Skip to content

basalt / audit/src / AuditPluginOptions

Interface: AuditPluginOptions ​

Defined in: audit/src/index.ts:1190

Properties ​

events? ​

> optional events?: string[]

Defined in: audit/src/index.ts:1201

Domain event patterns recorded from the EventBus (when present). Default: everything. Pass [] to disable.


hooks? ​

> optional hooks?: string[]

Defined in: audit/src/index.ts:1196

Lifecycle hook patterns to record automatically. Default: auth, billing, tenancy and permission activity.


integrity? ​

> optional integrity?: AuditIntegrity

Defined in: audit/src/index.ts:1228

'hash-chain' makes the trail verifiable: every entry is linked to the previous one of its tenant's chain, audit.verify() detects tampering, and the audit:verify CLI command is registered. See AuditOptions.integrity.


onCaptureError? ​

> optional onCaptureError?: (error, info) => void

Defined in: audit/src/index.ts:1221

Called when a bridged capture fails — a hook or event the plugin picked up automatically. Defaults to logging.

The bridge is opportunistic: it must never fail (or slow down) the domain write that emitted the hook, the same rule @basaltkit/realtime applies to its own bridge. A deliberate audit.record() still throws, because there the audit is the operation.

The default logs rather than staying quiet: a trail with a silent hole is worse than no trail, because it looks complete.

Parameters ​

error ​

unknown

info ​
event ​

string

source ​

"hook" | "event"

Returns ​

void


redact? ​

> optional redact?: AuditRedactor

Defined in: audit/src/index.ts:1207

Scrubs each payload before it is stored. Defaults to masking common secret keys (password, token, secret, authorization, api-key, …). Pass a custom function to change the policy, or (p) => p to store payloads verbatim.


requestContext? ​

> optional requestContext?: boolean | AuditRequestContextResolver

Defined in: audit/src/index.ts:1235

Record the client ip and userAgent. true registers an HTTP enricher (works on every adapter) that puts them in ctx().client; a function resolves them from the context itself. Off by default — IP is PII.


store? ​

> optional store?: AuditStore

Defined in: audit/src/index.ts:1191

Released under the MIT License.