basalt / audit/src / AuditStore
Interface: AuditStore
Defined in: audit/src/index.ts:147
Append-only by contract: no update, no delete.
The chain methods are optional — a store without them works exactly as before, but cannot back integrity: 'hash-chain'. A store that implements them MUST also reject an append whose (auditChainKey(tenantId), seq) already exists with AuditChainConflictError (a unique constraint in SQL): that is what keeps concurrent writers on several replicas from forking a chain.
Methods
append()
> append(entry): Promise<void>
Defined in: audit/src/index.ts:148
Parameters
entry
Returns
Promise<void>
auditTenants()?
> optional auditTenants(): Promise<(string | undefined)[]>
Defined in: audit/src/index.ts:165
Every tenant that has at least one row, chained or not (undefined = rows without a tenant). Optional: Audit.verifyAll uses it to reach tenants whose rows were all written outside a chain — without it, it falls back to scanning query({}), which reads the whole trail. Implement it with a SELECT DISTINCT tenant_id in a durable store.
Returns
Promise<(string | undefined)[]>
chainHead()?
> optional chainHead(tenantId): Promise<AuditChainHead | undefined>
Defined in: audit/src/index.ts:151
Latest chained entry of the tenant's chain (undefined tenant = system chain).
Parameters
tenantId
string | undefined
Returns
Promise<AuditChainHead | undefined>
chainTenants()?
> optional chainTenants(): Promise<(string | undefined)[]>
Defined in: audit/src/index.ts:157
Tenants that have a chain (undefined = the system chain).
Returns
Promise<(string | undefined)[]>
countUnchained()?
> optional countUnchained(tenantId): Promise<number>
Defined in: audit/src/index.ts:155
Rows of the tenant (undefined = no tenant) written without a chain (before integrity was on).
Parameters
tenantId
string | undefined
Returns
Promise<number>
query()
> query(query): Promise<AuditEntry[]>
Defined in: audit/src/index.ts:149
Parameters
query
Returns
Promise<AuditEntry[]>
readChain()?
> optional readChain(tenantId, range): Promise<AuditEntry[]>
Defined in: audit/src/index.ts:153
Chained entries of one chain with fromSeq <= seq <= toSeq, ascending, at most limit.
Parameters
tenantId
string | undefined
range
Returns
Promise<AuditEntry[]>
readUnchained()?
> optional readUnchained(tenantId, range): Promise<AuditEntry[]>
Defined in: audit/src/index.ts:174
Rows attributed to the tenant (undefined = no tenant) that are NOT part of its chain — no seq, or a chain other than auditChainKey(tenantId) — with at >= range.since, plus every such row that carries a seq or a chain name whatever its at (a legacy row has neither). Oldest first, at most range.limit. Optional: without it Audit.verify falls back to scanning query().
Parameters
tenantId
string | undefined
range
Returns
Promise<AuditEntry[]>