Documentation
¶
Overview ¶
SPDX-License-Identifier: MPL-2.0 Package audit owns retained accountability records. Domains choose accountable actions; operational logs and repeated public denials are not Audit events.
SPDX-License-Identifier: MPL-2.0
Index ¶
- Constants
- Variables
- func AppendInTx(parent context.Context, tx pgx.Tx, prepared Prepared) error
- func Migrate(ctx context.Context, dsn string) error
- type Config
- type Event
- type Module
- type Page
- type Prepared
- type Record
- type Service
- func (s *Service) Append(parent context.Context, actor achrix.Principal, event Event) (Record, error)
- func (s *Service) CheckDatabase(dsn string) error
- func (s *Service) Export(ctx context.Context, actor achrix.Principal, target, cursor string, limit int) (Page, error)
- func (s *Service) Prepare(ctx context.Context, actor achrix.Principal, event Event) (Prepared, error)
- func (s *Service) Query(ctx context.Context, actor achrix.Principal, target, cursor string, limit int) (Page, error)
Constants ¶
const ( Append = "achrix.audit.append" Query = "achrix.audit.query" Export = "achrix.audit.export" )
const ModuleVersion = "0.2.0-development"
ModuleVersion is the unpublished source-line label, not the packaged build version. Deprecated: use Module.Descriptor().Version for component/update/recovery identity.
Variables ¶
Functions ¶
func AppendInTx ¶
AppendInTx owns Audit SQL while the caller owns the native PostgreSQL transaction and commit. The domain must roll back if this call fails. A successful return alone does not prove either write has committed.
Types ¶
type Config ¶
type Config struct {
// MaxConns bounds this instance's pool. Zero uses four; negatives are invalid.
MaxConns int32
// MaxOperations bounds active owned leases, including nested AppendInTx work.
// Zero uses 16; explicit values must be at least two.
MaxOperations int
Now func() time.Time
}
Config.Now is a trusted, concurrent-safe product time source. Records store UTC microsecond instants; it conveys no trusted timestamp or clock attestation.
type Event ¶
type Event struct{ Action, Target, Authority, Outcome string }
Event deliberately has no caller-selected actor, time, ID or arbitrary payload. Authority identifies the owning domain capability, not an authorization grant.
type Module ¶
type Module struct {
// contains filtered or unexported fields
}
Module owns only Audit storage, pool, admission and lifecycle. Identity's declared dependency orders its shutdown drain before this Module is stopped.
func NewPostgres ¶
func (*Module) Descriptor ¶
func (m *Module) Descriptor() achrix.Descriptor
func (*Module) FailureCount ¶
FailureCount counts bounded operational failures, not durable accountability.
type Prepared ¶
type Prepared struct {
// contains filtered or unexported fields
}
Prepared is opaque, single-use and bound to the original live operation and Audit Module. It cannot extend a deadline or be retained as an access grant.
type Service ¶
type Service struct {
// contains filtered or unexported fields
}
func NewService ¶
func NewService(app *achrix.Application, module *Module) (*Service, error)
func (*Service) Append ¶
func (s *Service) Append(parent context.Context, actor achrix.Principal, event Event) (Record, error)
Append commits an authorized standalone record. Atomic domain actions instead use Prepare/AppendInTx within their owning transaction.
func (*Service) CheckDatabase ¶
CheckDatabase prevents a same-transaction consumer from silently composing different database profiles. Equivalent parsed connection settings match; passwords, TLS trust and fallback settings are compared without being exposed.