mirror of
https://github.com/openclaw/openclaw.git
synced 2026-08-27 12:56:01 -06:00
feat(audit): add execution identity inspection (#117034)
* feat(audit): add opt-in execution identity inspection * fix(audit): gate recovery identity retention * fix(audit): keep recovery identity type private * test(audit): type internal recovery fixture * test(audit): split recovery identity coverage * docs(audit): define operator read trust boundary * test(qa): register identity scenario child * fix(audit): enforce shared identity retention bounds * fix(audit): seal public ingress identity boundary * fix(audit): keep ingress guard lint-clean * fix(gateway): preserve advertised method order * chore(protocol): sync advertised method order * fix(protocol): encode audit selector invariants * test(audit): prove exact execution guard * fix(audit): keep identity storage lazy
This commit is contained in:
@@ -112,7 +112,7 @@ const coreCliCommandCatalog = defineCommandDescriptorCatalog([
|
||||
},
|
||||
{
|
||||
name: "audit",
|
||||
description: "Inspect metadata-only run, tool, and message lifecycle records",
|
||||
description: "Inspect activity records and exact-run identity context",
|
||||
hasSubcommands: false,
|
||||
},
|
||||
{
|
||||
|
||||
@@ -10,10 +10,11 @@ import { runCommandWithRuntime } from "../cli-utils.js";
|
||||
export function registerAuditCommand(program: Command): void {
|
||||
program
|
||||
.command("audit")
|
||||
.description("Inspect metadata-only run, tool, and message lifecycle records")
|
||||
.description("Inspect activity records and exact-run identity context")
|
||||
.option("--agent <id>", "Filter by agent id")
|
||||
.option("--session <key>", "Filter by exact session key")
|
||||
.option("--run <id>", "Filter by run id")
|
||||
.option("--execution <id>", "Inspect one exact execution id")
|
||||
.option("--kind <kind>", "Filter by kind (agent_run, tool_action, or message)")
|
||||
.option(
|
||||
"--status <status>",
|
||||
@@ -24,7 +25,8 @@ export function registerAuditCommand(program: Command): void {
|
||||
.option("--after <timestamp>", "Include records at/after ISO time or Unix milliseconds")
|
||||
.option("--before <timestamp>", "Include records at/before ISO time or Unix milliseconds")
|
||||
.option("--cursor <sequence>", "Continue from a previous result cursor")
|
||||
.option("--limit <count>", "Maximum records (1-500)", "100")
|
||||
.option("--limit <count>", "Maximum records (1-500; decisions 1-100)")
|
||||
.option("--explain", "Inspect execution identity and run-admission reasoning", false)
|
||||
.option("--json", "Output a bounded JSON page", false)
|
||||
.addHelpText(
|
||||
"after",
|
||||
@@ -38,6 +40,7 @@ export function registerAuditCommand(program: Command): void {
|
||||
agentId: opts.agent as string | undefined,
|
||||
sessionKey: opts.session as string | undefined,
|
||||
runId: opts.run as string | undefined,
|
||||
executionId: opts.execution as string | undefined,
|
||||
kind: opts.kind as AuditListCommandOptions["kind"],
|
||||
status: opts.status as AuditListCommandOptions["status"],
|
||||
direction: opts.direction as AuditListCommandOptions["direction"],
|
||||
@@ -46,6 +49,7 @@ export function registerAuditCommand(program: Command): void {
|
||||
before: opts.before as string | undefined,
|
||||
cursor: opts.cursor as string | undefined,
|
||||
limit: opts.limit as string | undefined,
|
||||
explain: Boolean(opts.explain),
|
||||
json: Boolean(opts.json),
|
||||
},
|
||||
defaultRuntime,
|
||||
|
||||
Reference in New Issue
Block a user