pub struct AuditTrail { /* private fields */ }Expand description
A tamper-evident audit trail with cryptographic hash chain.
Each entry is cryptographically linked to the previous entry using blake3 hashing. This makes it possible to detect any tampering with historical entries.
Implementations§
Source§impl AuditTrail
impl AuditTrail
Sourcepub fn append(
&self,
actor: AgentId,
action: AuditAction,
resource: String,
) -> HashDigest
pub fn append( &self, actor: AgentId, action: AuditAction, resource: String, ) -> HashDigest
Append an audit entry. Computes hash chain automatically.
Sourcepub fn append_with_meta(
&self,
actor: AgentId,
action: AuditAction,
resource: String,
metadata: Option<Value>,
) -> HashDigest
pub fn append_with_meta( &self, actor: AgentId, action: AuditAction, resource: String, metadata: Option<Value>, ) -> HashDigest
Append an audit entry with optional metadata.
Sourcepub fn verify(&self) -> Result<bool, AuditError>
pub fn verify(&self) -> Result<bool, AuditError>
Verify the integrity of the hash chain.
The chain is valid if:
- The first entry has prev_hash “genesis” or “pruned” (after auto-pruning)
- Every subsequent entry’s prev_hash matches the previous entry’s hash
- Every entry’s hash can be independently recomputed
Sourcepub fn entries(&self, from_seq: u64, to_seq: u64) -> Vec<AuditEntry>
pub fn entries(&self, from_seq: u64, to_seq: u64) -> Vec<AuditEntry>
Get entries within a sequence range (inclusive).
Sourcepub fn all_entries(&self) -> Vec<AuditEntry>
pub fn all_entries(&self) -> Vec<AuditEntry>
Get all entries.
Sourcepub fn by_agent(&self, agent_id: &str) -> Vec<AuditEntry>
pub fn by_agent(&self, agent_id: &str) -> Vec<AuditEntry>
Query entries by agent ID.
Sourcepub fn by_action(&self, action: &AuditAction) -> Vec<AuditEntry>
pub fn by_action(&self, action: &AuditAction) -> Vec<AuditEntry>
Query entries by action type.
Sourcepub fn by_action_type(&self, type_name: &str) -> Vec<AuditEntry>
pub fn by_action_type(&self, type_name: &str) -> Vec<AuditEntry>
Query entries by action discriminant (for faster lookup).
Sourcepub fn export_json(&self, from_seq: u64) -> Result<String, AuditError>
pub fn export_json(&self, from_seq: u64) -> Result<String, AuditError>
Export entries from a sequence number as JSON.
Sourcepub fn export_all_json(&self) -> Result<String, AuditError>
pub fn export_all_json(&self) -> Result<String, AuditError>
Export all entries as JSON.
Sourcepub fn flush(&self, state_store: &StateStore) -> Result<(), AuditError>
pub fn flush(&self, state_store: &StateStore) -> Result<(), AuditError>
Flush entries to the state store for persistence.
Sourcepub fn restore_from(&self, entries: Vec<AuditEntry>)
pub fn restore_from(&self, entries: Vec<AuditEntry>)
Restore previously persisted entries.
Sets seq_counter to max(entries.seq) + 1 so new entries
don’t collide with restored ones. Trims to max_entries if
the restored set is larger, re-linking the hash chain.
