fix(audit): readable names, single writer, denial rows, redacted args

The activity log recorded Start's hashed function id (a sha256 URL
segment) as the name; the middleware now reads compile-time
serverFnMeta.name with the path segment as fallback. toServerResult
resolves { success:false } instead of throwing, so the middleware logged
failures as successes while toServerResult wrote a duplicate row with its
own dead name parser — the middleware is now the single writer and reads
the envelope's success flag. Admin denials, which threw before the logging
middleware ran, get their own audit row. Arguments are redacted
(phone/otp/token keys) and truncated at 2KB. The admin activities search
binds its filter parameters (likePattern escaping) instead of
interpolating raw input. Adds vitest with node-env tests for the
middleware, redaction, and filter utils, and extends logging coverage to
mutating fns that lacked it.
This commit is contained in:
2026-08-23 18:27:53 -07:00
parent 60e91d1371
commit 9fc79dfc07
18 changed files with 691 additions and 67 deletions
+14
View File
@@ -0,0 +1,14 @@
// Mirrors PocketBase's own scan of a quoted literal: a backslash consumes the
// character after it, so an unterminated literal is exactly what a trailing
// backslash produces.
export const literalTerminates = (expression: string) => {
const open = expression.indexOf("'");
for (let i = open + 1; i < expression.length; i++) {
if (expression[i] === "\\") {
i++;
continue;
}
if (expression[i] === "'") return true;
}
return false;
};