Skip to content

fix: enforce privacy-safe audit event payloads - #30

Open
kholdrex wants to merge 5 commits into
masterfrom
test/audit-event-contract
Open

kholdrex wants to merge 5 commits into
masterfrom
test/audit-event-contract

Conversation

@kholdrex

@kholdrex kholdrex commented Sep 9, 2026

Copy link
Copy Markdown
Owner

Summary

Audit event payloads are now constrained to an explicit, privacy-safe contract before publication. This prevents raw SQL, prompts, bind values, row data, plans, and unsafe structured values from reaching telemetry subscribers while preserving useful decision metadata.

Changes

  • Allowlist audit payload keys and accept only safe scalar values.
  • Replace caller-supplied duration values with the measured duration.
  • Cover successful events, failure events, SecurityError, unsafe values, and subscriber failures.

Test plan

  • 605 RSpec examples pass.
  • RuboCop reports no offenses across 60 files.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant