Commit 24a8574
authored
feat(logging): Winston structured logging, AuditLog module, and Sentry integration (#3318)
* feat(logging): add Winston structured logging, AuditLog module, and Sentry integration
- Winston JSON logging with configurable levels + X-Request-ID middleware
- AuditLog module with model, service, routes, policy, controller, and tests
- Sentry SDK integration with request context enrichment
- Enriched health endpoint with version, uptime, and dependency checks
- Config: log.json, log.level, sentry.dsn/environment/enabled, audit.ttlDays/enabled
* fix(logging): address review feedback — validation, layer fixes, JSDoc
- Validate X-Request-ID header to prevent log injection
- Mount requestId middleware before pre-parser routes
- Add orgId morgan token for org-scoped request correlation
- Fix Sentry dynamic import to destructure default export
- Add Zod validation in AuditService.log before persisting
- Validate userId/orgId as ObjectId in Zod schemas
- Return 400 on invalid audit query params instead of silent fallback
- Guard deleteMany against empty/missing filter
- Move health endpoint DB logic to HomeService (layer separation)
- Use response envelope in health endpoint
- Move health test to home module tests
- Add JSDoc @returns and @param annotations
* refactor(audit): replace manual controller instrumentation with auto-capture middleware
Move audit logging from individual controller calls to a global Express
middleware that hooks into res.on('finish'), matching the existing
analytics middleware pattern. This removes AuditService imports from
auth, billing, and organizations controllers while preserving the same
audit coverage via automatic route-based action derivation.
* fix(audit): address CodeRabbit review — reject blank action, use Winston logger, add 503 test
- AuditQuery.action now uses .min(1) to reject empty/whitespace-only strings
- AuditService error paths use Winston logger instead of console.error
- Added integration test for degraded health (503) response path
- Mock logger in audit service unit tests to avoid winston config dependency
* fix(health): protect detailed response behind admin auth
Public /api/health returns only { status } for K8s probes.
Admin users (via JWT cookie) get full details: db, uptime, version, memory.
Uses passport optional auth pattern (custom callback, never rejects).
* fix(audit): improve JSDoc @returns type for list method
Document the paginated result shape {data, total, page, perPage} for better developer experience.
* fix(audit): move validation to repository, add JSDoc, restore config in tests
- Move Zod schema validation from service to repository layer (proper dependency direction)
- Add @returns to optionalAuth and route factory JSDoc in home.route.js
- Restore config.organizations.enabled in afterAll to prevent cross-test leak1 parent 15ce95b commit 24a8574
34 files changed
Lines changed: 2381 additions & 19 deletions
File tree
- config/defaults
- lib
- middlewares
- tests
- services
- tests
- modules
- analytics/tests
- audit
- config
- controllers
- middlewares
- models
- policies
- repositories
- routes
- services
- tests
- auth/controllers
- home
- controllers
- routes
- services
- tests
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
50 | 50 | | |
51 | 51 | | |
52 | 52 | | |
53 | | - | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
54 | 58 | | |
55 | 59 | | |
56 | 60 | | |
| |||
90 | 94 | | |
91 | 95 | | |
92 | 96 | | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
93 | 102 | | |
94 | 103 | | |
95 | 104 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
39 | 39 | | |
40 | 40 | | |
41 | 41 | | |
42 | | - | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
43 | 50 | | |
44 | 51 | | |
45 | 52 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
9 | 9 | | |
10 | 10 | | |
11 | 11 | | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
12 | 20 | | |
13 | 21 | | |
14 | 22 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
43 | 43 | | |
44 | 44 | | |
45 | 45 | | |
| 46 | + | |
| 47 | + | |
46 | 48 | | |
47 | 49 | | |
48 | 50 | | |
| |||
177 | 179 | | |
178 | 180 | | |
179 | 181 | | |
180 | | - | |
| 182 | + | |
181 | 183 | | |
182 | 184 | | |
183 | 185 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
10 | 10 | | |
11 | 11 | | |
12 | 12 | | |
| 13 | + | |
13 | 14 | | |
14 | 15 | | |
15 | 16 | | |
| |||
70 | 71 | | |
71 | 72 | | |
72 | 73 | | |
| 74 | + | |
73 | 75 | | |
74 | 76 | | |
75 | 77 | | |
| |||
149 | 151 | | |
150 | 152 | | |
151 | 153 | | |
| 154 | + | |
152 | 155 | | |
153 | 156 | | |
154 | 157 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
197 | 197 | | |
198 | 198 | | |
199 | 199 | | |
| 200 | + | |
200 | 201 | | |
201 | 202 | | |
202 | 203 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
19 | 19 | | |
20 | 20 | | |
21 | 21 | | |
| 22 | + | |
| 23 | + | |
22 | 24 | | |
23 | 25 | | |
24 | 26 | | |
| |||
103 | 105 | | |
104 | 106 | | |
105 | 107 | | |
| 108 | + | |
| 109 | + | |
106 | 110 | | |
107 | 111 | | |
108 | 112 | | |
| |||
208 | 212 | | |
209 | 213 | | |
210 | 214 | | |
| 215 | + | |
| 216 | + | |
211 | 217 | | |
212 | 218 | | |
213 | 219 | | |
| |||
224 | 230 | | |
225 | 231 | | |
226 | 232 | | |
| 233 | + | |
| 234 | + | |
227 | 235 | | |
228 | 236 | | |
229 | 237 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
7 | 7 | | |
8 | 8 | | |
9 | 9 | | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
10 | 21 | | |
11 | 22 | | |
12 | 23 | | |
13 | 24 | | |
14 | 25 | | |
| 26 | + | |
15 | 27 | | |
16 | 28 | | |
17 | | - | |
18 | | - | |
19 | | - | |
| 29 | + | |
| 30 | + | |
20 | 31 | | |
21 | | - | |
22 | 32 | | |
23 | 33 | | |
24 | 34 | | |
| |||
0 commit comments