auditlog

package
v0.0.26 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 24, 2026 License: MIT Imports: 5 Imported by: 0

README

auditlog middleware

Records a structured AuditEntry after downstream handling. Status codes map to info, warning or critical severity. Configure one or more Sink implementations; the default writes through log.Printf.

sink := auditlog.NewBufferSink(10_000)
app.Use(auditlog.New(auditlog.Config{
    Sinks: []auditlog.Sink{sink},
    MinSeverity: auditlog.SeverityWarning,
    CaptureHeaders: []string{"X-Request-ID"},
}))

Captured header values are masked, but minimize collection and apply your data retention policy. This request-summary middleware is distinct from the core fh.AuditSink/ledger used by compliance features.

Documentation

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

func New

func New(cfg Config) fh.HandlerFunc

Types

type AuditEntry

type AuditEntry struct {
	Timestamp   time.Time         `json:"timestamp"`
	Severity    Severity          `json:"severity"`
	Event       Event             `json:"event"`
	ClientIP    string            `json:"client_ip"`
	Method      string            `json:"method"`
	Path        string            `json:"path"`
	StatusCode  int               `json:"status_code"`
	UserAgent   string            `json:"user_agent"`
	PrincipalID string            `json:"principal_id,omitempty"`
	RequestID   string            `json:"request_id,omitempty"`
	Details     map[string]string `json:"details,omitempty"`
	Duration    string            `json:"duration,omitempty"`
}

type BufferSink

type BufferSink struct {
	// contains filtered or unexported fields
}

func NewBufferSink

func NewBufferSink(maxSize int) *BufferSink

func (*BufferSink) Clear

func (s *BufferSink) Clear()

func (*BufferSink) Entries

func (s *BufferSink) Entries() []AuditEntry

func (*BufferSink) Write

func (s *BufferSink) Write(entry AuditEntry)

type Config

type Config struct {
	Sinks          []Sink
	MinSeverity    Severity
	Skip           func(fh.Ctx) bool
	CaptureHeaders []string
	Logger         fh.Logger
}

type Event

type Event string
const (
	EventAuthFailure    Event = "auth_failure"
	EventCSRFBlock      Event = "csrf_block"
	EventRateLimit      Event = "rate_limit"
	EventIPBlocked      Event = "ip_blocked"
	EventSuspicious     Event = "suspicious_request"
	EventConfigChange   Event = "config_change"
	EventPrivilegeEsc   Event = "privilege_escalation"
	EventDataAccess     Event = "data_access"
	EventInjection      Event = "injection_attempt"
	EventMITM           Event = "mitm_detected"
	EventDDoS           Event = "ddos_detected"
	EventReplayDetected Event = "replay_detected"
)

type LogSink

type LogSink struct {
	// contains filtered or unexported fields
}

func (*LogSink) Write

func (s *LogSink) Write(entry AuditEntry)

type Severity

type Severity string
const (
	SeverityInfo     Severity = "info"
	SeverityWarning  Severity = "warning"
	SeverityCritical Severity = "critical"
)

type Sink

type Sink interface {
	Write(entry AuditEntry)
}

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL