/* * This file is part of a proprietary work. * * Copyright (c) 2025 Fossorial, Inc. * All rights reserved. * * This file is licensed under the Fossorial Commercial License. * You may not use this file except in compliance with the License. * Unauthorized use, copying, modification, or distribution is strictly prohibited. * * This file is not licensed under the AGPLv3. */ import { actionAuditLog, db } from "@server/db"; import { registry } from "@server/openApi"; import { NextFunction } from "express"; import { Request, Response } from "express"; import { eq, gt, lt, and, count } from "drizzle-orm"; import { OpenAPITags } from "@server/openApi"; import { z } from "zod"; import createHttpError from "http-errors"; import HttpCode from "@server/types/HttpCode"; import { fromError } from "zod-validation-error"; import { QueryActionAuditLogResponse } from "@server/routers/auditLogs/types"; import response from "@server/lib/response"; import logger from "@server/logger"; import { queryAccessAuditLogsParams, queryAccessAuditLogsQuery, querySites } from "./queryActionAuditLog"; function generateCSV(data: any[]): string { if (data.length === 0) { return "orgId,action,actorType,timestamp,actor\n"; } const headers = Object.keys(data[0]).join(","); const rows = data.map(row => Object.values(row).map(value => typeof value === 'string' && value.includes(',') ? `"${value.replace(/"/g, '""')}"` : value ).join(",") ); return [headers, ...rows].join("\n"); } registry.registerPath({ method: "get", path: "/org/{orgId}/logs/actionk/export", description: "Export the action audit log for an organization as CSV", tags: [OpenAPITags.Org], request: { query: queryAccessAuditLogsQuery, params: queryAccessAuditLogsParams }, responses: {} }); export async function exportAccessAuditLogs( req: Request, res: Response, next: NextFunction ): Promise { try { const parsedQuery = queryAccessAuditLogsQuery.safeParse(req.query); if (!parsedQuery.success) { return next( createHttpError( HttpCode.BAD_REQUEST, fromError(parsedQuery.error) ) ); } const { timeStart, timeEnd, limit, offset } = parsedQuery.data; const parsedParams = queryAccessAuditLogsParams.safeParse(req.params); if (!parsedParams.success) { return next( createHttpError( HttpCode.BAD_REQUEST, fromError(parsedParams.error) ) ); } const { orgId } = parsedParams.data; const baseQuery = querySites(timeStart, timeEnd, orgId); const log = await baseQuery.limit(limit).offset(offset); const csvData = generateCSV(log); res.setHeader('Content-Type', 'text/csv'); res.setHeader('Content-Disposition', `attachment; filename="audit-logs-${orgId}-${Date.now()}.csv"`); return res.send(csvData); } catch (error) { logger.error(error); return next( createHttpError(HttpCode.INTERNAL_SERVER_ERROR, "An error occurred") ); } }