mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
chore: audit log entries for all idp sync changes (#15919)
This commit is contained in:
@@ -2,6 +2,7 @@ package audit
|
||||
|
||||
import (
|
||||
"github.com/coder/coder/v2/coderd/database"
|
||||
"github.com/coder/coder/v2/coderd/idpsync"
|
||||
)
|
||||
|
||||
// Auditable is mostly a marker interface. It contains a definitive list of all
|
||||
@@ -26,7 +27,10 @@ type Auditable interface {
|
||||
database.CustomRole |
|
||||
database.AuditableOrganizationMember |
|
||||
database.Organization |
|
||||
database.NotificationTemplate
|
||||
database.NotificationTemplate |
|
||||
idpsync.OrganizationSyncSettings |
|
||||
idpsync.GroupSyncSettings |
|
||||
idpsync.RoleSyncSettings
|
||||
}
|
||||
|
||||
// Map is a map of changed fields in an audited resource. It maps field names to
|
||||
|
||||
@@ -20,6 +20,7 @@ import (
|
||||
"github.com/coder/coder/v2/coderd/database"
|
||||
"github.com/coder/coder/v2/coderd/database/dbtime"
|
||||
"github.com/coder/coder/v2/coderd/httpmw"
|
||||
"github.com/coder/coder/v2/coderd/idpsync"
|
||||
"github.com/coder/coder/v2/coderd/tracing"
|
||||
)
|
||||
|
||||
@@ -121,11 +122,22 @@ func ResourceTarget[T Auditable](tgt T) string {
|
||||
return typed.Name
|
||||
case database.NotificationTemplate:
|
||||
return typed.Name
|
||||
case idpsync.OrganizationSyncSettings:
|
||||
return "Organization Sync"
|
||||
case idpsync.GroupSyncSettings:
|
||||
return "Organization Group Sync"
|
||||
case idpsync.RoleSyncSettings:
|
||||
return "Organization Role Sync"
|
||||
default:
|
||||
panic(fmt.Sprintf("unknown resource %T for ResourceTarget", tgt))
|
||||
}
|
||||
}
|
||||
|
||||
// noID can be used for resources that do not have an uuid.
|
||||
// An example is singleton configuration resources.
|
||||
// 51A51C = "Static"
|
||||
var noID = uuid.MustParse("51A51C00-0000-0000-0000-000000000000")
|
||||
|
||||
func ResourceID[T Auditable](tgt T) uuid.UUID {
|
||||
switch typed := any(tgt).(type) {
|
||||
case database.Template:
|
||||
@@ -169,6 +181,12 @@ func ResourceID[T Auditable](tgt T) uuid.UUID {
|
||||
return typed.ID
|
||||
case database.NotificationTemplate:
|
||||
return typed.ID
|
||||
case idpsync.OrganizationSyncSettings:
|
||||
return noID // Deployment all uses the same org sync settings
|
||||
case idpsync.GroupSyncSettings:
|
||||
return noID // Org field on audit log has org id
|
||||
case idpsync.RoleSyncSettings:
|
||||
return noID // Org field on audit log has org id
|
||||
default:
|
||||
panic(fmt.Sprintf("unknown resource %T for ResourceID", tgt))
|
||||
}
|
||||
@@ -214,6 +232,12 @@ func ResourceType[T Auditable](tgt T) database.ResourceType {
|
||||
return database.ResourceTypeOrganization
|
||||
case database.NotificationTemplate:
|
||||
return database.ResourceTypeNotificationTemplate
|
||||
case idpsync.OrganizationSyncSettings:
|
||||
return database.ResourceTypeIdpSyncSettingsOrganization
|
||||
case idpsync.RoleSyncSettings:
|
||||
return database.ResourceTypeIdpSyncSettingsRole
|
||||
case idpsync.GroupSyncSettings:
|
||||
return database.ResourceTypeIdpSyncSettingsGroup
|
||||
default:
|
||||
panic(fmt.Sprintf("unknown resource %T for ResourceType", typed))
|
||||
}
|
||||
@@ -261,6 +285,12 @@ func ResourceRequiresOrgID[T Auditable]() bool {
|
||||
return true
|
||||
case database.NotificationTemplate:
|
||||
return false
|
||||
case idpsync.OrganizationSyncSettings:
|
||||
return false
|
||||
case idpsync.GroupSyncSettings:
|
||||
return true
|
||||
case idpsync.RoleSyncSettings:
|
||||
return true
|
||||
default:
|
||||
panic(fmt.Sprintf("unknown resource %T for ResourceRequiresOrgID", tgt))
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user