Files
rvbox/internal/server/store/audit_helpers.go
T

22 lines
946 B
Go

package store
import (
"context"
"crypto/sha256"
"database/sql"
"fmt"
)
// appendLateExpiryAudit records the first observed queue-deadline
// contradiction without copying command text, script bodies, or output into
// the separate audit budget. The command row remains the fast status path;
// this row is the durable operator/audit history.
func appendLateExpiryAudit(ctx context.Context, tx *sql.Tx, occurredAt int64, clientID string, issue [16]byte, receiptUnixNano int64) error {
payload := []byte(fmt.Sprintf("receipt_unix_nano=%d", receiptUnixNano))
digest := sha256.Sum256(payload)
_, err := tx.ExecContext(ctx, `INSERT INTO audit_events (
occurred_at, source, client_id, issue_uuid, action, outcome, compression, payload, raw_bytes, stored_bytes, sha256
) VALUES (?, 'session', ?, ?, 'late_after_expiry', 'observed', 1, ?, ?, ?, ?)`, occurredAt, clientID, issue[:], payload, len(payload), len(payload), digest[:])
return err
}