mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: add support for workspace app audit (#16801)
This change adds support for workspace app auditing. To avoid audit log spam, we introduce the concept of app audit sessions. An audit session is unique per workspace app, user, ip, user agent and http status code. The sessions are stored in a separate table from audit logs to allow use-case specific optimizations. Sessions are ephemeral and the table does not function as a log. The logic for auditing is placed in the DBTokenProvider for workspace apps so that wsproxies are included. This is the final change affecting the API fo #15139. Updates #15139
This commit is contained in:
@@ -195,6 +195,8 @@ type databaseRequest struct {
|
||||
Workspace database.Workspace
|
||||
// Agent is the agent that the app is running on.
|
||||
Agent database.WorkspaceAgent
|
||||
// App is the app that the user is trying to access.
|
||||
App database.WorkspaceApp
|
||||
|
||||
// AppURL is the resolved URL to the workspace app. This is only set for non
|
||||
// terminal requests.
|
||||
@@ -288,6 +290,7 @@ func (r Request) getDatabase(ctx context.Context, db database.Store) (*databaseR
|
||||
// in the workspace or not.
|
||||
var (
|
||||
agentNameOrID = r.AgentNameOrID
|
||||
app database.WorkspaceApp
|
||||
appURL string
|
||||
appSharingLevel database.AppSharingLevel
|
||||
// First check if it's a port-based URL with an optional "s" suffix for HTTPS.
|
||||
@@ -353,8 +356,9 @@ func (r Request) getDatabase(ctx context.Context, db database.Store) (*databaseR
|
||||
appSharingLevel = ps.ShareLevel
|
||||
}
|
||||
} else {
|
||||
for _, app := range apps {
|
||||
if app.Slug == r.AppSlugOrPort {
|
||||
for _, a := range apps {
|
||||
if a.Slug == r.AppSlugOrPort {
|
||||
app = a
|
||||
if !app.Url.Valid {
|
||||
return nil, xerrors.Errorf("app URL is not valid")
|
||||
}
|
||||
@@ -410,6 +414,7 @@ func (r Request) getDatabase(ctx context.Context, db database.Store) (*databaseR
|
||||
User: user,
|
||||
Workspace: workspace,
|
||||
Agent: agent,
|
||||
App: app,
|
||||
AppURL: appURLParsed,
|
||||
AppSharingLevel: appSharingLevel,
|
||||
}, nil
|
||||
|
||||
Reference in New Issue
Block a user