Class: DecisionLogRepository
Defined in: server/access/decision-log-repository.ts:23
Append-only writer for the decision audit log. SENSITIVE security dataset —
the trace holds policy references + condition outcomes only, never full
resource payloads. In v1 this backs the OPT-IN createTableDecisionSink
adapter (an onDecision hook implementation); the default audit boundary is
the no-op hook. Writes are fire-and-forget off the hot path (the sink wraps
append so a failure never fails the can() decision), so this repo only
exposes append + read helpers; there is no update/delete surface.
Extends
BaseRepository<PrismaClient,Tx<PrismaClient>>
Constructors
Constructor
new DecisionLogRepository(prismaClient: PrismaClientLike<Tx<PrismaClient<PrismaClientOptions, never, DefaultArgs>>> & PrismaClient<PrismaClientOptions, never, DefaultArgs>, options?: RepositoryOptions): DecisionLogRepository;Defined in: server/persistence/base-repository.ts:68
Parameters
| Parameter | Type |
|---|---|
prismaClient | PrismaClientLike<Tx<PrismaClient<PrismaClientOptions, never, DefaultArgs>>> & PrismaClient<PrismaClientOptions, never, DefaultArgs> |
options | RepositoryOptions |
Returns
DecisionLogRepository
Inherited from
Properties
ENTITY_TYPE?
protected readonly optional ENTITY_TYPE?: string;Defined in: server/persistence/base-repository.ts:61
Set ENTITY_TYPE in child repositories to enable automatic activity
logging. When set, create/update/delete operations auto-log unless
silenced with .silent. Requires an activity model on the consumer's
Prisma schema.
Inherited from
logger?
protected readonly optional logger?: Logger;Defined in: server/persistence/base-repository.ts:64
Inherited from
prismaClient
protected prismaClient: PrismaClientLike<Tx<PrismaClient<PrismaClientOptions, never, DefaultArgs>>> & PrismaClient<PrismaClientOptions, never, DefaultArgs>;Defined in: server/persistence/base-repository.ts:69
Inherited from
Accessors
actorId
Get Signature
get protected actorId(): string | null | undefined;Defined in: server/persistence/base-repository.ts:76
Returns
string | null | undefined
Inherited from
auditCreate
Get Signature
get protected auditCreate(): {
createdBy: string | null | undefined;
updatedBy: string | null | undefined;
};Defined in: server/persistence/base-repository.ts:90
Returns
{
createdBy: string | null | undefined;
updatedBy: string | null | undefined;
}createdBy
createdBy: string | null | undefined = actorId;updatedBy
updatedBy: string | null | undefined = actorId;Inherited from
auditDelete
Get Signature
get protected auditDelete(): {
deletedAt: Date;
deletedBy: string | null | undefined;
};Defined in: server/persistence/base-repository.ts:99
Returns
{
deletedAt: Date;
deletedBy: string | null | undefined;
}deletedAt
deletedAt: Date;deletedBy
deletedBy: string | null | undefined;Inherited from
auditUpdate
Get Signature
get protected auditUpdate(): {
updatedBy: string | null | undefined;
};Defined in: server/persistence/base-repository.ts:95
Returns
{
updatedBy: string | null | undefined;
}updatedBy
updatedBy: string | null | undefined;Inherited from
silent
Get Signature
get silent(): this;Defined in: server/persistence/base-repository.ts:115
Suppress activity logging for the next mutation call. One-shot: the flag is consumed by the next create/update/delete.
Example
await repo.silent.update(id, data); // no activity logged
await repo.update(id, data); // activity logged normallyReturns
this
Inherited from
tx
Get Signature
get protected tx(): TTx;Defined in: server/persistence/base-repository.ts:86
The current Prisma handle: the active transaction if one is running on this async context, otherwise the raw client.
Returns
TTx
Inherited from
Methods
append()
append(entry: AccessDecisionEntry): Promise<{
action: string;
allowed: boolean;
decidedAt: Date;
id: string;
organizationId: string | null;
reason: string | null;
resourceId: string | null;
resourceType: string | null;
scopeKey: string;
subjectId: string;
subjectType: RbacSubjectType;
trace: JsonValue;
}>;Defined in: server/access/decision-log-repository.ts:27
Parameters
| Parameter | Type |
|---|---|
entry | AccessDecisionEntry |
Returns
Promise<{
action: string;
allowed: boolean;
decidedAt: Date;
id: string;
organizationId: string | null;
reason: string | null;
resourceId: string | null;
resourceType: string | null;
scopeKey: string;
subjectId: string;
subjectType: RbacSubjectType;
trace: JsonValue;
}>
consumeSilent()
protected consumeSilent(): boolean;Defined in: server/persistence/base-repository.ts:128
Consume and reset the silent flag. Called by template methods.
Returns
boolean
Inherited from
findRecentForSubject()
findRecentForSubject(
scopeKey: string,
subjectType: SubjectType,
subjectId: string,
limit?: number
): Promise<{
action: string;
allowed: boolean;
decidedAt: Date;
id: string;
organizationId: string | null;
reason: string | null;
resourceId: string | null;
resourceType: string | null;
scopeKey: string;
subjectId: string;
subjectType: RbacSubjectType;
trace: JsonValue;
}[]>;Defined in: server/access/decision-log-repository.ts:52
Recent decisions for a subject (newest first).
Parameters
| Parameter | Type | Default value |
|---|---|---|
scopeKey | string | undefined |
subjectType | SubjectType | undefined |
subjectId | string | undefined |
limit | number | 100 |
Returns
Promise<{
action: string;
allowed: boolean;
decidedAt: Date;
id: string;
organizationId: string | null;
reason: string | null;
resourceId: string | null;
resourceType: string | null;
scopeKey: string;
subjectId: string;
subjectType: RbacSubjectType;
trace: JsonValue;
}[]>
logActivity()
protected logActivity(
_entityId: string,
_action: string,
_metadata?: Record<string, unknown>
): Promise<void>;Defined in: server/persistence/base-repository.ts:140
Log an activity entry.
NOTE: This is not implemented because there's no activity model implemented in taproot yet! https://linear.app/kaizenlabs/issue/ENG-7846/add-activity-log-tables
Parameters
| Parameter | Type |
|---|---|
_entityId | string |
_action | string |
_metadata? | Record<string, unknown> |
Returns
Promise<void>