias.deleted",
"media.uploaded",
"media.deleted",
"admin_account.created",
"admin_account.removed",
"catalog_sync.requested",
"catalog_sync.cancel_requested",
"catalog_sync.completed",
"catalog_sync.unchanged",
"catalog_sync.cancelled",
"catalog_sync.failed",
] as const;
export const AUDIT_TARGET_TYPES = [
"guide",
"extra_section",
"glossary_alias",
"media",
"admin_account",
"catalog_sync",
] as const;
export type AuditAction = (typeof AUDIT_ACTIONS)[number];
export type AuditTargetType = (typeof AUDIT_TARGET_TYPES)[number];
export type AuditMetadata = Record<
string,
string | number | boolean | null
>;
export interface AuditActor {
id: string;
label: string;
}
export interface AuditLogInput {
action: AuditAction;
targetType: AuditTargetType;
targetId: string;
scope?: string;
resultingVersion?: number;
metadata?: AuditMetadata;
}
type AuditWriter = Pick<Database, "insert">;
export function auditActor(user: {
id: string;
name?: string | null;
email?: string | null;
}): AuditActor {
return {
id: user.id,
label: (user.name?.trim() || user.email?.trim() || user.id).slice(0, 160),
};
}
export async function writeAuditLog(
writer: AuditWriter,
actor: AuditActor,
event: AuditLogInput,
): Promise<void> {
await writer.insert(auditLogs).values({
actorId: actor.id,
actorLabel: actor.label,
action: event.action,
targetType: event.targetType,
targetId: event.targetId,
scope: event.scope,
resultingVersion: event.resultingVersion,
metadata: event.metadata ?? {},
});
}
export async function writeAuditLogBestEffort(
actor: AuditActor,
event: AuditLogInput,
): Promise<void> {
try {
await writeAuditLog(getDb(), actor, event);
} catch {
securityLog("audit-write-failed", {
actorId: actor.id,
targetId: event.targetId,
});
}
}
export interface AuditLogFilters {
actorId?: string;
targetType?: AuditTargetType;
page?: number;
pageSize?: number;
}
export async function listAuditLogs(filters: AuditLogFilters = {}) {
const page = Math.max(1, Math.floor(filters.page ?? 1));
const pageSize = Math.max(1, Math.min(100, Math.floor(filters.pageSize ?? 50)));
const conditions = [
filters.actorId ? eq(auditLogs.actorId, filters.actorId) : undefined,
filters.targetType
? eq(auditLogs.targetType, filters.targetType)
: undefined,
].filter((condition) => condition !== undefined);
const where = conditions.length ? and(...conditions) : undefined;
const db = getDb();
const [events, [total]] = await Promise.all([
db
.select()
.from(auditLogs)
.where(where)
.orderBy(desc(auditLogs.createdAt), desc(auditLogs.id))
.limit(pageSize)
.offset((page - 1) * pageSize),
db
.select({ value: count() })
.from(auditLogs)
.where(where),
]);
return {
events,
page,
pageSize,
total: total.value,
pageCount: Math.max(1, Math.ceil(total.value / pageSize)),
};
}
export async function listAuditActors() {
const rows = await getDb()
.selectDistinctOn([auditLogs.actorId], {
id: auditLogs.actorId,
label: auditLogs.actorLabel,
})
.from(auditLogs)
.orderBy(auditLogs.actorId, desc(auditLogs.id));
return rows.sort((left, right) =>
left.label.localeCompare(right.label, "th"),
);
}
export const AUDIT_TARGET_LABELS: Record<
AuditTargetType,
string
> = {
guide: "Guide",
extra_section: "Extra section",
glossary_alias: "Glossary",
media: "Media",
admin_account: "Admin account",
catalog_sync: "Catalog sync",
};
export const AUDIT_ACTION_LABELS: Record<AuditAction, string> = {
"guide.created": "สร้าง Guide",
"guide.overview.saved": "บันทึก Overview",
"guide.weapon.saved": "บันทึก Weapons",
"guide.artifact.saved": "บันทึก Artifacts",
"guide.constellations.saved": "บันทึก Constellations",
"guide.team.saved": "บันทึก Team",
"guide.extra.created": "สร้าง Extra section",
"guide.extra.saved": "บันทึก Extra section",
"guide.extra.deleted": "ลบ Extra section",
"guide.extra.reordered": "เรียง Extra sections",
"guide.trashed": "ย้าย Guide ไปถังขยะ",
"guide.restored": "กู้คืน Guide",
"guide.published": "เผยแพร่ Guide",
"guide.unpublished": "ยกเลิกเผยแพร่ Guide",
"guide.permanently_deleted": "ลบ Guide ถาวร",
"glossary_alias.created": "เพิ่ม Glossary shortcut",
"glossary_alias.deleted": "ลบ Glossary shortcut",
"media.uploaded": "อัปโหลด Media",
"media.deleted": "ลบ Media",
"admin_account.created": "สร้างบัญชี Admin",
"admin_account.removed": "ลบบัญชี Admin",
"catalog_sync.requested": "เริ่ม Catalog sync",
"catalog_sync.cancel_requested": "ขอยกเลิก Catalog sync",
"catalog_sync.completed": "Catalog sync สำเร็จ",
"catalog_sync.unchanged": "Catalog เป็นเวอร์ชันล่าสุด",
"catalog_sync.cancelled": "ยกเลิก Catalog sync แล้ว",
"catalog_sync.failed": "Catalog sync ล้มเหลว",
};
export function isAuditTargetType(
value: string | undefined,
): value is AuditTargetType {
return AUDIT_TARGET_TYPES.some((type) => type === value);
}