Summary
None of the subscription lifecycle endpoints write an audit_log entry: POST /api/subscriptions (register), DELETE /api/subscriptions/{id} (delete — which also cascades every assigned agent to API-key auth), PUT/DELETE /api/subscriptions/agents/{name} (assign / clear), and the settings toggles under /api/subscriptions/settings/*. src/backend/routers/subscriptions.py contains no platform_audit_service.log(...) call at all, whereas sibling credential/config surfaces (e.g. routers/agent_config.py) audit every mutation.
Context
A subscription token is a credential and its assignment decides which account pays for an agent's turns — SEC-001 lists credential operations and settings among the audited event families. On 2026-08-27 every subscription on a developer instance was deleted by a test suite (companion issue), dropping all agents to API-key auth and disabling auto-switch; the audit log held only the agent-lifecycle rows of an unrelated test agent, so the deletion had to be reconstructed from system_settings.updated_at and backups. The same blindness applies to a malicious or accidental deletion on a production instance.
Acceptance Criteria
Technical Notes
- Precedent:
platform_audit_service.log(...) calls in src/backend/routers/agent_config.py
- The delete cascade lives in
src/backend/db/subscriptions.py::delete_subscription (returns the cleared-agent count already)
Summary
None of the subscription lifecycle endpoints write an
audit_logentry:POST /api/subscriptions(register),DELETE /api/subscriptions/{id}(delete — which also cascades every assigned agent to API-key auth),PUT/DELETE /api/subscriptions/agents/{name}(assign / clear), and the settings toggles under/api/subscriptions/settings/*.src/backend/routers/subscriptions.pycontains noplatform_audit_service.log(...)call at all, whereas sibling credential/config surfaces (e.g.routers/agent_config.py) audit every mutation.Context
A subscription token is a credential and its assignment decides which account pays for an agent's turns — SEC-001 lists credential operations and settings among the audited event families. On 2026-08-27 every subscription on a developer instance was deleted by a test suite (companion issue), dropping all agents to API-key auth and disabling auto-switch; the audit log held only the agent-lifecycle rows of an unrelated test agent, so the deletion had to be reconstructed from
system_settings.updated_atand backups. The same blindness applies to a malicious or accidental deletion on a production instance.Acceptance Criteria
/settings/*toggles each write anaudit_logentry with actor, source, endpoint, target subscription id + name, and (for assign/clear/delete-cascade) the affected agent namesdocs/memory/architecture.mdSEC-001 coverage line updatedTechnical Notes
platform_audit_service.log(...)calls insrc/backend/routers/agent_config.pysrc/backend/db/subscriptions.py::delete_subscription(returns the cleared-agent count already)