Documentation
¶
Overview ¶
Package activity merges alerts + transactions + intelligence_events + audit_events into a single time-ordered feed, with per-source RBAC and seek-cursor pagination.
Spec: specs/system/activity.spec.yaml (status: approved).
Architectural notes:
One UNION query. Service.List runs exactly one SQL statement — a UNION ALL across the up-to-four sources, with severity / time-range / source / host filters pushed down to each leg. Spec C-01 + AC-11.
Per-source RBAC. The caller's permission set determines which legs of the UNION are populated. Without alert:read the alerts leg returns zero rows; without host:read transactions and intelligence return zero; without audit:read audit returns zero. The "hidden by RBAC" count is reported alongside the items so the UI can render "47 items; 200 hidden by your role". Spec C-02 + AC-03 / AC-04.
Cursor on occurred_at DESC. Same pattern as audit + intelligence APIs. Empty cursor on the response means terminal page.
HTTP-free. The package MUST NOT import internal/server or net/http. The HTTP surface lives in api-activity (the internal/server handler delegates here). Spec C-07 + AC-12.
Index ¶
Constants ¶
This section is empty.
Variables ¶
var ( // ErrInvalidLimit is returned when limit is outside [1, 200]. ErrInvalidLimit = errors.New("activity: limit must be in [1, 200]") // ErrInvalidSource is returned when filter.Source is non-empty // and not in the closed enum. ErrInvalidSource = errors.New("activity: invalid source") // ErrInvalidSeverity is returned when filter.Severity is non-empty // and not in the closed enum. ErrInvalidSeverity = errors.New("activity: invalid severity") )
Sentinel errors.
var AllSeverities = []Severity{ SeverityInfo, SeverityLow, SeverityMedium, SeverityHigh, SeverityCritical, }
AllSeverities is the registration-order list.
var AllSources = []Source{ SourceAlert, SourceTransaction, SourceIntelligence, SourceAudit, SourceMonitoring, }
AllSources is the registration-order list.
Functions ¶
func FormatAudit ¶
FormatAudit renders an audit row as "<actor> <predicate>". The actor is the recorded actor_label, falling back to a readable actor_type. The raw resource_id (a UUID) is intentionally NOT placed in the title; the resource_type provides lightweight context in the summary.
func IsKnownSeverity ¶
IsKnownSeverity reports whether s is in the closed Severity enum.
func IsKnownSource ¶
IsKnownSource reports whether s is in the closed Source enum.
Types ¶
type Caller ¶
Caller is the per-source permission gate. A caller without CanReadAlerts sees zero alert rows; etc. The activity service reports the count hidden by the gate so the UI can render an honest "N visible / M hidden" line.
type Filter ¶
type Filter struct {
Source string // "" or one of AllSources
Severity string // "" or one of AllSeverities
HostID *uuid.UUID
Since *time.Time
Until *time.Time
Cursor string
Limit int
}
Filter narrows the union query. Empty fields are wildcards.
type Row ¶
type Row struct {
ID uuid.UUID
Source Source
Severity Severity
HostID *uuid.UUID // nil for audit / system rows
Title string
Summary string
OccurredAt time.Time
}
Row is one entry in the activity feed.
type RuleTitleFunc ¶
RuleTitleFunc resolves a Kensa rule id to its catalog title. Injected by the server from the rule catalog so this package takes no kensa dependency. Nil-safe: a nil func (or a miss) falls back to the rule id.
type Service ¶
type Service struct {
// contains filtered or unexported fields
}
Service serves Activity feeds via a single UNION query.
func NewService ¶
NewService binds a Service to a pgxpool.
func (*Service) List ¶
List returns a page of activity rows and the count hidden by RBAC. Spec C-01..C-06; AC-01..AC-10.
func (*Service) WithRuleTitler ¶
func (s *Service) WithRuleTitler(f RuleTitleFunc) *Service
WithRuleTitler injects the rule-id -> title resolver used to render the compliance (transaction) leg's headline. Nil-safe; without it the leg falls back to the raw rule id. Returns the Service for chaining.
type Severity ¶
type Severity string
Severity is the closed enum used by the union (info/low/medium/high/critical). Audit-event rows whose native severity is warning|error are mapped to medium|high in the SELECT to fit the closed set.
type Source ¶
type Source string
Source classifies which underlying table produced a Row. Stored as the 'source' literal column in the UNION query.
const ( SourceAlert Source = "alert" SourceTransaction Source = "transaction" SourceIntelligence Source = "intelligence" SourceAudit Source = "audit" // SourceMonitoring projects host_monitoring_history band-transition // rows into the unified feed. Spec system-activity v1.1.0 C-08. SourceMonitoring Source = "monitoring" )