mirror of
https://github.com/coollabsio/coolify.git
synced 2026-10-06 05:58:14 -04:00
Add audit levels and record user, OAuth, DNS, notification, and settings changes while removing the obsolete scheduled job monitoring UI and services.
70 lines
2.4 KiB
PHP
70 lines
2.4 KiB
PHP
<?php
|
|
|
|
use App\Models\AuditEvent;
|
|
use Illuminate\Support\Facades\Log;
|
|
|
|
if (! function_exists('auditLog')) {
|
|
/**
|
|
* Queue an audit event for persistence after the response.
|
|
*
|
|
* @param string $event Dot-namespaced event name, e.g. `api.private_key.created`.
|
|
* @param array<string, mixed> $context Identifiers + outcome details.
|
|
* @param string $level Log level: info | warning | error.
|
|
*/
|
|
function auditLog(string $event, array $context = [], string $level = 'info'): void
|
|
{
|
|
$level = AuditEvent::normalizeLevel($level);
|
|
|
|
try {
|
|
$request = app()->bound('request') ? request() : null;
|
|
$user = auth()->user();
|
|
$token = $user?->currentAccessToken();
|
|
$payload = AuditEvent::redactContext(array_merge([
|
|
'event' => $event,
|
|
'ip' => $request?->ip(),
|
|
'ua' => substr((string) $request?->userAgent(), 0, 200),
|
|
'user_id' => $user?->id,
|
|
'user_email' => $user?->email,
|
|
'team_id' => $token ? data_get($token, 'team_id') : null,
|
|
'token_id' => $token?->id,
|
|
'token_name' => $token?->name,
|
|
'method' => $request?->method(),
|
|
'path' => $request?->path(),
|
|
], $context));
|
|
|
|
Log::channel('audit')->{$level}($event, $payload);
|
|
} catch (Throwable) {
|
|
// The database sink remains available when the optional channel fails.
|
|
}
|
|
|
|
AuditEvent::record($event, $context, $level);
|
|
}
|
|
}
|
|
|
|
if (! function_exists('auditLogWebhookFailure')) {
|
|
/**
|
|
* Record a webhook signature/auth verification failure.
|
|
*/
|
|
function auditLogWebhookFailure(string $provider, string $reason, array $context = []): void
|
|
{
|
|
try {
|
|
$request = app()->bound('request') ? request() : null;
|
|
|
|
$event = "webhook.{$provider}.signature_failed";
|
|
|
|
$base = [
|
|
'reason' => $reason,
|
|
'method' => $request?->method(),
|
|
'path' => $request?->path(),
|
|
'event_header' => $request?->header('X-GitHub-Event')
|
|
?? $request?->header('X-Gitlab-Event')
|
|
?? $request?->header('X-Gitea-Event')
|
|
?? $request?->header('X-Event-Key'),
|
|
];
|
|
|
|
auditLog($event, array_merge($base, $context), 'warning');
|
|
} catch (Throwable) {
|
|
}
|
|
}
|
|
}
|