Skip to content

Add admin audit query endpoint with retention pruning - #1029

Merged
Userunknown84 merged 2 commits into
Userunknown84:mainfrom
pavsoss:feat/1023-audit-query
Jul 31, 2026
Merged

Userunknown84 merged 2 commits into
Userunknown84:mainfrom
pavsoss:feat/1023-audit-query

Conversation

@pavsoss

@pavsoss pavsoss commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

Summary

Part 2 of 2 for #1023. Builds on the tamper-evident audit store by making the
trail usable operationally.

Depends on Part 1 (feat/1023-audit-store).

  • GET /audit (admin only) returns stored records newest-first, with
    exact-match filters (actor, action, resource), an inclusive ISO-8601 time
    window, and limit/offset pagination. The response also reports whether the
    hash chain still verifies, so integrity status travels with the data.
  • Access reuses the existing privileged-route pattern: the service-to-service
    internal secret plus the forwarded caller identity and admin role — no new
    auth scheme.
  • A configurable retention window (AUDIT_RETENTION_DAYS) prunes records past
    the cutoff and re-seals the surviving chain so verification continues to pass.
    Pruning is the only sanctioned mutation of the otherwise append-only trail.
  • The new endpoint is documented in the OpenAPI spec.

Parts

Test plan

Coverage for filter composition, the inclusive time window, pagination and
limit clamping, and for the retention cutoff — including that pruning removes
only expired records, returns the deleted count, leaves the retained trail
verifying, and is a no-op for a non-positive window.

Closes #1023

@vercel

vercel Bot commented Jul 29, 2026

Copy link
Copy Markdown

@pavsoss is attempting to deploy a commit to the Aditya Sharma's projects Team on Vercel.

A member of the Team first needs to authorize it.

@Userunknown84 Userunknown84 left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Merge Conflict Shown

@pavsoss
pavsoss requested a review from Userunknown84 July 31, 2026 12:45
@Userunknown84
Userunknown84 merged commit aca7c27 into Userunknown84:main Jul 31, 2026
1 of 9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Feature]: Tamper-evident, queryable audit trail for the Flask ML API

2 participants