Respect username filters in audit event CSV export
What does this MR do and why?
Admin::AuditLogReportsController kept its own strong-params allowlist which
omitted entity_username, so filtering the instance audit events log by a user
and exporting returned every User-entity event on the instance. The Log tab
was unaffected, so the table and its export disagreed.
The frontend, ExportCsvService and CombinedAuditEventFinder all already
handled entity_username - only the controller's allowlist was wrong. Replacing
it with the shared AuditEvents::AuditEventsParams concern (already used by the
instance, group and project audit event controllers) removes the duplicated list
that was the root cause, so the two surfaces cannot drift again.
This also explains the intermittent 500s on the issue: the unfiltered scan
walks every user's events, and the response is streamed, so the error lands
inside the downloaded file. Group and project filters were unaffected, since they
send entity_id, which was already permitted - two of the three tokens worked,
which is why this went unnoticed.
It matters most for Support security-log requests, where the export packages audit data for a customer and a dropped filter yields a plausible-looking file of unrelated users' records. Previously fail-open, now fail-closed.
Two caveats worth flagging:
- The concern also permits
sortandauthor_username. Neither can widen a result set, andauthor_usernameisn't reachable from this page - themembertoken that produces it lives on the group/project pages, which have no export. Hence the tests coverentity_usernameonly. - The concern also provides
audit_params→filter_by_author→can_view_events_from_all_members?, which is defined only in the group/project controllers. We callaudit_events_paramsand never reach it, exactly asAdmin::AuditLogsControllerdoes. Not a permissions gap; this endpoint is admin-gated.
References
- Closes #624680 (closed)
Screenshots or screen recordings
Consider the following filter: User Events = Administrator, and then we export to CSV:
| Before | After |
|---|---|
| audit-events-1788128416.csv - CSV includes ALL user events | audit-events-1788133165.csv - CSV only includes events from the Administrator user |
How to set up and validate locally
- In the GDK, ensure you have a license/subscription applied as audit events are an Enterprise feature.
- Go to Admin area > Monitoring > Audit events (Log tab).
- Filter with the User Events token for one user eg.
Administrator- the table shows only their events. - Click Export as CSV.
- On
master, the CSV will include all user events - On
fix/use-filters-in-audit-event-export, the CSV will only include user events fromAdministrator.
- On
- Confirm the
Group EventsandProject Eventsfilters still apply to the export correctly.
MR acceptance checklist
Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.
