Kaizen
Browse modulesAccessaccess/serverClasses

Class: DecisionLogRepository

Defined in: server/access/decision-log-repository.ts:23

Append-only writer for the decision audit log. SENSITIVE security dataset — the trace holds policy references + condition outcomes only, never full resource payloads. In v1 this backs the OPT-IN createTableDecisionSink adapter (an onDecision hook implementation); the default audit boundary is the no-op hook. Writes are fire-and-forget off the hot path (the sink wraps append so a failure never fails the can() decision), so this repo only exposes append + read helpers; there is no update/delete surface.

Extends

Constructors

Constructor

new DecisionLogRepository(prismaClient: PrismaClientLike<Tx<PrismaClient<PrismaClientOptions, never, DefaultArgs>>> & PrismaClient<PrismaClientOptions, never, DefaultArgs>, options?: RepositoryOptions): DecisionLogRepository;

Defined in: server/persistence/base-repository.ts:68

Parameters

ParameterType
prismaClientPrismaClientLike<Tx<PrismaClient<PrismaClientOptions, never, DefaultArgs>>> & PrismaClient<PrismaClientOptions, never, DefaultArgs>
optionsRepositoryOptions

Returns

DecisionLogRepository

Inherited from

BaseRepository.constructor

Properties

ENTITY_TYPE?

protected readonly optional ENTITY_TYPE?: string;

Defined in: server/persistence/base-repository.ts:61

Set ENTITY_TYPE in child repositories to enable automatic activity logging. When set, create/update/delete operations auto-log unless silenced with .silent. Requires an activity model on the consumer's Prisma schema.

Inherited from

BaseRepository.ENTITY_TYPE


logger?

protected readonly optional logger?: Logger;

Defined in: server/persistence/base-repository.ts:64

Inherited from

BaseRepository.logger


prismaClient

protected prismaClient: PrismaClientLike<Tx<PrismaClient<PrismaClientOptions, never, DefaultArgs>>> & PrismaClient<PrismaClientOptions, never, DefaultArgs>;

Defined in: server/persistence/base-repository.ts:69

Inherited from

BaseRepository.prismaClient

Accessors

actorId

Get Signature

get protected actorId(): string | null | undefined;

Defined in: server/persistence/base-repository.ts:76

Returns

string | null | undefined

Inherited from

BaseRepository.actorId


auditCreate

Get Signature

get protected auditCreate(): {
  createdBy: string | null | undefined;
  updatedBy: string | null | undefined;
};

Defined in: server/persistence/base-repository.ts:90

Returns
{
  createdBy: string | null | undefined;
  updatedBy: string | null | undefined;
}
createdBy
createdBy: string | null | undefined = actorId;
updatedBy
updatedBy: string | null | undefined = actorId;

Inherited from

BaseRepository.auditCreate


auditDelete

Get Signature

get protected auditDelete(): {
  deletedAt: Date;
  deletedBy: string | null | undefined;
};

Defined in: server/persistence/base-repository.ts:99

Returns
{
  deletedAt: Date;
  deletedBy: string | null | undefined;
}
deletedAt
deletedAt: Date;
deletedBy
deletedBy: string | null | undefined;

Inherited from

BaseRepository.auditDelete


auditUpdate

Get Signature

get protected auditUpdate(): {
  updatedBy: string | null | undefined;
};

Defined in: server/persistence/base-repository.ts:95

Returns
{
  updatedBy: string | null | undefined;
}
updatedBy
updatedBy: string | null | undefined;

Inherited from

BaseRepository.auditUpdate


silent

Get Signature

get silent(): this;

Defined in: server/persistence/base-repository.ts:115

Suppress activity logging for the next mutation call. One-shot: the flag is consumed by the next create/update/delete.

Example
await repo.silent.update(id, data);   // no activity logged
await repo.update(id, data);          // activity logged normally
Returns

this

Inherited from

BaseRepository.silent


tx

Get Signature

get protected tx(): TTx;

Defined in: server/persistence/base-repository.ts:86

The current Prisma handle: the active transaction if one is running on this async context, otherwise the raw client.

Returns

TTx

Inherited from

BaseRepository.tx

Methods

append()

append(entry: AccessDecisionEntry): Promise<{
  action: string;
  allowed: boolean;
  decidedAt: Date;
  id: string;
  organizationId: string | null;
  reason: string | null;
  resourceId: string | null;
  resourceType: string | null;
  scopeKey: string;
  subjectId: string;
  subjectType: RbacSubjectType;
  trace: JsonValue;
}>;

Defined in: server/access/decision-log-repository.ts:27

Parameters

ParameterType
entryAccessDecisionEntry

Returns

Promise<{ action: string; allowed: boolean; decidedAt: Date; id: string; organizationId: string | null; reason: string | null; resourceId: string | null; resourceType: string | null; scopeKey: string; subjectId: string; subjectType: RbacSubjectType; trace: JsonValue; }>


consumeSilent()

protected consumeSilent(): boolean;

Defined in: server/persistence/base-repository.ts:128

Consume and reset the silent flag. Called by template methods.

Returns

boolean

Inherited from

BaseRepository.consumeSilent


findRecentForSubject()

findRecentForSubject(
   scopeKey: string, 
   subjectType: SubjectType, 
   subjectId: string, 
   limit?: number
): Promise<{
  action: string;
  allowed: boolean;
  decidedAt: Date;
  id: string;
  organizationId: string | null;
  reason: string | null;
  resourceId: string | null;
  resourceType: string | null;
  scopeKey: string;
  subjectId: string;
  subjectType: RbacSubjectType;
  trace: JsonValue;
}[]>;

Defined in: server/access/decision-log-repository.ts:52

Recent decisions for a subject (newest first).

Parameters

ParameterTypeDefault value
scopeKeystringundefined
subjectTypeSubjectTypeundefined
subjectIdstringundefined
limitnumber100

Returns

Promise<{ action: string; allowed: boolean; decidedAt: Date; id: string; organizationId: string | null; reason: string | null; resourceId: string | null; resourceType: string | null; scopeKey: string; subjectId: string; subjectType: RbacSubjectType; trace: JsonValue; }[]>


logActivity()

protected logActivity(
   _entityId: string, 
   _action: string, 
   _metadata?: Record<string, unknown>
): Promise<void>;

Defined in: server/persistence/base-repository.ts:140

Log an activity entry.

NOTE: This is not implemented because there's no activity model implemented in taproot yet! https://linear.app/kaizenlabs/issue/ENG-7846/add-activity-log-tables

Parameters

ParameterType
_entityIdstring
_actionstring
_metadata?Record<string, unknown>

Returns

Promise<void>

Inherited from

BaseRepository.logActivity

On this page