DEV1.0: Initial commit - Workflow Portal with security fixes
- Backend: Express.js + PostgreSQL/SQLite with LDAP/AD integration - Frontend: React 18 + Vite + TailwindCSS/DaisyUI - Security fixes applied (2026-07 + 2026-08): - LDAP injection prevention, CSRF protection, HttpOnly cookies - Session hashing (SHA-256), account lockout, rate limiting - Input validation (zod), file upload security, CSP/HSTS headers - V3: express-rate-limit updated (ip-address SSRF fix) - V4: postcss updated (nanoid DoS fix) - V5: Rate-limit on /health endpoint - V6: Session rotation on login (session fixation prevention) - V9: Task values array limit (DoS prevention) - V10: Frontend XSS audit completed - Docker: Multi-stage build, non-root user, PostgreSQL + backup service
This commit is contained in:
18
backend/auditLog.js
Normal file
18
backend/auditLog.js
Normal file
@@ -0,0 +1,18 @@
|
||||
/**
|
||||
* Audit logging module (async).
|
||||
*
|
||||
* Punkt 13: Now stores ip_address and user_agent.
|
||||
* Fire-and-forget: errors are logged but don't block the caller.
|
||||
*/
|
||||
const db = require('./db');
|
||||
|
||||
function auditLog(userId, action, entityType, entityId, details, req) {
|
||||
const ip = req?.ip || req?.headers?.['x-forwarded-for'] || null;
|
||||
const userAgent = req?.headers?.['user-agent'] || null;
|
||||
|
||||
db.prepare('INSERT INTO audit_log (user_id, action, entity_type, entity_id, details, ip_address, user_agent) VALUES (?, ?, ?, ?, ?, ?, ?)')
|
||||
.run(userId || null, action, entityType || null, entityId || null, details || null, ip, userAgent)
|
||||
.catch(err => console.error('Audit log error:', err.message));
|
||||
}
|
||||
|
||||
module.exports = { auditLog };
|
||||
Reference in New Issue
Block a user