mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
fix: show audit logs for forgot password flow (#15181)
Fixes https://github.com/coder/coder/issues/15150 Audit logs for requesting a password reset, and a user updating their password, now show up in the audit log.
This commit is contained in:
+14
-3
@@ -274,8 +274,15 @@ func (api *API) convertAuditLog(ctx context.Context, dblog database.GetAuditLogs
|
||||
|
||||
func auditLogDescription(alog database.GetAuditLogsOffsetRow) string {
|
||||
b := strings.Builder{}
|
||||
|
||||
// NOTE: WriteString always returns a nil error, so we never check it
|
||||
_, _ = b.WriteString("{user} ")
|
||||
|
||||
// Requesting a password reset can be performed by anyone that knows the email
|
||||
// of a user so saying the user performed this action might be slightly misleading.
|
||||
if alog.AuditLog.Action != database.AuditActionRequestPasswordReset {
|
||||
_, _ = b.WriteString("{user} ")
|
||||
}
|
||||
|
||||
if alog.AuditLog.StatusCode >= 400 {
|
||||
_, _ = b.WriteString("unsuccessfully attempted to ")
|
||||
_, _ = b.WriteString(string(alog.AuditLog.Action))
|
||||
@@ -298,8 +305,12 @@ func auditLogDescription(alog database.GetAuditLogsOffsetRow) string {
|
||||
return b.String()
|
||||
}
|
||||
|
||||
_, _ = b.WriteString(" ")
|
||||
_, _ = b.WriteString(codersdk.ResourceType(alog.AuditLog.ResourceType).FriendlyString())
|
||||
if alog.AuditLog.Action == database.AuditActionRequestPasswordReset {
|
||||
_, _ = b.WriteString(" for")
|
||||
} else {
|
||||
_, _ = b.WriteString(" ")
|
||||
_, _ = b.WriteString(codersdk.ResourceType(alog.AuditLog.ResourceType).FriendlyString())
|
||||
}
|
||||
|
||||
if alog.AuditLog.ResourceType == database.ResourceTypeConvertLogin {
|
||||
_, _ = b.WriteString(" to")
|
||||
|
||||
Reference in New Issue
Block a user