Uploaded image for project: 'Red Hat 3scale API Management'
  1. Red Hat 3scale API Management
  2. THREESCALE-10843

Add more detailed session and account activity to Audit Logs

XMLWordPrintable

    • Icon: Feature Request Feature Request
    • Resolution: Unresolved
    • Icon: Major Major
    • None
    • 2.14.0 GA
    • System
    • False
    • None
    • False
    • Not Started
    • Not Started
    • Not Started
    • Not Started
    • Not Started
    • Not Started

      Current Behaviour

      User session is not audited.

      Expected Behaviour

      User sessions are audited and a distinction is made in the audit log between a successful and failed session create event.

      customer is looking for the following audit logs:

      • Login, success:
      • Login, Failed:
      • User Account change password, success
      • User Account change password, failure
      • User Account locked, success:

      Release Notes:

      • Removed audit logs for login/logout success
      • Login and logout are audited by `UserSession`. `created` for login, `revoked_at` for logout.
      • Password change is audited by `User#password_digest`
      • A new audit log is generated when the user fails trying to change its password.
      • All above is valid for admin and developer portals.

              Unassigned Unassigned
              rhn-support-keprice Kevin Price
              Martin Kudlej Martin Kudlej
              Joan Lledo Joan Lledo
              Votes:
              9 Vote for this issue
              Watchers:
              9 Start watching this issue

                Created:
                Updated: