Repository navigation
Feat/issue 119 audit logs append only - #160
Merged
Merged
Conversation
…ao de integridade
- Adicao de colunas previous_hash e hash com encadeamento criptografico SHA-256 no AuditLog - Triggers em nivel de SGBD (PostgreSQL / SQLite) bloqueando operacoes de UPDATE e DELETE - Bloqueio de mutacao na camada de aplicacao e eventos ORM - Servico de verificacao de integridade e continuidade da trilha de auditoria - Migracao Alembic e regras de permissao RBAC SQL para o banco - Testes automatizados cobrindo hash chain, triggers de bloqueio e deteccao de adulteracao - Documentacao tecnica completa e guia de armazenamento imutavel WORM
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
…ra módulo de mensagens
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
📌 Descrição & Motivação
Esta Pull Request implementa uma arquitetura de segurança em profundidade (Defense in Depth) e integridade criptográfica (Hash Chain) para a tabela
audit_logs, assegurando que registros administrativos sensíveis sejam estritamente append-only e não possam ser alterados (UPDATE) ou removidos (DELETE), seja por falha lógica na aplicação ou por comandos SQL diretos.Closes #119
🛠️ O que foi feito?
1. Integridade Criptográfica (Hash Chain SHA-256)
app/models/audit_log.py:previous_hash(VARCHAR(64), nullable para registro gênese) ehash(VARCHAR(64), non-nullable, indexada).app/core/security/audit.py:compute_audit_hash(...)utilizando SHA-256 sobre dados sensíveis (id,actor_user_id,action,resource_type,resource_id,result,details,created_at,previous_hash).2. Repositório, Serviço & Verificação de Integridade
app/repositories/audit_repository.py:update()edelete()para lançarAuditImmutabilityError(AUDIT_LOG_IMMUTABLE).add_record()para resgatar o último hash e encadear deterministicamente o novo registro.list_all_chronological()para recuperação sequencial da trilha.app/services/audit_service.py:verify_audit_trail_integrity(db)para auditoria em lote, detectando imediatamente quebras de elo (previous_hash) ou divergência de payload (hash mismatch).3. Triggers no SGBD & Permissões RBAC SQL
block_audit_log_mutation()e Triggerprevent_audit_log_mutationabortando transações deUPDATEeDELETE.RAISE(ABORT, ...)para manter a semântica em ambientes de teste.@event.listens_for(AuditLog, 'before_update')ebefore_deleteinterceptando mutações via session antes do flush.migrations/versions/e8b9c0d1e2f3_audit_logs_append_only_and_hash_chain.py):downgrade()limpo.REVOKE ALL; GRANT INSERT, SELECT ON audit_logs TO app_user).4. Documentação Técnica & Armazenamento WORM
docs/audit-immutability-worm.md:📦 Commits Atômicos