Skip to content

Emit document-audit events on SaveChanges

Placeholder ppxd requested to merge feat/event-document-audit into main

Summary

  • Record DocumentCreated/Modified/Deleted audit events for user-facing documents (project, release, environment, machine, account, channel, variable set, project group, feed, certificate) whenever they are persisted — the second of the two central, generic emission points for the Event history (the first being PR #412's deployment lifecycle handler).
  • Emission hooks the existing SquidDbContext.SaveChangesAsync and scans the ChangeTracker for entities registered in IAuditDocumentRegistry — a single decoupled allowlist (entities carry no audit concern, matching Squid's external-contributor philosophy). Adding a new audited document = one registry entry; no other change.
  • Audit rows are written in a second save afterwards so insert-generated ids are populated. The write is best-effort: a failure is logged and swallowed so it can never roll back or fail the originating change. Provenance comes from the context's ICurrentUser, so a portal/API edit is attributed to the editing user.
  • Extract a shared EventFactory so EventService and the interceptor build events identically (provenance + reference serialization in one place).
  • Serialize the Event-audit integration test classes into one xUnit collection to remove cross-class DB races (a latent flakiness the third class exposed).

Purely additive — no existing signature or behavior changed; the audit write is swallowed on failure. Builds on #411 (foundation) + #412 (lifecycle).

Test plan

  • Unit (7): AuditDocumentRegistry maps each document type to the right feed keys + name; unregistered/null entities are not audited; the registered-type allowlist is pinned.
  • Integration (real Postgres, 5): insert/modify/delete a document → DocumentCreated/Modified/Deleted with feed keys + name; two documents in one save → one event each on their own feeds; an unregistered entity (ServerTask) → nothing.
  • Non-breaking sweep: 144 doc-saving integration tests (Retention, Snapshot, Certificate, Variable, ServerTask) green with the interceptor active on every save.
  • Regression: full solution build clean; 62 Events unit + 22 Events integration green; verified in isolation (PR builds + passes on clean main).

Merge request reports

Loading