mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: add support for workspace app audit (#16801)
This change adds support for workspace app auditing. To avoid audit log spam, we introduce the concept of app audit sessions. An audit session is unique per workspace app, user, ip, user agent and http status code. The sessions are stored in a separate table from audit logs to allow use-case specific optimizations. Sessions are ephemeral and the table does not function as a log. The logic for auditing is placed in the DBTokenProvider for workspace apps so that wsproxies are included. This is the final change affecting the API fo #15139. Updates #15139
This commit is contained in:
@@ -3434,6 +3434,28 @@ type WorkspaceApp struct {
|
||||
OpenIn WorkspaceAppOpenIn `db:"open_in" json:"open_in"`
|
||||
}
|
||||
|
||||
// Audit sessions for workspace apps, the data in this table is ephemeral and is used to deduplicate audit log entries for workspace apps. While a session is active, the same data will not be logged again. This table does not store historical data.
|
||||
type WorkspaceAppAuditSession struct {
|
||||
// The agent that the workspace app or port forward belongs to.
|
||||
AgentID uuid.UUID `db:"agent_id" json:"agent_id"`
|
||||
// The app that is currently in the workspace app. This is may be uuid.Nil because ports are not associated with an app.
|
||||
AppID uuid.UUID `db:"app_id" json:"app_id"`
|
||||
// The user that is currently using the workspace app. This is may be uuid.Nil if we cannot determine the user.
|
||||
UserID uuid.UUID `db:"user_id" json:"user_id"`
|
||||
// The IP address of the user that is currently using the workspace app.
|
||||
Ip string `db:"ip" json:"ip"`
|
||||
// The user agent of the user that is currently using the workspace app.
|
||||
UserAgent string `db:"user_agent" json:"user_agent"`
|
||||
// The slug or port of the workspace app that the user is currently using.
|
||||
SlugOrPort string `db:"slug_or_port" json:"slug_or_port"`
|
||||
// The HTTP status produced by the token authorization. Defaults to 200 if no status is provided.
|
||||
StatusCode int32 `db:"status_code" json:"status_code"`
|
||||
// The time the user started the session.
|
||||
StartedAt time.Time `db:"started_at" json:"started_at"`
|
||||
// The time the session was last updated.
|
||||
UpdatedAt time.Time `db:"updated_at" json:"updated_at"`
|
||||
}
|
||||
|
||||
// A record of workspace app usage statistics
|
||||
type WorkspaceAppStat struct {
|
||||
// The ID of the record
|
||||
|
||||
Reference in New Issue
Block a user