feat: add GET /api/v2/agent-firewall/sessions/{id}/logs endpoint (#24816)

Add a `GET /api/v2/agent-firewall/sessions/{id}/logs` endpoint that
returns agent firewall audit logs for a given session, sorted by
sequence number ascending.

The endpoint supports `seq_after` and `seq_before` (exclusive bounds)
and `limit` query parameters. This enables the frontend to fetch exactly
the firewall events that fall between two AI Bridge interceptions within
a thread, as described in FR 4 of the Boundary/Bridge correlation RFC.

Authorization reuses the `boundary_log` RBAC resource (owner and auditor
can read; members cannot). Returns 404 for unauthorized users to avoid
leaking existence information.

The endpoint is enterprise-only, gated behind `FeatureBoundary`
entitlement, matching the session endpoint from #24814.

Depends on #24814

> [!NOTE]
> This PR was authored by Coder Agents.
This commit is contained in:
Sas Swart
2026-06-22 13:56:29 +02:00
committed by GitHub
parent c0b8fa9418
commit 335d6bda1b
13 changed files with 829 additions and 8 deletions
+1
View File
@@ -336,6 +336,7 @@ func New(ctx context.Context, options *Options) (_ *API, err error) {
)
r.Route("/sessions/{id}", func(r chi.Router) {
r.Get("/", api.agentFirewallSessionByID)
r.Get("/logs", api.agentFirewallSessionLogs)
})
})
r.Route("/licenses", func(r chi.Router) {