feat: enhance audit service with PII redaction, persistence, severity levels, and alerting integration.#531
Merged
Smartdevs17 merged 1 commit intoJun 2, 2026
Conversation
… levels, and alerting integration.
|
@Dubemtopsite Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Implement comprehensive audit logging for sensitive operations
Closes #428
Summary
Overhauls the audit logging system with a tamper-evident, compliance-grade audit trail. Adds severity classification, enriched context, persistent storage, real-time alerting, archival, and PII-safe querying.
Changes
backend/services/auditTypes.ts— Enhanced schemaAuditSeverity(low|medium|high|critical) for event classificationAuditContextwithipAddress,userAgent,sessionId,location,deviceId,platformAuditActionunion with 14 critical security events (auth.failed,admin.role_changed,api.key_revoked,security.threat_detected, etc.)AuditArchiveEntry,ArchivalPolicy,AuditQueryFilter,AuditQueryResult,ComplianceAuditReporttypesbackend/services/auditService.ts— Core enhancementscapture()acceptsseverityand optionalAuditContext; defaults to'low'save()/load()via AsyncStorage; no delete/update surface exposedsanitizeInput()strips\r\n"'\\;from identifiers;sanitizeMetadata()redacts PII-like keys (email, phone, ssn, credit card) and inline PII valuesresourceType,severity, textsearch; sort bytimestamp/action/actorId;queryPaginated()with offset/limit paginationAlertingServicevia pluggable channels (console, Slack, PagerDuty)applyRetention()moves pruned events to cold storage whenArchivalPolicyis enabledgenerateComplianceReport()includes integrity verification, severity/actor/resource breakdowns, retention days, supported export formatsqueryWithoutPii()redacts all PII from resultsbackend/services/piiAudit.ts— Passes severity (highfor export/delete,mediumotherwise) and optionalAuditContextsrc/services/auditIntegration.ts— New convenience layer bridging backendAuditServicewith the app; exportscaptureAuditEvent,queryAuditEventsPaginated,generateComplianceReport,persistAuditLog, etc.src/services/adminDashboardService.ts— Addedseverityto mock audit eventsbackend/services/__tests__/auditService.test.ts— 37 tests covering:Edge cases addressed
maxLogSize(default 100k) prevents unbounded memory growth; archival moves aged data to cold AsyncStorage keysqueryWithoutPii()for safe consumptionDate.now()with timestamp-based queries — appropriate for this client-side architectureVerification