Skip to content

docs(core): document audit-log filter behaviour per backend - #97

Open
lakhansamani wants to merge 1 commit into
mainfrom
docs/audit-log-filter-backends
Open

lakhansamani wants to merge 1 commit into
mainfrom
docs/audit-log-filter-backends

Conversation

@lakhansamani

Copy link
Copy Markdown
Contributor

Operator-facing consequences of authorizerdev/authorizer#802 belong in the docs sections, not in a design spec. This puts them where a reader will actually find them.

Why

docs/core/graphql-api.md already documented all six _audit_logs filters — while CassandraDB/ScyllaDB and Couchbase silently applied only two of them. The reference was correct about the intent and wrong about the behaviour, with nothing telling the reader which.

Changes

docs/core/graphql-api.md — in the _audit_logs section: filters combine with AND and are applied by every backend; a callout for upgraders explaining that on those two backends four filters were previously accepted and ignored (and that any two filters at once failed outright on Cassandra/Scylla), so result counts and pagination.total will drop after upgrade. Stated explicitly as a correction rather than data loss, because that is how it will look otherwise.

docs/core/databases.md — two > Note for … callouts in the existing per-backend style:

  • CassandraDB/ScyllaDB: the two new secondary indexes backfill in the background (materialized views on Scylla), so resource filters can return incomplete results until it completes — check nodetool viewbuildstatus, expect elevated I/O. Timestamp-range filters cannot use an index and perform an ALLOW FILTERING scan.
  • Couchbase: index creation is synchronous, so a new index on an already-populated collection can outrun the client; this is handled by retry plus the server-side definition, and startup is not blocked.

Deliberately not documented

AdminAuthMode / the auth_mode audit field from authorizerdev/authorizer#806. That PR ships the plumbing and emits no audit records, so documenting the field now would describe behaviour that does not exist. It lands with the phase that writes it.

Notes

No version number is asserted — the next release is not cut yet, so the upgrade callout references the PR and points at the changelog instead of guessing 2.4.2.

npx docusaurus build exits 0 with no broken links.

Release notes proper are in authorizerdev/authorizer's CHANGELOG.md under [Unreleased].

The _audit_logs reference already listed all six filters while two
backends silently ignored four of them. Records that they now apply
everywhere, what upgraders should expect, and the index-backfill
caveats on cassandra/scylla and couchbase.

Operator-facing behaviour belongs in these sections, not in a spec.
@netlify

netlify Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for authorizerdev-docs ready!

Name Link
🔨 Latest commit 0925a40
🔍 Latest deploy log https://app.netlify.com/projects/authorizerdev-docs/deploys/6ac4e2b370e46e00080dd3c1
😎 Deploy Preview https://deploy-preview-97--authorizerdev-docs.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
🤖 Make changes Run an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

@vercel

vercel Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
docs Ready Ready Preview Oct 6, 2026 12:00pm UTC

This branch was successfully deployed

1 active deployment
Preview — 0925a40f Deployed Oct 6, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant