Skip to content

feat: add workspace build start/stop to audit log #4744

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 14 commits into from
Oct 25, 2022
Prev Previous commit
Next Next commit
adding workspace name to string
  • Loading branch information
Kira-Pilot committed Oct 25, 2022
commit ec3e6bf9f2f8f95a6e3075e14661043ad0b0a46c
9 changes: 8 additions & 1 deletion coderd/audit.go
Original file line number Diff line number Diff line change
Expand Up @@ -219,6 +219,10 @@ func convertAuditLog(dblog database.GetAuditLogsOffsetRow) codersdk.AuditLog {
}
}

type WorkspaceResourceInfo struct {
WorkspaceName string
}

func auditLogDescription(alog database.GetAuditLogsOffsetRow) string {
str := fmt.Sprintf("{user} %s %s",
codersdk.AuditAction(alog.Action).FriendlyString(),
Expand All @@ -229,7 +233,10 @@ func auditLogDescription(alog database.GetAuditLogsOffsetRow) string {
// "{user} started workspace build for workspace {target}"
// where target is a workspace instead of the workspace build
if alog.ResourceType == database.ResourceTypeWorkspaceBuild {
str += " for workspace"
workspace_bytes := []byte(alog.AdditionalFields)
var workspaceResourceInfo WorkspaceResourceInfo
json.Unmarshal(workspace_bytes, &workspaceResourceInfo)
str += " for workspace " + workspaceResourceInfo.WorkspaceName
}

// We don't display the name for git ssh keys. It's fairly long and doesn't
Expand Down
10 changes: 6 additions & 4 deletions coderd/audit/request.go
Original file line number Diff line number Diff line change
Expand Up @@ -20,8 +20,9 @@ type RequestParams struct {
Audit Auditor
Log slog.Logger

Request *http.Request
Action database.AuditAction
Request *http.Request
Action database.AuditAction
AdditionalFields json.RawMessage
}

type Request[T Auditable] struct {
Expand All @@ -44,7 +45,8 @@ func ResourceTarget[T Auditable](tgt T) string {
case database.Workspace:
return typed.Name
case database.WorkspaceBuild:
return string(typed.Transition)
// this isn't used
return string(typed.BuildNumber)
case database.GitSSHKey:
return typed.PublicKey
case database.Group:
Expand Down Expand Up @@ -149,7 +151,7 @@ func InitRequest[T Auditable](w http.ResponseWriter, p *RequestParams) (*Request
Diff: diffRaw,
StatusCode: int32(sw.Status),
RequestID: httpmw.RequestID(p.Request),
AdditionalFields: json.RawMessage("{}"),
AdditionalFields: p.AdditionalFields,
})
if err != nil {
p.Log.Error(logCtx, "export audit log", slog.Error(err))
Expand Down
26 changes: 22 additions & 4 deletions coderd/workspacebuilds.go
Original file line number Diff line number Diff line change
Expand Up @@ -300,12 +300,30 @@ func (api *API) postWorkspaceBuilds(rw http.ResponseWriter, r *http.Request) {
// if a user starts/stops a workspace, audit the workspace build
if action == rbac.ActionUpdate {

var auditAction database.AuditAction
if createBuild.Transition == codersdk.WorkspaceTransitionStart {
auditAction = database.AuditActionStart
} else if createBuild.Transition == codersdk.WorkspaceTransitionStop {
auditAction = database.AuditActionStop
} else {
auditAction = database.AuditActionWrite
}

// We pass the workspace name to the Auditor so that it
// can form a friendly string for the user.
workspaceResourceInfo := map[string]string{
"workspaceName": workspace.Name,
}

wri_bytes, _ := json.Marshal(workspaceResourceInfo)

var (
aReq, commitAudit = audit.InitRequest[database.WorkspaceBuild](rw, &audit.RequestParams{
Audit: *auditor,
Log: api.Logger,
Request: r,
Action: database.AuditActionWrite,
Audit: *auditor,
Log: api.Logger,
Request: r,
Action: auditAction,
AdditionalFields: wri_bytes,
})
)

Expand Down