Respect username filters in audit event CSV export

What does this MR do and why?

Admin::AuditLogReportsController kept its own strong-params allowlist which omitted entity_username, so filtering the instance audit events log by a user and exporting returned every User-entity event on the instance. The Log tab was unaffected, so the table and its export disagreed.

The frontend, ExportCsvService and CombinedAuditEventFinder all already handled entity_username - only the controller's allowlist was wrong. Replacing it with the shared AuditEvents::AuditEventsParams concern (already used by the instance, group and project audit event controllers) removes the duplicated list that was the root cause, so the two surfaces cannot drift again.

This also explains the intermittent 500s on the issue: the unfiltered scan walks every user's events, and the response is streamed, so the error lands inside the downloaded file. Group and project filters were unaffected, since they send entity_id, which was already permitted - two of the three tokens worked, which is why this went unnoticed.

It matters most for Support security-log requests, where the export packages audit data for a customer and a dropped filter yields a plausible-looking file of unrelated users' records. Previously fail-open, now fail-closed.

Two caveats worth flagging:

  • The concern also permits sort and author_username. Neither can widen a result set, and author_username isn't reachable from this page - the member token that produces it lives on the group/project pages, which have no export. Hence the tests cover entity_username only.
  • The concern also provides audit_params → filter_by_author → can_view_events_from_all_members?, which is defined only in the group/project controllers. We call audit_events_params and never reach it, exactly as Admin::AuditLogsController does. Not a permissions gap; this endpoint is admin-gated.

References

Screenshots or screen recordings

Consider the following filter: User Events = Administrator, and then we export to CSV:

Screenshot_2026-08-31_at_11.38.51_AM

Before After
audit-events-1788128416.csv - CSV includes ALL user events audit-events-1788133165.csv - CSV only includes events from the Administrator user

How to set up and validate locally

  1. In the GDK, ensure you have a license/subscription applied as audit events are an Enterprise feature.
  2. Go to Admin area > Monitoring > Audit events (Log tab).
  3. Filter with the User Events token for one user eg. Administrator - the table shows only their events.
  4. Click Export as CSV.
    • On master, the CSV will include all user events
    • On fix/use-filters-in-audit-event-export, the CSV will only include user events from Administrator.
  5. Confirm the Group Events and Project Events filters still apply to the export correctly.

MR acceptance checklist

Evaluate this MR against the MR acceptance checklist. It helps you analyze changes to reduce risks in quality, performance, reliability, security, and maintainability.

Merge request reports

Loading
Loading