Record WebCRT device login/commands and NE exec in operation audit.

Make session lifecycle and typed CLI lines searchable in audit_log with password redaction, and surface summaries plus device filters in the ops UI.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
oliver 2026-09-01 21:36:44 +08:00
parent 497a5e048e
commit 8915455b52
12 changed files with 783 additions and 40 deletions

View file

@ -261,8 +261,12 @@ def _finish_connect(
"session_open_failed",
session_id=sess.session_id,
ne_id=sess.ne_id,
ne_name=sess.ne_name,
ne_ip=sess.ne_ip,
protocol=sess.protocol,
source=str(device.get("source") or ""),
owner_user_id=sess.owner_user_id,
owner_username=sess.owner_username,
client=client or "",
error=str(exc)[:500],
transcript_len=len(partial),
@ -500,6 +504,8 @@ def _finish_connect(
protocol=sess.protocol,
encoding=sess.encoding,
source=str(device.get("source") or ""),
owner_user_id=sess.owner_user_id,
owner_username=sess.owner_username,
hop_enabled=bool(creds.get("hop_enabled")),
hop_vendor=str(creds.get("hop_vendor") or "") if creds.get("hop_enabled") else "",
cli_hop_guard=bool(hop_guard),
@ -608,9 +614,12 @@ def create_session(
"session_connecting",
session_id=session_id,
ne_id=sess.ne_id,
ne_name=sess.ne_name,
ne_ip=sess.ne_ip,
protocol=sess.protocol,
encoding=enc,
owner_user_id=sess.owner_user_id,
owner_username=sess.owner_username,
client=client or "",
async_connect=bool(async_connect),
)
@ -746,7 +755,11 @@ def close_session(session_id: str, *, reason: str = "closed", client: str = "")
"session_closed",
session_id=session_id,
ne_id=sess.ne_id,
ne_name=sess.ne_name,
ne_ip=sess.ne_ip,
protocol=sess.protocol,
owner_user_id=sess.owner_user_id,
owner_username=sess.owner_username,
reason=reason,
client=client or "",
bytes_in=sess.bytes_in,