@companyio/auditlog
v0.1.4
Published
Universal audit log for multi-tenant CompanyIO products
Readme
@companyio/auditlog
Universal audit log for CompanyIO products. Fuel, POS, school, HR, sales, and expenses can record what changed. None of them own a second audit table.
Audit log owns append-only entries: actor, action, entity, description, metadata, and an optional source document. It does not send notifications and it does not know about stations, invoices, or employees. Pass opaque action, entityType, entityId, and sourceModule / sourceType / sourceId.
The host owns PostgreSQL, DATABASE_URL, Prisma Client, and migrations. This package does not create a database or a Prisma Client. Tenant columns are main_business_id and branch_id. They are not Prisma relations to Business or Branch.
pnpm exec auditlog init --schema apps/api/prisma/schema.prisma
pnpm exec auditlog status
pnpm --filter @companyio/api exec prisma migrate deploy --config prisma7.config.tsauditlog init appends prisma/auditlog.prisma between // @companyio/auditlog:begin and // @companyio/auditlog:end when AuditLog is missing. It copies prisma/migrations/0001_auditlog_baseline only when no host folder name already contains auditlog. It does not connect to PostgreSQL and it does not run migrate.
Fastify
attachAuditLog(app, {
store: createPrismaAuditLogStore(prisma),
prefix: '/api/v1/audit-logs',
authenticate: async (request) => getUser(request),
getContext: (_request, user) => ({
main_business_id: user.main_business_id,
branch_id: user.branch_id,
user_id: user.id,
}),
});List and get are scoped to that business and branch. The entry user_id is the actor, taken from the session unless the caller passes one.
