/** * Audit logging module (async). * * Punkt 13: Now stores ip_address and user_agent. * Fire-and-forget: errors are logged but don't block the caller. */ const db = require('./db'); function auditLog(userId, action, entityType, entityId, details, req) { const ip = req?.ip || req?.headers?.['x-forwarded-for'] || null; const userAgent = req?.headers?.['user-agent'] || null; db.prepare('INSERT INTO audit_log (user_id, action, entity_type, entity_id, details, ip_address, user_agent) VALUES (?, ?, ?, ?, ?, ?, ?)') .run(userId || null, action, entityType || null, entityId || null, details || null, ip, userAgent) .catch(err => console.error('Audit log error:', err.message)); } module.exports = { auditLog };