Add workspace audit history - #1920
Draft
RhysSullivan wants to merge 1 commit into
Draft
Conversation
Contributor
Cloudflare preview
Sign-in is Cloudflare Access (one-time PIN to an allowed email). The preview has its own database and encryption key; it is destroyed when this PR closes. |
@executor-js/cli
@executor-js/config
@executor-js/execution
@executor-js/sdk
@executor-js/codemode-core
@executor-js/runtime-quickjs
@executor-js/plugin-file-secrets
@executor-js/plugin-graphql
@executor-js/plugin-keychain
@executor-js/plugin-mcp
@executor-js/plugin-onepassword
@executor-js/plugin-openapi
executor
commit: |
RhysSullivan
force-pushed
the
workspace-audit-history
branch
from
September 1, 2026 18:42
7e40e37 to
199ab29
Compare
Deploying with
|
| Status | Name | Latest Commit | Updated (UTC) |
|---|---|---|---|
| ✅ Deployment successful! View logs |
executor-cloud | 95b4419 | Sep 02 2026, 10:43 AM |
Deploying with
|
| Status | Name | Latest Commit | Preview URL | Updated (UTC) |
|---|---|---|---|---|
| ✅ Deployment successful! View logs |
executor-marketing | 95b4419 | Commit Preview URL Branch Preview URL |
Sep 02 2026, 10:42 AM |
RhysSullivan
force-pushed
the
workspace-audit-history
branch
5 times, most recently
from
September 2, 2026 10:31
1ca74ee to
6db082b
Compare
RhysSullivan
force-pushed
the
workspace-audit-history
branch
from
September 2, 2026 10:40
6db082b to
c8e6502
Compare
Co-authored-by: Max schwenk <maschwenk@gmail.com>
RhysSullivan
force-pushed
the
workspace-audit-history
branch
from
September 2, 2026 10:40
c8e6502 to
95b4419
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds workspace audit history. Second of two stacked PRs split from #1786; based on #1919.
A new append-only, tenant-scoped
audit_eventtable records configuration changes: integrations, connections, OAuth clients, and tool policies. When a failed write is compensated, the log recordsrolled_back, orrollback_failedif the provider restore also failed. Payloads hold safe identifiers only, never credential values. Reads are admin-gated and shown in the admin console Activity tab.Also included: the fumadb MySQL generator now requires bounded string primary keys, and
IdColumnTypeis exported (major changeset).Verification
bun run format:checkbun run lintbun run typecheckbun run testadmin-users-console(cloud and selfhost) asserts the Activity tab renders audit events;workspace-write-permissions(cloud) exercises the migration chain at boot.Checklist
bun run changeset), or this change needs none.