Documentation
¶
Overview ¶
Package audit appends a structured record of every validation to a JSONL audit log. Records contain only the SHA-256 hash of the key, never the raw secret, so the audit log is safe to ship alongside other operational logs.
Each line is a JSON object:
{"ts":"2026-...","provider":"openai","key_sha256":"...","is_valid":true,
"status_code":200,"error_code":"","duration_ms":123}
The file is opened once per write and held until Close(); concurrent Emit calls are serialized through an internal mutex.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func DefaultPath ¶
func DefaultPath() string
DefaultPath returns the conventional audit log location: ~/.kunji/audit.jsonl (override with KUNJI_AUDIT_FILE).
Types ¶
type Logger ¶
type Logger struct {
// contains filtered or unexported fields
}
Logger is the audit writer. A nil Logger is a valid no-op (Emit returns nil and Close returns nil) so callers don't need to nil-check.
func Open ¶
Open creates or appends to the audit log at path. Missing parent dirs are created with 0700 perms. If path == "", a no-op Logger is returned.
type Record ¶
type Record struct {
Timestamp string `json:"ts"`
Provider string `json:"provider"`
KeySHA256 string `json:"key_sha256"`
IsValid bool `json:"is_valid"`
StatusCode int `json:"status_code,omitempty"`
ErrorCode string `json:"error_code,omitempty"`
DurationMs int64 `json:"duration_ms,omitempty"`
}
Record is one line in the audit log.