Skip to content

Log authentication events alongside audit events

Drew Blessing requested to merge dblessing-auth-events-logging into master

What does this MR do?

Part 3 of #224102 (closed) and a follow-up to !39652 (merged).

This implements creation of authentication events alongside existing authentication-related audit events. For now, we will store the duplicate information. A later iteration will clean this up so we're not storing duplicate events indefinitely. The issue tracking that is #247640.

Screenshots

Does this MR meet the acceptance criteria?

Conformity

Availability and Testing

Security

If this MR contains changes to processing or storing of credentials or tokens, authorization and authentication methods and other items described in the security review guidelines:

  • Label as security and @ mention @gitlab-com/gl-security/appsec
  • The MR includes necessary changes to maintain consistency between UI, API, email, or other methods
  • Security reports checked/validated by a reviewer from the AppSec team
Edited by Drew Blessing

Merge request reports

Loading