pub enum AuditEvent {
Show 27 variants
CertificateIssued,
CertificateIssueFailed,
CertificateRevoked,
CertificateRevokeFailed,
AccountDeactivated,
AccountContactUpdated,
AccountDeleted,
OrderDeleted,
EabCreated,
EabRevoked,
EabDeleted,
OperatorCreated,
OperatorRoleChanged,
OperatorContactUpdated,
OperatorPasswordChanged,
OperatorDisabled,
OperatorEnabled,
OperatorDeleted,
OperatorTotpEnrolled,
OperatorTotpDisabled,
OperatorRecoveryCodesRegenerated,
SessionRevoked,
JobCancelled,
JobAdvanced,
NonceCleanupCompleted,
AuditPruned,
DatabaseTransferred,
}Expand description
What this trail records: every action the CA takes on a certificate and its refusal, plus every administrative action taken on the CA itself.
A refusal is an audit record in its own right. “Who tried to revoke this certificate and was turned away” is the question the successes cannot answer, and it is the one asked after something has gone wrong.
Variants§
CertificateIssued
CertificateIssueFailed
CertificateRevoked
CertificateRevokeFailed
AccountDeactivated
AccountContactUpdated
AccountDeleted
OrderDeleted
EabCreated
EabRevoked
EabDeleted
OperatorCreated
OperatorRoleChanged
OperatorContactUpdated
OperatorPasswordChanged
OperatorDisabled
OperatorEnabled
OperatorDeleted
OperatorTotpEnrolled
OperatorTotpDisabled
OperatorRecoveryCodesRegenerated
SessionRevoked
JobCancelled
JobAdvanced
NonceCleanupCompleted
AuditPruned
DatabaseTransferred
Implementations§
Source§impl AuditEvent
impl AuditEvent
Sourcepub fn as_str(&self) -> &'static str
pub fn as_str(&self) -> &'static str
The stored form. This is the authority on the audit_log.event
vocabulary: 20260809120000_add_audit_log.sql’s CHECK (event IN (…))
was dropped by a later rebuild precisely so this enum is the only place
the set is defined, and AuditEntry::insert binds this, never a free
string.
Sourcepub fn outcome(&self) -> &'static str
pub fn outcome(&self) -> &'static str
success or failure, and the only definition of which is which.
The column exists so “show me everything that was refused” is an index
lookup rather than event LIKE '%_failed' written out in the CLI, the
API and the page. Deriving it here rather than at each insert is what
stops the two columns ever disagreeing. Exhaustive on purpose — no
catch-all — so an admin *_failed event added later is a compile error
until its author says which side it falls on.