Trait Implementations§
Source§impl Debug for AuditTrail
impl Debug for AuditTrail
Auto Trait Implementations§
impl !Freeze for AuditTrail
impl !RefUnwindSafe for AuditTrail
impl Send for AuditTrail
impl Sync for AuditTrail
impl Unpin for AuditTrail
impl UnsafeUnpin for AuditTrail
impl UnwindSafe for AuditTrail
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> Instrument for T
impl<T> Instrument for T
Source§fn instrument(self, span: Span) -> Instrumented<Self>
fn instrument(self, span: Span) -> Instrumented<Self>
Source§fn in_current_span(self) -> Instrumented<Self>
fn in_current_span(self) -> Instrumented<Self>
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§impl<T> Pipe for Twhere
T: ?Sized,
impl<T> Pipe for Twhere
T: ?Sized,
Source§fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> Rwhere
Self: Sized,
fn pipe<R>(self, func: impl FnOnce(Self) -> R) -> Rwhere
Self: Sized,
Source§fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> Rwhere
R: 'a,
fn pipe_ref<'a, R>(&'a self, func: impl FnOnce(&'a Self) -> R) -> Rwhere
R: 'a,
self and passes that borrow into the pipe function. Read moreSource§fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> Rwhere
R: 'a,
fn pipe_ref_mut<'a, R>(&'a mut self, func: impl FnOnce(&'a mut Self) -> R) -> Rwhere
R: 'a,
self and passes that borrow into the pipe function. Read moreSource§fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
fn pipe_borrow<'a, B, R>(&'a self, func: impl FnOnce(&'a B) -> R) -> R
Source§fn pipe_borrow_mut<'a, B, R>(
&'a mut self,
func: impl FnOnce(&'a mut B) -> R,
) -> R
fn pipe_borrow_mut<'a, B, R>( &'a mut self, func: impl FnOnce(&'a mut B) -> R, ) -> R
Source§fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
fn pipe_as_ref<'a, U, R>(&'a self, func: impl FnOnce(&'a U) -> R) -> R
self, then passes self.as_ref() into the pipe function.Source§fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
fn pipe_as_mut<'a, U, R>(&'a mut self, func: impl FnOnce(&'a mut U) -> R) -> R
self, then passes self.as_mut() into the pipe
function.Source§fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
fn pipe_deref<'a, T, R>(&'a self, func: impl FnOnce(&'a T) -> R) -> R
self, then passes self.deref() into the pipe function.Source§impl<T> Pointable for T
impl<T> Pointable for T
Source§impl<T> PolicyExt for Twhere
T: ?Sized,
impl<T> PolicyExt for Twhere
T: ?Sized,
Source§impl<R, P> ReadPrimitive<R> for P
impl<R, P> ReadPrimitive<R> for P
Source§fn read_from_little_endian(read: &mut R) -> Result<Self, Error>
fn read_from_little_endian(read: &mut R) -> Result<Self, Error>
ReadEndian::read_from_little_endian().Source§impl<T> Tap for T
impl<T> Tap for T
Source§fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
fn tap_borrow<B>(self, func: impl FnOnce(&B)) -> Self
Borrow<B> of a value. Read moreSource§fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
fn tap_borrow_mut<B>(self, func: impl FnOnce(&mut B)) -> Self
BorrowMut<B> of a value. Read moreSource§fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
fn tap_ref<R>(self, func: impl FnOnce(&R)) -> Self
AsRef<R> view of a value. Read moreSource§fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
fn tap_ref_mut<R>(self, func: impl FnOnce(&mut R)) -> Self
AsMut<R> view of a value. Read moreSource§fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
fn tap_deref<T>(self, func: impl FnOnce(&T)) -> Self
Deref::Target of a value. Read moreSource§fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
fn tap_deref_mut<T>(self, func: impl FnOnce(&mut T)) -> Self
Deref::Target of a value. Read moreSource§fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self
fn tap_dbg(self, func: impl FnOnce(&Self)) -> Self
.tap() only in debug builds, and is erased in release builds.Source§fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self
fn tap_mut_dbg(self, func: impl FnOnce(&mut Self)) -> Self
.tap_mut() only in debug builds, and is erased in release
builds.Source§fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
fn tap_borrow_dbg<B>(self, func: impl FnOnce(&B)) -> Self
.tap_borrow() only in debug builds, and is erased in release
builds.Source§fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
fn tap_borrow_mut_dbg<B>(self, func: impl FnOnce(&mut B)) -> Self
.tap_borrow_mut() only in debug builds, and is erased in release
builds.Source§fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
fn tap_ref_dbg<R>(self, func: impl FnOnce(&R)) -> Self
.tap_ref() only in debug builds, and is erased in release
builds.Source§fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
fn tap_ref_mut_dbg<R>(self, func: impl FnOnce(&mut R)) -> Self
.tap_ref_mut() only in debug builds, and is erased in release
builds.Source§fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
fn tap_deref_dbg<T>(self, func: impl FnOnce(&T)) -> Self
.tap_deref() only in debug builds, and is erased in release
builds.