Skip to content

bug: subscription register/delete/assign and the auto-switch settings are not audit-logged — a wiped subscription leaves no trace (SEC-001 gap) #2421

Description

@webmixgamer

Summary

None of the subscription lifecycle endpoints write an audit_log entry: POST /api/subscriptions (register), DELETE /api/subscriptions/{id} (delete — which also cascades every assigned agent to API-key auth), PUT/DELETE /api/subscriptions/agents/{name} (assign / clear), and the settings toggles under /api/subscriptions/settings/*. src/backend/routers/subscriptions.py contains no platform_audit_service.log(...) call at all, whereas sibling credential/config surfaces (e.g. routers/agent_config.py) audit every mutation.

Context

A subscription token is a credential and its assignment decides which account pays for an agent's turns — SEC-001 lists credential operations and settings among the audited event families. On 2026-08-27 every subscription on a developer instance was deleted by a test suite (companion issue), dropping all agents to API-key auth and disabling auto-switch; the audit log held only the agent-lifecycle rows of an unrelated test agent, so the deletion had to be reconstructed from system_settings.updated_at and backups. The same blindness applies to a malicious or accidental deletion on a production instance.

Acceptance Criteria

  • Register, delete, assign, clear-assignment and the /settings/* toggles each write an audit_log entry with actor, source, endpoint, target subscription id + name, and (for assign/clear/delete-cascade) the affected agent names
  • Token values never appear in any entry — masked/absent, per the existing credential-audit convention
  • A delete records how many agents were cascaded to API-key auth
  • SEC-001 tests extended to cover the new event actions; docs/memory/architecture.md SEC-001 coverage line updated

Technical Notes

  • Precedent: platform_audit_service.log(...) calls in src/backend/routers/agent_config.py
  • The delete cascade lives in src/backend/db/subscriptions.py::delete_subscription (returns the cleared-agent count already)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    complexity-lowComplexity: low (board points 1-3)priority-p2Importantstatus-readyGreenlit and ready for development (vetted; counterpart to status-incubating)theme-securityTheme: Securitytype-bugBug fix

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions