chore: audit log entries for all idp sync changes (#15919)

This commit is contained in:
Steven Masley
2025-01-02 15:02:04 -06:00
committed by GitHub
parent 761a19663f
commit 73ec6b2635
18 changed files with 259 additions and 64 deletions
+2
View File
@@ -4,6 +4,7 @@ import (
"database/sql"
"fmt"
"reflect"
"strings"
"github.com/google/uuid"
"golang.org/x/xerrors"
@@ -49,6 +50,7 @@ func diffValues(left, right any, table Table) audit.Map {
)
diffName := field.FieldType.Tag.Get("json")
diffName = strings.TrimSuffix(diffName, ",omitempty")
atype, ok := diffKey[diffName]
if !ok {
+20
View File
@@ -5,8 +5,10 @@ import (
"os"
"reflect"
"runtime"
"strings"
"github.com/coder/coder/v2/coderd/database"
"github.com/coder/coder/v2/coderd/idpsync"
"github.com/coder/coder/v2/codersdk"
)
@@ -286,6 +288,23 @@ var auditableResourcesTypes = map[any]map[string]Action{
"method": ActionTrack,
"kind": ActionTrack,
},
&idpsync.OrganizationSyncSettings{}: {
"field": ActionTrack,
"mapping": ActionTrack,
"assign_default": ActionTrack,
},
&idpsync.GroupSyncSettings{}: {
"field": ActionTrack,
"mapping": ActionTrack,
"regex_filter": ActionTrack,
"auto_create_missing_groups": ActionTrack,
// Configured in env vars
"legacy_group_name_mapping": ActionIgnore,
},
&idpsync.RoleSyncSettings{}: {
"field": ActionTrack,
"mapping": ActionTrack,
},
}
// auditMap converts a map of struct pointers to a map of struct names as
@@ -335,6 +354,7 @@ func entry(v any, f map[string]Action) (string, map[string]Action) {
// This field is explicitly ignored.
continue
}
jsonTag = strings.TrimSuffix(jsonTag, ",omitempty")
if _, ok := fcpy[jsonTag]; !ok {
_, _ = fmt.Fprintf(os.Stderr, "ERROR: Audit table entry missing action for field %q in type %q\nPlease update the auditable resource types in: %s\n", d.FieldType.Name, name, self())
//nolint:revive