mengstack-website/guide/audit.md
MengStack Dev fca3326e34 docs: 官网文档全面更新 — M2-M8 指南 + API 参考 + v0.2.0 更新日志
- 更新 changelog.md: v0.2.0 记录 M2-M8 全部完成,路线图更新
- 新增 5 篇指南: RBAC、组织管理、审计日志、通知模块、质量横切
- 新增 5 篇 API 文档: RBAC(11)、Org(5)、Audit(1)、Settings(7)、Notification(7)
- 更新 api/overview.md: 完整 37 端点列表
- 更新 config.ts: 侧边栏分组 + 11 页 SEO 元数据
2026-10-03 01:55:55 +08:00

100 lines
2.5 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

---
title: 审计日志 | 操作追踪与合规记录 - MengStack官方文档
---
# 审计日志
审计日志模块自动记录系统中的关键操作,支持多维筛选和分页查询,满足合规审计需求。
## 数据模型
```go
type AuditLog struct {
ID uint // 自增主键
TenantID string // 租户 ID
UserID uint // 操作人 ID
Action string // 操作类型(create / update / delete / login 等)
Resource string // 资源类型(user / role / tenant 等)
ResourceID string // 资源 ID
Detail string // 操作详情(JSON 格式)
IP string // 操作人 IP 地址
CreatedAt time.Time // 操作时间
}
```
## 记录时机
审计日志在以下场景自动写入:
| 场景 | Action | Resource |
|------|--------|----------|
| 用户注册 | `create` | `user` |
| 用户登录 | `login` | `auth` |
| 修改密码 | `update` | `user` |
| 创建角色 | `create` | `role` |
| 删除角色 | `delete` | `role` |
| 分配角色 | `assign` | `user_role` |
| 创建租户 | `create` | `tenant` |
| 修改配置 | `update` | `setting` |
## 查询方式
支持按用户、操作类型、资源类型筛选,并支持分页:
```bash
# 查询所有审计日志
curl http://localhost:2222/api/v1/audit/logs \
-H "Authorization: Bearer <token>" \
-H "X-Tenant-ID: <tenant_id>"
# 按用户筛选
curl "http://localhost:2222/api/v1/audit/logs?user_id=1" \
-H "Authorization: Bearer <token>" \
-H "X-Tenant-ID: <tenant_id>"
# 按操作类型筛选 + 分页
curl "http://localhost:2222/api/v1/audit/logs?action=delete&page=1&page_size=10" \
-H "Authorization: Bearer <token>" \
-H "X-Tenant-ID: <tenant_id>"
```
## 响应格式
```json
{
"code": 0,
"message": "success",
"data": {
"items": [
{
"id": 1,
"tenant_id": "550e8400-...",
"user_id": 1,
"action": "create",
"resource": "role",
"resource_id": "5",
"detail": "{\"name\":\"editor\"}",
"ip": "192.168.1.100",
"created_at": "2026-10-03T10:00:00+08:00"
}
],
"total": 42,
"page": 1
}
}
```
## 安全特性
- 审计日志按 `tenant_id` 严格隔离,租户只能查看自己的日志
- 日志记录不可修改、不可删除(只写不删)
- IP 地址从请求上下文中自动提取
## API 端点
| 方法 | 路径 | 说明 |
|------|------|------|
| GET | `/api/v1/audit/logs` | 分页查询审计日志 |
详细接口参数见 [审计日志 API 参考](/api/audit)。