pub struct AuditRecord {
pub event: AuditEvent,
pub profile: String,
pub actor: Actor,
pub account_id: Option<String>,
pub order_id: Option<String>,
pub cert_serial: Option<String>,
pub identifiers: Vec<String>,
pub client: ClientContext,
pub reason: Option<String>,
pub detail: Option<String>,
}Expand description
One row, before it is written.
Built with AuditRecord::new plus the with_* setters rather than a
struct literal: the four events populate different subsets — an issuance
failure has no serial, an accountless revocation has no account — and a
literal would mean a column of Nones at every call site.
Fields§
§event: AuditEvent§profile: String§actor: Actor§account_id: Option<String>§order_id: Option<String>§cert_serial: Option<String>§identifiers: Vec<String>§client: ClientContext§reason: Option<String>§detail: Option<String>Implementations§
Source§impl AuditRecord
impl AuditRecord
Sourcepub fn new(event: AuditEvent, profile: impl Into<String>, actor: Actor) -> Self
pub fn new(event: AuditEvent, profile: impl Into<String>, actor: Actor) -> Self
A record of event at profile, by actor, with every optional field
empty; the with_* builders fill them in.
Sourcepub fn admin(event: AuditEvent, actor: Actor) -> Self
pub fn admin(event: AuditEvent, actor: Actor) -> Self
A record for an administrative action that is not scoped to one ACME
endpoint — an operator, a session, the nonce table, the audit log
itself. profile is stored empty (the column stays NOT NULL; ""
reads as “no profile”), and the acting identity is Actor plus
whatever AuditRecord::with_detail carries. Account, EAB and order
actions keep AuditRecord::new with their real profile.
Sourcepub fn with_order(
self,
order_id: Uuid,
account_id: Uuid,
identifiers: &[Identifier],
) -> Self
pub fn with_order( self, order_id: Uuid, account_id: Uuid, identifiers: &[Identifier], ) -> Self
Fills in the subject from an order: its id, its account and the names it covers, the last frozen into the row rather than joined back — the order may be deleted long before the row is read.
Takes the three fields rather than the stored order, which is a row of the storage layer this vocabulary sits below.
Sourcepub fn with_account(self, account_id: impl Into<String>) -> Self
pub fn with_account(self, account_id: impl Into<String>) -> Self
The account the row is about.
Sourcepub fn with_serial(self, serial: impl Into<String>) -> Self
pub fn with_serial(self, serial: impl Into<String>) -> Self
The certificate serial, lowercase unseparated hex.
Sourcepub fn with_client(self, client: ClientContext) -> Self
pub fn with_client(self, client: ClientContext) -> Self
Where the request came from: address, reverse name, User-Agent and
request id.
Sourcepub fn with_reason(self, reason: impl Into<String>) -> Self
pub fn with_reason(self, reason: impl Into<String>) -> Self
The RFC 8555 problem type on a refusal, or the RFC 5280 reason code on a revocation. Never both — see the column comment in the migration.
Sourcepub fn with_detail(self, detail: impl Into<String>) -> Self
pub fn with_detail(self, detail: impl Into<String>) -> Self
Free text for a human reading the trail. Never parsed.