Admin audit: server-side filters + per-grant use counts - #719
Open
time-attack wants to merge 32 commits into
Open
Admin audit: server-side filters + per-grant use counts#719time-attack wants to merge 32 commits into
time-attack wants to merge 32 commits into
Conversation
…oarding Under HARNESS=claude with only CLAUDE_CODE_OAUTH_TOKEN (or ANTHROPIC_AUTH_TOKEN), turns work but the deployment reported itself unconfigured: surface-config's modelProviderConfigured only consulted the credential store, and the admin onboarding badge said 'Needs a key'. harnessCarriedModelAuth(config) names the provider a harness authenticates on its own (claude -> anthropic via OAuth/auth token, codex -> openai via CODEX_ACCESS_TOKEN). It is OR'd into modelProviderConfigured and exposed to the admin as a sibling harnessAuth field on GET /v1/admin/model-providers. The credential-store statuses stay untouched: anthropic still reports absent, because those keys feed pi-transport calls and deleting or adding them is independent of harness OAuth.
Co-Authored-By: QM <qm@ycombinator.com>
Invert PR 690's auth flow: the subscription login is a per-user keychain credential, core is the single custodian and refresher, and harnesses receive derived ephemeral material at spawn (Codex: minimal auth.json without the refresh token; Claude: injected env token). - CodexAuthStore abstraction: keychainCodexAuthStore (production, CODEX_AUTH_CREDENTIAL) and fileCodexAuthStore (local dev, CODEX_AUTH_FILE), both with central refresh and single-flight rotation - claude harness authEnv hook + keychainHarnessAuthEnv (CLAUDE_AUTH_CREDENTIAL) - child auth.json never carries the refresh token; no sync-back path, so the lock-file persistence machinery and JWKS re-verification are gone - production ban now applies only to the file path; keychain path is the supported production route
- AuditLog.tail gains resourceContains; optional tallyByResource(action) - Postgres impl: LIKE filter, grouped count query, (action, at) index - /v1/admin/audit accepts ?action=&resource=&limit= (cap 2000 when filtered) - /v1/admin/keychain grants now carry useCount from keychain.materialize audit rows
Adds the missing coverage for 499cc64 and removes the one comment that violated the repo's zero-comments rule: - audit-log unit + pg: tail resourceContains substring filter, tallyByResource per-resource counts scoped to one action - admin/audit route: action / resource / limit filters constrain results - admin/keychain route: grant useCount counts (grant <id>) materialize rows, ignoring owner-auth rows and unrelated grant ids pg tests are DATABASE_URL-gated (green locally against real Postgres); tsc + eslint clean.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Supersedes #713 (closed, unmerged) — same change, now with the missing test coverage and the one stray comment removed.
Backs the admin per-grant usage view with real Postgres queries instead of the 200-event tail:
New in this PR over #713
Verified: tsc + eslint clean; the 5 Postgres tests pass against real Postgres; 30 non-pg tests pass. Also exercised end-to-end live (filters + useCount) against a booted instance.
Need help on this PR? Tag
@codesmith-botwith what you need. Autofix is disabled.