Skip to content

docs(proposals): structured security audit log format evaluation (#784) - #2

Open
henschwartz wants to merge 1 commit into
praxis-proxy:mainfrom
henschwartz:proposal/00784-structured-security-audit-log-format
Open

docs(proposals): structured security audit log format evaluation (#784)#2
henschwartz wants to merge 1 commit into
praxis-proxy:mainfrom
henschwartz:proposal/00784-structured-security-audit-log-format

Conversation

@henschwartz

Copy link
Copy Markdown

Summary

Discussion link

praxis-proxy/praxis#784 (tracking issue; origin documents migration from praxis)

Test plan

  • Frontmatter: issue, discussion, authors, stakeholders, repos, graduation_criteria
  • No ## How? section

@praxis-bot praxis-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review Summary

# Severity Line Finding
1 Critical 105 OCSF category numbering is incorrect: 6003 is Web Resources Activity, not API Activity (6002); HTTP Activity is class 4002, not part of category 6
2 Large 78 peer_identity_trust filter missing from security filter enumeration despite being SecurityClass::Security and producing HTTP 403 denials

Technical claims about policy (X-Policy-Violation, violation codes, policy.deny fallback, http_authz_rejection), basic_auth, ip_acl, rate_limit, csrf, guardrails, cors, access_log, and reload_diagnostics.rs were verified against the codebase and are accurate. Frontmatter is consistent with sibling proposals (00797, 00799).

Comment thread proposals/00784_structured-security-audit-log-format.md
Comment thread proposals/00784_structured-security-audit-log-format.md
Spike proposal migrated from praxis-proxy/praxis#1004; evaluates OCSF,
ECS, CloudEvents, and custom JSON for denial audit records.

Signed-off-by: Hen Schwartz <hschwart@redhat.com>
@henschwartz
henschwartz force-pushed the proposal/00784-structured-security-audit-log-format branch from c488ea2 to 3cafc9f Compare August 25, 2026 08:28
@shaneutt
shaneutt requested review from alexsnaps and shaneutt August 25, 2026 16:36
@shaneutt shaneutt self-assigned this Aug 25, 2026
@shaneutt shaneutt moved this from Next to Review in Core Proxy Aug 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Review

Development

Successfully merging this pull request may close these issues.

3 participants