Skip to content

Fix incorrect IP address when creating audit event

What does this MR do?

Fix incorrect IP address when creating audit event

The IP address on the user (aka. current_sign_in_ip) can potentially be stale if the user has not logged out for some time. AuditEvenService is capable of resolving the IP address directly from the Gitlab::RequestContext and do not need this information passed in from the caller.

I have raised a broader MR to remove the ability to pass IP address when calling AuditEvenService.

Related to #296230 (closed)

Does this MR meet the acceptance criteria?

Conformity

Availability and Testing

Security

If this MR contains changes to processing or storing of credentials or tokens, authorization and authentication methods and other items described in the security review guidelines:

  • [-] Label as security and @ mention @gitlab-com/gl-security/appsec
  • [-] The MR includes necessary changes to maintain consistency between UI, API, email, or other methods
  • [-] Security reports checked/validated by a reviewer from the AppSec team
Edited by Tan Le

Merge request reports