Files
minstrel/internal/audit/audit.go
T
bvandeusenandClaude Opus 5.5 e17556dce9
release / govulncheck (push) Successful in 18s
release / web (push) Successful in 1m26s
release / go (push) Successful in 1m45s
release / integration (push) Successful in 5m6s
release / android (push) Successful in 5m58s
release / Build signed APK (releases and dev) (push) Successful in 6m17s
release / Attach APK to the Release (tag releases only) (push) Skipped
release / Build + push container image (push) Successful in 26s
release / Verify release artifacts (tag releases only) (push) Skipped
feat: Lidarr searches for a better copy of a rip that has none (M498 #5447)
The operator chose option 2: an album holding a video rip that is the only
copy of its song is searched in Lidarr (AlbumSearch), at most once a week
and ten albums a pass. Lidarr grabs only when the quality profile allows an
upgrade, so nothing is removed and the rip stays held back either way.

- lidarr.Client.SearchAlbums posts the AlbumSearch command.
- ListAlbumsWithSoleCopyRips finds the albums: a held-back rip with no
  present clean copy sharing its song or its pending group, and not searched
  in the last week (audit action lidarr_rip_search).
- Suspect sources shows when Lidarr last searched the track's album.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-08 22:32:30 -04:00

117 lines
4.7 KiB
Go

// Package audit writes admin-driven user-management events to audit_log.
// Thin wrapper over the sqlc-generated WriteAuditLog query — the value
// is centralizing the action-name vocabulary and the metadata
// marshaling so callers don't repeat boilerplate.
//
// Audit writes are best-effort from the caller's perspective: a failed
// audit write must NOT fail the user-facing operation. Callers
// log-and-continue. The audit log is observability, not a transaction
// participant.
package audit
import (
"context"
"encoding/json"
"log/slog"
"github.com/jackc/pgx/v5/pgtype"
"github.com/jackc/pgx/v5/pgxpool"
"git.fabledsword.com/bvandeusen/minstrel/internal/db/dbq"
)
// Action is the discriminator stored in audit_log.action. New values
// added in U2/U3 + future tasks; declare them here so callers don't
// stringly-type and so a future audit-search UI has a single source
// of truth for the vocabulary.
type Action string
const (
// U1
ActionRegister Action = "register"
ActionPromoteAdmin Action = "promote_admin"
ActionDemoteAdmin Action = "demote_admin"
ActionInviteCreate Action = "invite_create"
ActionInviteRedeem Action = "invite_redeem"
ActionInviteRevoke Action = "invite_revoke"
// U2 (declared early; callers in U1 don't use them yet, but
// having them here means U2's diff is purely additive on the
// caller side, not also touching this file).
ActionCreateUserAdmin Action = "create_user_admin"
ActionDeleteUser Action = "delete_user"
ActionPasswordResetAdmin Action = "password_reset_admin"
ActionAutoApproveToggle Action = "auto_approve_toggle"
// U3
ActionPasswordChangeSelf Action = "password_change_self"
ActionTokenRegenerate Action = "token_regenerate"
ActionForgotPasswordInit Action = "forgot_password_initiated"
ActionPasswordResetByEmail Action = "password_reset_via_email"
// Active-sessions surface (#370). Worth auditing rather than silent:
// revoking sessions is what a user does when they think an account is
// compromised, so the audit trail is most useful precisely when it's
// exercised.
ActionSessionRevoke Action = "session_revoke"
ActionSessionRevokeOthers Action = "session_revoke_others"
// Duplicate merge (#3911). Irreversible: a copy's file and row are removed
// and its history moved onto the copy kept. The metadata names both, so the
// log can answer "where did that file go" long after the report is gone.
ActionDuplicateMerge Action = "duplicate_merge"
// Lidarr release change (M498 #5437): the duplicate resolver moved an
// album's monitored release in Lidarr to one that lists each song once.
// Written with no actor; the metadata names the album and both releases.
ActionLidarrReleaseChange Action = "lidarr_release_change"
// Lidarr rip search (M498 #5447): the resolver asked Lidarr to search an
// album whose only copy of a song is a video rip, for a better release.
// Written with no actor; the metadata names the album and how many rips.
ActionLidarrRipSearch Action = "lidarr_rip_search"
// Subsonic password (#5026): generated in Settings for t/s-only clients.
ActionSubsonicPasswordSet Action = "subsonic_password_set"
ActionSubsonicPasswordClear Action = "subsonic_password_clear"
)
// Write inserts one audit_log row. metadata is marshaled as JSON;
// nil metadata writes SQL NULL. Errors are returned so callers can
// log them — but per package doc, callers should NOT fail user-facing
// operations on audit-write failures.
//
// actorID may be a zero/invalid pgtype.UUID for system actions
// (e.g. self-registration where the new user is both actor and
// target — pass them as the same id, or pass invalid for actor and
// the new user as target).
func Write(ctx context.Context, pool *pgxpool.Pool, actorID, targetID pgtype.UUID, action Action, metadata map[string]any) error {
q := dbq.New(pool)
var jsonMeta []byte
if metadata != nil {
b, err := json.Marshal(metadata)
if err != nil {
return err
}
jsonMeta = b
}
return q.WriteAuditLog(ctx, dbq.WriteAuditLogParams{
ActorID: actorID,
TargetID: targetID,
Action: string(action),
Metadata: jsonMeta,
})
}
// WriteOrLog writes the audit row; on error, logs at Warn and swallows
// (audit failures must not break user-facing operations — see package doc).
// Use this when the audit is observability, not gating; use Write directly
// when the caller needs strict semantics (e.g. tests).
func WriteOrLog(ctx context.Context, pool *pgxpool.Pool, logger *slog.Logger, actorID, targetID pgtype.UUID, action Action, metadata map[string]any) {
if err := Write(ctx, pool, actorID, targetID, action, metadata); err != nil {
if logger != nil {
logger.Warn("audit failed", "action", string(action), "err", err)
}
}
}