basalt / audit/src / AuditEntry
Interface: AuditEntry
Defined in: audit/src/index.ts:33
One immutable line of the trail.
Properties
actorId?
> readonly optional actorId?: string
Defined in: audit/src/index.ts:40
Enriched from the ALS context at record time.
at
> readonly at: number
Defined in: audit/src/index.ts:47
event
> readonly event: string
Defined in: audit/src/index.ts:37
hash?
> readonly optional hash?: string
Defined in: audit/src/index.ts:57
Self-describing hash over prevHash + the canonical entry: v2:sha256:<hex> or v2:hmac-sha256:<keyId>:<hex> (see computeAuditHashV2), or a bare 64-hex legacy (v1) hash on entries written before key ids existed.
id
> readonly id: string
Defined in: audit/src/index.ts:34
ip?
> readonly optional ip?: string
Defined in: audit/src/index.ts:44
Client IP of the originating HTTP request (opt-in, PII — see requestContext).
payload
> readonly payload: unknown
Defined in: audit/src/index.ts:38
prevHash?
> readonly optional prevHash?: string
Defined in: audit/src/index.ts:51
hash of the previous entry in the chain (AUDIT_CHAIN_GENESIS for the first).
requestId?
> readonly optional requestId?: string
Defined in: audit/src/index.ts:42
seq?
> readonly optional seq?: number
Defined in: audit/src/index.ts:49
Position in the tenant's hash chain (from 1). Absent on unchained entries.
source
> readonly source: "hook" | "event" | "manual"
Defined in: audit/src/index.ts:36
Where it came from: a lifecycle hook, a domain event or a manual record.
tenantId?
> readonly optional tenantId?: string
Defined in: audit/src/index.ts:41
userAgent?
> readonly optional userAgent?: string
Defined in: audit/src/index.ts:46
User-agent of the originating HTTP request (opt-in, truncated to 512 chars).