fix: stop tracking chat title in audit logs (#24564)

Chat titles can contain sensitive information (secrets, internal project
names, etc.) and should not be visible in audit logs.

- Use truncated chat UUID (first 8 chars) as `resource_target` instead
of the title
- Mark the `title` field as `ActionSecret` so diffs render as `••••••••`

<details><summary>Implementation notes</summary>

Two changes:
1. `coderd/audit/request.go`: `ResourceTarget` for Chat returns
`typed.ID.String()[:8]` instead of `typed.Title`
2. `enterprise/audit/table.go`: Chat `title` field tracking changed from
`ActionTrack` to `ActionSecret`

No frontend changes needed. The frontend already handles `secret: true`
fields.

</details>

> 🤖
This commit is contained in:
Cian Johnston
2026-04-21 14:26:22 +01:00
committed by GitHub
parent a62c0c1afc
commit 4d45b69b03
3 changed files with 12 additions and 10 deletions
+1 -1
View File
@@ -386,7 +386,7 @@ var auditableResourcesTypes = map[any]map[string]Action{
"workspace_id": ActionTrack,
"build_id": ActionIgnore, // Internal lifecycle.
"agent_id": ActionIgnore, // Internal lifecycle.
"title": ActionTrack,
"title": ActionSecret,
"status": ActionIgnore, // Churns every message.
"worker_id": ActionIgnore, // Internal.
"started_at": ActionIgnore,